security · compliance
About the Team
OpenAI’s Governance, Risk, and Compliance team helps ensure security and privacy are grounded in how our products and systems actually operate. Assurance Operations partners with Security, Engineering, Infrastructure, Product, Privacy, and Legal to make controls provable, risk decisions explicit, and audit readiness a result of well-designed systems.
About the Role
We are hiring a technical, product-minded GRC builder who can own consequential audits while improving the control and evidence systems behind them. You will build a reusable common control framework, use Codex to automate assurance work, validate changing system scope, and turn repeated audit friction into measurable improvements. We are looking for someone who questions inherited assumptions, solves novel problems creatively, works closely with engineers, and makes the next audit easier by improving the underlying system.
You’ll be responsible for
- Lead external, internal, customer, and certification audit work from scoping through evidence review, fieldwork, remediation, and closeout.
- Build a common control framework linking risk, control intent, implementation, owner, system, environment, evidence, and applicable frameworks.
- Validate actual scope and ownership instead of assuming last year's controls, product boundaries, or evidence remain accurate.
- Use Codex to build and test evidence checks, control mappings, request triage, owner workflows, monitoring, and remediation reporting.
- Partner with engineers on cloud architecture, identity, logging, data flows, software chan