About the company
OpenAIās mission is to ensure that general-purpose artificial intelligence benefits all of humanity. Our Communications team is composed of PR/Media Relations, Events, Design, and other external-facing functions. The teamās ethos is to support OpenAI's mission and goals by clearly and authentically explaining our technology, values, and approach to safely building powerful AI. The Events team is a dynamic group dedicated to crafting extraordinary experiences that encompass our company's values and mission. Our team is driven by a passion for bringing people together to connect in meaningful ways.
Job Summary
In this role, you will:
šPartner with engineering teams to implement and audit OpenAIās security controls across our products, infrastructure, and internal processes. šWork closely with the teams at OpenAI to shape controls and enable an agile approach to Risk Management across the organization. šDirectly facilitate operational, regulatory, and certification security requirements (e.g., SOC2, ISO, NIST 800-53, etc.) and manage audits to successful outcomes. šDesign and build automation for compliance and security controls. šDesign efficient organizational processes to enable compliance across the organization. šAlign across departments on the roadmaps for implementation of processes and controls.
You might thrive in this role if you have:
šExperience leading 3rd party compliance audits and control implementation (SOC2, ISO, HIPAA, NIST, etc.). šA robust understanding of security and privacy compliance and regulatory standards. šDeep understanding of cloud infrastructure and security concepts, including experience with managing compliance requirements against distributed consumer and enterprise applications. šExcellent project management skills, with a track record of having delivered on complex initiatives in a fast-moving environment. šA strong technical background, with prior experience as a security, software, or IT engineer as a bonus. šAbility to clearly distill compliance requirements into internal requirements for various teams including engineering, security, and legal. šAbility to empathize and collaborate with colleagues, independently manage and run projects, and prioritize efforts for risk reduction. šStrong attention to detail.