Description
Compensation
The base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. The salary range for this position is $216K – $252K, with generous equity, performance-related bonuses for eligible employees, and the following benefits:
- Medical, dental, and vision insurance for you and your family, with employer contributions to Health Savings Accounts
- Pre-tax accounts for Health FSA, Dependent Care FSA, and commuter expenses (parking and transit)
- 401(k) retirement plan with employer match
- Paid parental leave (up to 24 weeks for birth parents and 20 weeks for non-birthing parents), plus paid medical and caregiver leave (up to 8 weeks)
- Paid time off: flexible PTO for exempt employees and up to 15 days annually for non-exempt employees
- 13+ paid company holidays, and multiple paid coordinated company office closures throughout the year for focus and recharge, plus paid sick or safe time (1 hour per 30 hours worked, or more, as required by applicable state or local law)
- Mental health and wellness support
- Employer-paid basic life and disability coverage
- Annual learning and development stipend to fuel your professional growth
- Daily meals in our offices, and meal delivery credits as eligible
- Relocation support for eligible employees
- Additional taxable fringe benefits, such as charitable donation matching and wellness stipends, may also be provided.
About the Team
OpenAI's Governance, Risk, and Compliance team helps ensure security and privacy are grounded in how our products and systems actually operate. Assurance Operations partners with Security, Engineering, Infrastructure, Product, Privacy, and Legal to make controls provable, risk decisions explicit, and audit readiness a result of well-designed systems.
About the Role
We are hiring a technical, product-minded GRC builder who can own consequential audits while improving the control and evidence systems behind them. You will build a reusable common control framework, use Codex to automate assurance work, validate changing system scope, and turn repeated audit friction into measurable improvements.
Responsibilities
- Lead external, internal, customer, and certification audit work from scoping through evidence review, fieldwork, remediation, and closeout.
- Build a common control framework linking risk, control intent, implementation, owner, system, environment, evidence, and applicable frameworks.
- Validate actual scope and ownership instead of assuming last year's controls, product boundaries, or evidence remain accurate.
- Use Codex to build and test evidence checks, control mappings, request triage, owner workflows, monitoring, and remediation reporting.
- Partner with engineers on cloud architecture, identity, logging, data flows, software changes, vulnerabilities, and control effectiveness.
- Design maintainable, permission-aware tools that preserve source provenance, human review, and evidence integrity.
- Reduce repeated requests and operational burden for control owners through measurable workflow improvements.
- Define roadmaps, decision rights, milestones, success metrics, and clear cross-functional escalations.
Requirements
- Direct ownership of meaningful audit, security, customer-assurance, or regulatory outcomes.
- Practical knowledge of control design, evidence, testing, operating effectiveness, and remediation.
- Technical fluency across cloud systems, identity, logging, APIs, data flows, and system boundaries.
- Ability to use Codex or comparable AI-assisted development tools to build, run, inspect, and test a working solution.
- Experience using code, SQL, APIs, structured data, automation, or data workflows to solve an operational problem.
- Ability to design reusable cross-framework controls without erasing framework-specific test and evidence requirements.
- First-principles curiosity, creative problem solving, intellectual humility, and the ability to update when facts change.
- Product and program judgment: define the user, scope, milestones, ownership, adoption, and measurable outcome.
- Clear, constructive partnership with Security, Engineering, Infrastructure, Product, Privacy, Legal, and audit teams.
- Frameworks such as SOC 2, ISO 27001/27017, PCI DSS, NIST, or FedRAMP are helpful; a specific degree, certification, or prior access to internal OpenAI tools is not required.