About the Team The Corporate Security team is responsible for safeguarding all OpenAI employees and executives. Our mission is to create a secure, resilient environment that allows our teams to focus on their work without risk or disruption. We manage physical security operations across offices, events, and global initiatives, partnering closely with internal teams and external agencies to stay ahead of emerging threats. About the Role As a Corporate Security Manager , based in our San Francisco office, you will lead day-to-day security operations while supporting the development of global physical security strategies, policies, and procedures. You will work cross-functionally to maintain a strong and adaptive security posture, manage vendor security teams, and serve as a key liaison with law enforcement and security partners. This position requires hands-on experience in corporate security operations. This role typically involves 4–5 days in the office each week . In this role, you will: Office Security: Develop, implement, and manage physical security measures, including policies, systems, and vendor relationships, to protect employees and visitors in the San Francisco offices. International Offices: Support the International Director to safeguard OpenAI’s global footprint by assisting with security policy writing, consistent with US and main office policy and procedures, including ongoing mitigation strategies. Events: Support local events when needed and work with the resilience team on updating policy and procedures that involve the GSOC’s support. Partnerships & Stakeholder Engagement: Establish and strengthen relationships with local law enforcement agencies, peer security organizations, and other external partners to stay current on emerging risks. Policy Development & Compliance: Be the primary point of contact for the Corporate Security Operations team for global policy and procedures. Support and contribute to all the Corp Sec pillars as needed, f
Jobs in United States
Security Consultant Intern in San Francisco
300 active opportunities · Updated October 2026
Showing
15 jobs
Explore current security consultant intern jobs in San Francisco. Filter by work mode, employment type, experience, department, date posted and distance.
We are hiring a Security Software Engineer to design and implement the hardware-backed security foundations used across OpenAI’s device ecosystem. A central focus of this role is hardening the boundary between our policy systems and the HSMs that protect sensitive cryptographic keys. This boundary determines which operations may be performed, what may be signed, which policies must be satisfied, and how changes to trusted software and policy are authorized. You will develop security-critical software and firmware within, or immediately adjacent to, an HSM trust boundary. Depending on your background, this may include HSM trusted applications, firmware services, cryptographic mechanisms, device drivers, PKCS#11 components, secure-provisioning protocols, or signing-policy enforcement systems. This is a hands-on software-engineering role. You will be expected to design systems, write and review production code, debug across hardware and software boundaries, and carry projects from initial requirements through deployment. It is not an HSM administration, PKI operations, compliance, or architecture-only position. In This Role, You Will Design and implement security-critical software and firmware for HSMs, secure elements, trusted execution environments, and hardware roots of trust. Build and harden the policy-to-HSM boundary responsible for authorizing certificate issuance and cryptographic signing operations. Develop HSM trusted applications, firmware components, host interfaces, device drivers, SDKs, or cryptographic service integrations. Implement or extend cryptographic interfaces such as PKCS#11, OpenSSL providers or engines, platform key-storage APIs, or comparable hardware-security interfaces. Build firmware and software that cryptographically enforces key generation, provisioning, usage, rotation, recovery, and destruction policies. Design and implement HSM-backed certificate authority, code-signing, key-management, and device-identity systems. Develop end-to-end
We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam. Security Engineering is the engineering function inside the Plaid security org that focuses on developing the industry-leading security systems and infrastructure. Security Engineering owns most of Plaid’s security-related infrastructure: secure data storage, key management systems, internal identity platform, internal authentication systems, internal permission management, and internal authorization service. We develop solutions across data encryption, key management, access control, and data loss prevention to protect sensitive consumer data. We believe in the Zero Trust security model and are always looking for ways to improve our authentication and access control platforms. About the role You will develop security capabilities to secure Plaid infrastructure and to secure sensitive data access. You will own, maintain, and build Plaid’s security infrastructure and services like Key Management System and Secure Token Service. You will consult with product engineers to ensure Plaid services meet security standards. You will help educate and support other engineering teams to improve security in their own products and services. You will assist with Plaid’s incident response and security awareness pro
Who Are We? Postman is the world’s leading API platform, used by more than 45 million+ developers and 500,000 organizations, including 98% of the Fortune 500. Postman is helping developers and professionals across the globe build the API-first world by simplifying each step of the API lifecycle and streamlining collaboration—enabling users to create better APIs, faster. The company is headquartered in San Francisco and has offices in Boston, New York, Austin, Tokyo, London, and Bangalore - where Postman was founded. Postman is privately held, with funding from Battery Ventures, BOND, Coatue, CRV, Insight Partners, and Nexus Venture Partners. Learn more at postman.com or connect with Postman on X via @getpostman. P.S: We highly recommend reading The "API-First World" graphic novel to understand the bigger picture and our vision at Postman. About the Team The Information Security organization at Postman operates across three pillars: Governance Risk & Compliance (GRC), Product Security, and Security Operations. We are a team of builders, not checkbox-checkers. We hold active SOC 2 Type II, ISO 27001, ISO 42001, and HIPAA compliance postures, and we are pursuing FedRAMP High and CMMC Level 2 authorization. Our security stack includes Wiz, SentinelOne, Okta, Jamf, and 1Password, and we operate across a multi-cloud environment. The Offensive Security team is the "red" pulse of this organization. We don't just find bugs — we simulate the adversary to ensure our defenses hold up under real-world pressure. We focus on continuous security validation, AI-augmented adversary emulation, and offensive AI security research at Postman's scale. The Opportunity We are looking for a Principal Offensive Security Engineer who is as much a strategist as they are a hacker. You will own the strategic direction of Postman's offensive security program — including building out a dedicated Offensive AI Security capability from the ground up — and operat
About the Team Safety Systems manages the complete lifecycle of safety efforts for OpenAI’s frontier models, ensuring our models are deployed responsibly and have a positive impact on society. Our work spans diverse research and engineering initiatives—from system-level safeguards and model training to evaluation and red-teaming—all aimed at mitigating misuse, misalignment, and maintaining our high bar for safety. We lead OpenAI's commitment to developing and deploying safe Artificial General Intelligence (AGI), fostering a culture of trust, responsibility, and transparency. Our goal is to continuously learn from deployments, distribute AI’s benefits widely, and ensure that powerful tools remain aligned with human values and safety considerations. Within Safety Systems, the Model Policy team works to ensure that frontier models behave safely and reliably in real-world environments by designing policies that define safe model behavior. Some of our publications include: Safety at every step OpenAI GPT6 System Card OpenAI Model Spec About the Role We’re hiring a Model Policy Manager to shape model behavior for U.S. government use, with a focus on national security applications. You’ll define nuanced policies and translate them into training and evaluation criteria, helping models navigate high-stakes scenarios while preserving their usefulness and capabilities. In this role, you will: Develop model policies that guide safe and useful behavior. Build evaluations, identify policy gaps and model failures, and use findings to improve policies and training. Work with research, engineering, and domain experts to support safe, reliable deployment. You might thrive in this role if you: Bring relevant experience in AI safety, policy, or risk assessment. Have strong judgment and can turn complex safety questions into clear, practical policies. Have the technical fluency to work hands-on with model data and evaluations. Are motivated by OpenAI’s mission and the responsible use of
Who are we? Cohere is the leading security-first enterprise AI company. We build cutting-edge foundation AI models and end-to-end products that are designed to solve real-world business problems. We’re training and deploying frontier models for enterprises who are building AI systems. We believe that our work is instrumental to the widespread adoption of AI and we are looking for folks that want to be part of that. We obsess over what we build. Each one of us is responsible for contributing to increasing the capabilities of our models and the value they drive for our customers. Cohere is a team of researchers, engineers, designers, and more, who are all passionate about their craft. We are a global technology company headquartered in Toronto with key offices in London, New York City, San Francisco, Montreal, Paris, Berlin and Seoul. Join us! Role Overview Ready to build AI agents that revolutionize enterprise security? The North Security team is looking for a Senior Software Engineer to create autonomous systems that handle the complex, critical tasks security practitioners face every day. Key Responsibilities As a Senior Software Engineer focused on agentic security, you'll build intelligent systems that empower security teams. Your responsibilities will include: Build autonomous security agents that perform alert triage, secure code reviews, threat modeling, and vulnerability assessment Develop agent orchestration systems that help security practitioners automate repetitive security tasks Design and implement agent security controls to ensure our AI agents can safely interact with sensitive enterprise data Create the security infrastructure that allows agents to operate in high-trust environments with stringent deployment requirements Ship production-ready agent capabilities that run efficiently in resource-constrained environments Research and implement novel security patterns for AI agent systems, sometimes requiring custom solutions where standard libraries fal
£225K – £325K/yr
Who are we? Cohere is the leading security-first enterprise AI company. We build cutting-edge foundation AI models and end-to-end products that are designed to solve real-world business problems. We’re training and deploying frontier models for enterprises who are building AI systems. We believe that our work is instrumental to the widespread adoption of AI and we are looking for folks that want to be part of that. We obsess over what we build. Each one of us is responsible for contributing to increasing the capabilities of our models and the value they drive for our customers. Cohere is a team of researchers, engineers, designers, and more, who are all passionate about their craft. We are a global technology company headquartered in Toronto with key offices in London, New York City, San Francisco, Montreal, Paris, Berlin and Seoul. Join us! As a Manager of Security Engineering, your key responsibilities include: Serve as trusted advisor to team’s leadership and partner teams by clearly articulating business risks associated with security issues Execute the long-term vision for the Security team in alignment with Cohere’s product and business goals. Collaborate closely with leadership to prioritize high-impact initiatives and strategic customer engagements. Vulnerability Management: Develop and implement enterprise-wide vulnerability management processes and tooling, including identification, prioritization, remediation tracking, and reporting, including customer artifacts Static Application Security Testing (SAST): Establish SAST programs, integrate tools into CI/CD pipelines, and analyze results to identify and remediate security flaws in source code Dynamic Application Security Testing (DAST): Implement DAST methodologies, configure scanning tools, and conduct regular assessments of running applications Penetration Testing: Lead and oversee internal and external penetration testing engagements, including web application, API, network and agentic AI platform inclu
About the Team OpenAI’s Hardware organization develops AI-native silicon and system-level solutions for the unique demands of advanced AI workloads. Building on efforts like Jalapeño, the team is developing future generations of AI-native silicon and tightly integrated systems to power the next generation of frontier models. By co-designing chips, systems, tools, and methodologies, the team helps deliver faster, more efficient, and production-ready hardware for OpenAI’s supercomputing platform. About the Role We're seeking a Security Engineer to join our First-Party Hardware team. In this role, you will own the end-to-end security foundation for OpenAI's first-party AI hardware systems, working across hardware security, embedded security, system security, and practical deployment at data center scale. You will partner with silicon, hardware, firmware, infrastructure, manufacturing, operations, and security teams to define and deliver system-level device trust. This includes boot integrity, device identity, provisioning, attestation, management-plane security, storage encryption, debug controls, firmware update and recovery, RMA, and decommissioning. You will be accountable for turning threat models into requirements, requirements into implementation, and implementation into validation evidence that can support launch decisions. Location: San Francisco, CA (Hybrid: 3 days/week onsite) Relocation assistance available. In this role, you will: Own security requirements, threat models, validation strategy, and launch-readiness evidence for first-party hardware platforms from early design through production deployment. Design and review secure boot, measured boot, roots of trust, platform firmware resilience, firmware signing, recovery, and anti-rollback strategies across heterogeneous devices. Own device identity, provisioning, enrollment, attestation, certificate lifecycle, and key-management requirements across manufacturing and data center bring-up. Harden management
$230K – $280K/yr
Who We Are Notion is the collaborative AI workspace where teams and agents think together . We're building one place where your knowledge, projects, meetings, and AI tools live side by side, so work is faster, clearer, and less fragmented. Millions of individuals, small teams, and large companies run their work on Notion. Notinos (our employees) are customer zero in bringing this future of work to life. We care about craft, building things that last, and the belief that great work is still fundamentally human. Our goal isn’t to ship the next feature. Each and every team of Notinos is working to set the standard for how humans work together in the AI era. From building a business’s system of record to making and managing AI agents to automating away the busy work, we care deeply about giving our customers more time for their life’s work. About the Role: Millions of people use Notion every day, and we’re growing quickly. The Infrastructure Security team’s mission is to build a secure-by-default foundation across Notion’s technical stacks—architecting systems that make the secure path the easy path. As an IC4 on this team, you’ll own meaningful infrastructure security problems end-to-end: from identifying risk, to designing pragmatic controls, to shipping secure defaults that scale across engineering. This role can be based in either San Francisco or New York City. We work from our offices on Mondays, Tuesdays and Thursdays (our Anchor Days) because we do our best thinking and building together in person. We’re looking for someone who’s excited to work alongside the team during those days. What You'll Achieve: Proactively enhance the security posture of our AWS accounts and cloud infrastructure. Create secure frameworks for secrets management and authentication/authorization. Design and deploy robust Identity and Access Management (IAM) solutions. Provide guidance and education on security and privacy best practices to cross-functional partners. Participate in (and hel
From $270K/yr
Who We Are Notion is the collaborative AI workspace where teams and agents think together . We're building one place where your knowledge, projects, meetings, and AI tools live side by side, so work is faster, clearer, and less fragmented. Millions of individuals, small teams, and large companies run their work on Notion. Notinos (our employees) are customer zero in bringing this future of work to life. We care about craft, building things that last, and the belief that great work is still fundamentally human. Our goal isn’t to ship the next feature. Each and every team of Notinos is working to set the standard for how humans work together in the AI era. From building a business’s system of record to making and managing AI agents to automating away the busy work, we care deeply about giving our customers more time for their life’s work. About the Role: Notion is looking for an experienced engineer who has designed and built secure software systems to help define the security foundations for our AI products. You’ll work with product and engineering teams on agent runtimes, tool permissions, retrieval, content writes, observability, and abuse-resistant design. You’ll turn product risks into clear architecture, reusable guardrails, automated tests, and production systems that help teams ship new features safely. This role is based in San Francisco. We work from our offices on Mondays, Tuesdays and Thursdays (our Anchor Days) because we do our best thinking and building together in person. We’re looking for someone who’s excited to work alongside the team during those days. What You'll Achieve: Define and build security architecture for product surfaces that operate across customer workspace content, including tool execution, content writes, retrieval, permission checks, provenance, and auditability. Make the secure path the easy path for product teams by shipping reusable libraries, review patterns, test fixtures, and guardrails that prevent classes of vulnerabilities.
About the Team The Safety Training research team aims to fundamentally advance our capabilities for precisely implementing safe behavior in AI models, and to leverage these advances to make OpenAI’s deployed models safe and beneficial. This requires a breadth of new ML research to address the growing set of safety challenges as AI becomes more powerful and used in more settings. Key focus areas include how to train nuanced safety behaviors, how to make the model robust to bad actors, how to address privacy and security risks, and how to make the model trustworthy in safety-critical situations. We seek to learn from deployment and distribute the benefits of AI, while ensuring that this powerful tool is used responsibly and safely. About the Role We’re seeking a researcher to train and evaluate models for U.S. government use, with a focus on national security applications. You’ll advance safety post-training and robustness, helping models follow nuanced policies while preserving their usefulness and capabilities. In this role, you will: Research and implement methods for safety training, reinforcement learning, and adversarial robustness. Develop evaluations, identify model failure modes, and use findings to improve training. Work with research, engineering, security, and policy partners to support safe, reliable deployment. You might thrive in this role if you: Bring 4+ years of relevant AI safety research experience, including RLHF, adversarial training, or robustness. Have a degree in computer science, machine learning, or a related field, and strong deep learning research or engineering skills. Have experience improving model safety for deployment and enjoy collaborative research. Are motivated by OpenAI’s mission and the responsible use of AI in safety-critical settings. Security Requirements Active TS/SCI clearance or equivalent. About OpenAI OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefi
About the Team OpenAI’s Client Platform Engineering (CPE) team delivers trusted devices at scale: secure by default, reliable by design, and effortless to use. We own platform capabilities across macOS, Windows, iOS, Android, and Linux, spanning endpoint posture and device trust, application delivery, onboarding, updates, telemetry, workflow orchestration, and employee-facing remediation. The team partners deeply with Security, Research, Applied, and specialized engineering groups to enable and protect OpenAI while reducing friction for the people advancing our mission. About the Role As an Engineering Manager for CPE, you will lead a team of engineers responsible for the strategy, delivery, and operation of OpenAI’s cross-platform client foundation. You will combine people leadership with strong technical judgment: setting direction, developing engineers, reviewing architecture and tradeoffs, and creating the operating mechanisms that turn ambiguous needs into durable platform outcomes. This is a high-leverage role at the intersection of security, reliability, developer velocity, and employee experience. CPE is a highly technical platform engineering organization delivering first-party services, automation, observability, and safe fleet operations. We’re looking for a leader who can guide its next chapter, scaling the team and its systems, partnering across the company, and raising the bar for secure, reliable, low-friction experiences across every supported platform. In this role, you will: Lead and develop a high-performing engineering team; hire thoughtfully, coach engineers, create clarity, and foster an inclusive, high-accountability culture that pushes perceived limits. Define and execute a multi-year client-platform strategy and roadmap across macOS, Windows, iOS, Android, and Linux, including how Codex and agents can reshape employee computing. Provide technical direction for endpoint posture, device trust, application delivery, device onboarding, updates,
About the Team Security is foundational to OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security organization protects OpenAI’s technology, people, and products by building and operating deeply technical systems that must work reliably at massive scale. Our work underpins OpenAI’s commitments around safety, privacy, and security across research, products, and emerging platforms. The Host Assurance team exists to make bare metal and VMs dependable & scalable foundations for OpenAI: secure by default, verifiable in practice, and resilient across providers and operating models. We operate at the trust boundary between hardware and cloud-scale orchestration, ensuring that hosts are eligible to safely run workloads with predictable security properties and auditability. About the Role OpenAI is seeking a Software Engineer, Host Assurance to build and operate the services, APIs, and host software that establish and maintain trust in our compute infrastructure. You will own production software from design and implementation through testing, rollout, observability, and operation. Your work will support capabilities such as machine identity, certificate issuance and enrollment, secure bootstrap, and host attestation across bare-metal and VM environments. Success in this role requires strong technical judgment, the ability to reason across software and host-system boundaries and learn unfamiliar parts of the stack, and a practical mindset for building systems that are secure, reliable, and usable in fast-moving production environments. The systems you build will sit on the critical path of OpenAI’s frontier infrastructure investments and will directly shape how large amounts of compute are brought online - securely, responsibly, and at global scale - underpinning long-lived commitments around privacy, security, and reliability. You will partner closely with infrastructure, research, and confidential computing initiatives—inc
About the Team Governance, Risk, and Compliance (GRC) is foundational to Security delivering mission outcomes at OpenAI. The GRC team provides security assurances and builds compliance for OpenAI’s technology, people, and products. We are technical in what we build but operational in how we do our work, and we partner deeply with Product, Security, Legal, Privacy, GTM, and Field Security to help OpenAI move quickly while maintaining trust with customers, auditors, regulators, and the public. About the Role We are looking for an experienced Product Lifecycle Assurance IC to help scale OpenAI’s GRC function across our product stack to ensure products address customer and regulatory compliance requirements at launch and regressions are detected promptly and corrected. You will partner closely with Product, Security, Legal, and Privacy teams to make sure OpenAI can move quickly while maintaining our security, privacy and compliance claims and giving customers, auditors, and regulators assurance about how OpenAI handles user data. You are responsible for product assurance end-to-end from inception to post-launch (continuous) monitoring. You leverage existing workflows, reviews, and data and enhance, augment and build the components needed to create an end-to-end product assurance program. This role is not about supporting SOC or ISO audits; it's a highly cross-functional and deeply technical operations role to ensure that OAI products meet the compliance bar at launch, regressions are prevented and detected, and our compliance state can be evidenced. This role also helps ensure that our product launch governance program operates effectively across key safety, privacy, legal and security stakeholders and lessons-learned from incidents and regressions are used to improve the program. You or in partnership with engineering teams, build key controls in our infrastructure stack, developer workflows and launch tooling to provide developers with guardrails, perform CI/CD confor
About the Team The SaaS and Software Governance team sits within Corporate IT and helps OpenAI scale from startup-speed tooling to mature enterprise architecture. The team owns practical governance for software, SaaS, integrations, APIs, identity, data access, and agent-enabled workflows, with a mandate to improve security, reduce software sprawl, and help business teams move faster through better foundations. About the Team OpenAI is scaling from an emerging, high-velocity startup into a mature enterprise operating model. The IT Software Architect will help shape the software, SaaS, Data integration, and agent-enabled architecture that lets the company move quickly while improving security, compliance, data quality, and customer, partner, and employee experience. This role is not a traditional ivory-tower architecture function. It is a hands-on governance and enablement role that partners with business teams, IT operations, Security, Procurement, Business Platforms, Applied teams and Data Engineering to guide software decisions, reduce unmanaged sprawl, and build reusable enterprise foundations. Why This Role Matters OpenAI’s software footprint is expanding rapidly across SaaS, internally built tools, agents, integrations, APIs, third-party platforms, and application systems that OpenAI. The company needs a stronger tools architecture layer that can help teams make good decisions early, avoid duplicate tools, govern sensitive data and identities, and identify where OpenAI should build instead of buy. The person in this role will help turn software governance from an approval checkpoint into an enterprise capability: a system that improves speed, reliability, security, and business outcomes. What You'll Do Own the target architecture for enterprise software, SaaS, integrations, APIs, and agent-enabled business systems across Corporate IT. Drive deprecation and consolidate targets for enterprise software. Build lightweight governance patterns that guide teams before
Other cities to consider
More places hiring for this role
Get new security consultant intern jobs in San Francisco, United States by email
Daily job updates · Unsubscribe anytime