
Data Scientist, Cybersecurity
About the Team
OpenAI’s Agentic Data Science team helps shape how AI agents are built, deployed, and improved across our products. We partner with product, engineering, research, and security teams to define meaningful measures of success, understand how our systems behave in the real world, and translate evidence into better decisions.
As AI agents become more capable, they can write and execute code, access sensitive systems, and complete increasingly complex tasks with greater autonomy. These capabilities create powerful opportunities to improve cybersecurity, but they also introduce risks that traditional security tools and processes were not designed to address. Meeting this moment requires new ways to measure security, evaluate defenses, and distinguish genuine risk reduction from friction that slows users down.
About the Role
We are looking for a senior data scientist to help define what effective cybersecurity looks like in the age of AI agents.
You will work across OpenAI’s Security organization and cybersecurity product teams to measure emerging risks, improve internal security controls, and shape AI-powered security products. The problems are foundational: How do we know whether an agent’s security controls are effective? Which safeguards meaningfully reduce risk, and which create unnecessary friction? When an AI system identifies a potential vulnerability, how do we determine whether the finding is accurate, actionable, and ultimately resolved? How do we detect anomalous behavior or risky access when the systems themselves are changing rapidly?
You will report into Data Science while partnering closely with Security, Cyber Product, Engineering, and Research. This is a high-ownership role for someone who can establish a new analytical discipline, operate across organizational boundaries, and turn ambiguous security challenges into measurable improvements.
In This Role You Will
Define how we measure AI-agent security. Establish metrics and evaluation frameworks for security-control coverage, agent behavior, sensitive actions, access patterns, detection quality, and emerging risks.
Improve security controls without introducing unnecessary friction. Quantify the effectiveness and operational costs of safeguards, including false positives, blocked actions, escalations, approval delays, and recovery paths. Help teams make controls safer, more precise, and easier to use.
Build the data foundations for security decisions. Partner with engineering and data teams to improve instrumentation, connect fragmented telemetry, establish trusted datasets, and surface important coverage and data-quality gaps.
Strengthen detection and response. Identify meaningful signals of anomalous behavior, risky access, sensitive-data exposure, and other security-relevant activity. Evaluate whether interventions improve detection quality, response times, and real-world security outcomes.
Shape AI-powered cybersecurity products. Partner with product, engineering, and research teams to assess how effectively AI systems identify security issues, support developer and enterprise workflows, and create measurable customer value.
Develop evaluation systems for security findings. Define quality measures for findings, including accuracy, severity, actionability, duplication, resolution, and downstream impact. Connect model behavior and product changes to outcomes such as triage, remediation, and vulnerability reduction.
Understand the complete security workflow. Measure how users discover, investigate, validate, prioritize, and resolve security issues. Identify opportunities to improve activation, adoption, retention, and enterprise value across customer-facing cybersecurity products.
Design rigorous measurement and experimentation strategies. Evaluate new models, security controls, product features, and workflows through controlled experiments, staged rollouts, observational analyses, and other methods appropriate for high-stakes environments.
Translate analysis into security and product strategy. Identify the highest-value decisions, clarify tradeoffs, recommend where teams should invest, and communicate findings clearly to technical partners and senior leadership.
Help establish a new security data science capability. Build a focused roadmap, create durable operating rhythms across Data Science and Security, and help shape how this discipline grows over time.
You Might Thrive in This Role If You Have
5+ years of experience in data science, applied research, analytics, or a related quantitative field, with a track record of owning ambiguous, high-impact problems.
Experience in cybersecurity, trust and safety, fraud or abuse prevention, privacy, platform integrity, or another domain involving adversarial behavior and difficult-to-measure risks.
Strong proficiency in SQL and Python, including experience investigating complex datasets, working through incomplete instrumentation, and building reproducible analytical workflows.
Experience defining meaningful metrics and evaluation frameworks when ground truth is limited, outcomes are delayed, or important risks cannot be observed directly.
Strong judgment in experimentation, causal inference, observational analysis, and the practical limitations of different measurement approaches.
The ability to partner effectively with security engineers, product managers, software engineers, researchers, data engineers, and senior leaders.
A demonstrated ability to translate technical analysis into concrete improvements in products, systems, controls, or organizational priorities.
Comfort operating independently, defining a roadmap, and bringing structure to a domain without established processes or industry standards.
You Could Be an Especially Great Fit If You Have
Experience with detection engineering, threat research, security operations, insider risk, identity and access management, or privacy-preserving security analytics.
Familiarity with AI agents, large language models, model evaluations, automated code review, or AI-powered cybersecurity products.
Experience evaluating security findings, vulnerability detection, remediation workflows, or developer-facing security tools.
Experience balancing security effectiveness against user experience, including false positives, approval flows, operational burden, and recovery behavior.
Experience building automated monitoring, anomaly detection, production-oriented data assets, or systems that connect model outputs to real-world outcomes.
A track record of building new cross-functional measurement programs or establishing analytical capabilities from the ground up.
About OpenAI
OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.
We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic.
For additional information, please see OpenAI’s Affirmative Action and Equal Employment Opportunity Policy Statement.
Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: protect computer hardware entrusted to you from theft, loss or damage; return all computer hardware in your possession (including the data contained therein) upon termination of employment or end of assignment; and maintain the confidentiality of proprietary, confidential, and non-public information. In addition, job duties require access to secure and protected information technology systems and related data security obligations.
To notify OpenAI that you believe this job posting is non-compliant, please submit a report through this form. No response will be provided to inquiries unrelated to job posting compliance.
We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link.
OpenAI Global Applicant Privacy Policy
At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.
Similar roles
Field Marketing Manager (North Central)
Datadog·San Francisco, United States
Datadog is seeking a Field Marketing Manager to support and execute high-impact programs across the North Central region in North America. In this role, you’ll collaborate with regional Sales and Marketing teams to drive pipeline generation and deliver engaging in-person and virtual event experiences. You’ll take ownership of regional marketing initiatives, gaining hands-on experience across campaign strategy, execution, and cross-functional…
- Full-time
Senior Litigation Paralegal
Reddit·San Francisco, United States
Reddit is a community of communities. It’s built on shared interests, passion, and trust, and is home to the most open and authentic conversations on the internet. Every day, Reddit users submit, vote, and comment on the topics they care most about. With 100,000+ active communities and approximately 130 million daily active unique visitors, Reddit is one of the internet’s…
- Full-time
International Payroll Lead
Reddit·United States
Reddit is a community of communities. It’s built on shared interests, passion, and trust, and is home to the most open and authentic conversations on the internet. Every day, Reddit users submit, vote, and comment on the topics they care most about. With 100,000+ active communities and approximately 130 million daily active unique visitors, Reddit is one of the internet’s…
- Full-time
Senior Product Quality Analyst - AI Voice
Spotify·London, Canada
The Personalization team makes deciding what to play next easier and more enjoyable for every listener. From Blend to Discover Weekly, we’re behind some of Spotify’s most-loved features. We built them by understanding the world of music and podcasts better than anyone else. Join us and you’ll keep millions of users listening by making great recommendations to each and every…
- Remote
- Full-time
- Express Entry — PR day one, no employer
Content Marketing Manager, Demand Generation
Openai·San Francisco, United States
About the Team The B2B Content team helps business audiences understand what AI makes possible and how to put it to work. We develop narrative, editorial, demo, and adoption programs that connect OpenAI’s products to concrete business value. We partner closely with Product Marketing, Demand Generation, Customer Education, Sales, and other teams to create content that is useful on its…
- Hybrid
- Full-time
Software Engineer - Application Platform
Figma·San Francisco, United States
Figma is growing our team of passionate creatives and builders on a mission to make design accessible to all. Figma’s platform helps teams bring ideas to life—whether you're brainstorming, creating a prototype, translating designs into code, or iterating with AI. From idea to product, Figma empowers teams to streamline workflows, move faster, and work together in real time from anywhere…
- Full-time
Account Executive, Velocity Platforms (Hunter)
Stripe·Chicago, United States
WHO WE ARE ABOUT STRIPE Stripe is a financial infrastructure platform for businesses. Millions of companies - from the world’s largest enterprises to the most ambitious startups - use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead.…
- Full-time
Senior Product Quality Analyst - AI Voice
Spotify·Worldwide
The Personalization team makes deciding what to play next easier and more enjoyable for every listener. From Blend to Discover Weekly, we’re behind some of Spotify’s most-loved features. We built them by understanding the world of music and podcasts better than anyone else. Join us and you’ll keep millions of users listening by making great recommendations to each and every…
- Remote
- Full-time