Primary record

Product Manager, Codex Security Controls & Partner Interfaces

OpenAI Indexed employerUS - Remote
Source-hosted applyChecked 3h ago$293K–$385K/yrFull-Time
Apply at OpenAI

OpenAI receives this application through Ashby. Babu Careers does not claim delivery.

Workplace

remote

Employment

Full-Time

Published

Jul 13, 2026

Closes

No date supplied

The role

ABOUT THE TEAM OpenAI’s Cyber team works to make frontier AI safe, trusted, and transformative for developers and enterprises. This team is building the security foundation for Codex: the native controls that govern what Codex can access and do, and the interfaces that allow customers and security partners to inspect, constrain, approve, and respond to Codex activity. Our goal is to make Codex secure by default, governable by enterprises, and interoperable with the security products customers already trust. This extends the existing product direction around tenant-scoped tools, guarded actions, approval systems, and scalable partner interfaces. ABOUT THE ROLE We are looking for a deeply technical Product Manager to help build Codex security controls and the partner ecosystem around them. This role focuses on securing Codex itself: how identity, permissions, tools, MCP servers, repositories, secrets, networks, and high-impact actions are governed across Codex products. You will also help define standard interfaces through which authorized customer and partner systems can provide security context, inspect activity, return policy decisions, receive telemetry, and initiate bounded responses. You will work closely with Codex product and engineering, OpenAI Security and Safety, enterprise customers, and partners across application security, identity, cloud security, data security, infrastructure, and security operations. IN THIS ROLE YOU WILL Build native security controls for Codex Partner with engineering, design, security, and safety teams to develop controls for: - Identity, roles, permissions, and tenant isolation. - Access to repositories, files, tools, MCP servers, secrets, networks, and infrastructure. - Read, write, execute, and deployment authority. - Human and policy-based approvals. - Prompt-injection and untrusted-content defenses. - Audit trails, provenance, stop conditions, revocation, and rollback. Help establish a graduated authority model in which local,

Requirements

Department: Security Products; Team: Security Products