Product Manager, Codex Security Controls & Partner Interfaces
WFA Digital Insight
The Product Manager role at Openai stands out due to its focus on building native security controls for Codex and defining partner interfaces. This position requires a deeply technical individual who can work closely with various teams to develop controls for identity, permissions, and access. The role's emphasis on making Codex secure by default, governable by enterprises, and interoperable with security products is a unique challenge that requires a mix of technical expertise and collaborative skills.
Job Description
ABOUT THE TEAM OpenAI’s Cyber team works to make frontier AI safe, trusted, and transformative for developers and enterprises. This team is building the security foundation for Codex: the native controls that govern what Codex can access and do, and the interfaces that allow customers and security partners to inspect, constrain, approve, and respond to Codex activity. Our goal is to make Codex secure by default, governable by enterprises, and interoperable with the security products customers already trust. This extends the existing product direction around tenant-scoped tools, guarded actions, approval systems, and scalable partner interfaces. ABOUT THE ROLE We are looking for a deeply technical Product Manager to help build Codex security controls and the partner ecosystem around them. This role focuses on securing Codex itself: how identity, permissions, tools, MCP servers, repositories, secrets, networks, and high-impact actions are governed across Codex products. You will also help define standard interfaces through which authorized customer and partner systems can provide security context, inspect activity, return policy decisions, receive telemetry, and initiate bounded responses. You will work closely with Codex product and engineering, OpenAI Security and Safety, enterprise customers, and partners across application security, identity, cloud security, data security, infrastructure, and security operations. IN THIS ROLE YOU WILL Build native security controls for Codex Partner with engineering, design, security, and safety teams to develop controls for: - Identity, roles, permissions, and tenant isolation.
- Access to repositories, files, tools, MCP servers, secrets, networks, and infrastructure.
- Read, write, execute, and deployment authority.
- Human and policy-based approvals.
- Prompt-injection and untrusted-content defenses.
- Audit trails, provenance, stop conditions, revocation, and rollback.
- Inspecting code, commands, artifacts, tool calls, or planned actions.
- Returning allow, deny, constrain, or require-approval decisions.
- Exporting normalized execution and security telemetry.
- Pausing activity, revoking access, or requiring reauthorization.
- Approved security providers and permitted data sharing.
- Approval requirements and time-limited exceptions.
- Policy inheritance and conflict resolution.
- Audit, investigation, and incident-response workflows.
- Understand identity, authorization, sandboxing, secrets, tool use, APIs, and audit systems.
- Think naturally in terms of trust boundaries, failure modes, and abuse paths.
- Can balance security, developer productivity, latency, reliability, and customer control.
- Have experience building integrations across complex enterprise systems or partner ecosystems.
- Can turn conflicting partner requirements into a coherent platform.
- Communicate credibly with developers, security architects, CISOs, researchers, and partner product teams.
- Prefer measurable security outcomes and real adoption over demonstrations or integration announcements.
- Familiarity with RBAC, ABAC, policy-as-code, OAuth, OIDC, workload identity, or secrets management.
- Experience with AI agents, MCP, sandboxed execution, prompt-injection defenses, or agent-security evaluations.
- Experience building SDKs, developer platforms, integration marketplaces, or certification programs.
- A common architecture for security context, policy decisions, inspection, telemetry, and response.
- Initial reference integrations with a focused group of partners.
- Evaluation and launch criteria for high-risk Codex capabilities.
- Baseline measures for control coverage, bypass resistance, latency, reliability, and developer experience.
How to Stand Out
- tip: To stand out in this role, highlight your technical expertise in software development, security, and collaboration with cross-functional teams.
- tip: Be prepared to provide specific examples of building native security controls and defining partner interfaces in your previous experience.
- tip: Emphasize your ability to work closely with engineering, design, security, and safety teams to develop controls for identity, permissions, and access.
- tip: Make sure to review the job description and requirements carefully, and be prepared to ask questions during the interview process.
- tip: Consider creating a portfolio or examples of your work to demonstrate your technical skills and experience.
- tip: Be prepared to discuss your experience with security principles, including identity, permissions, and access control, and how you have applied them in previous roles.
- tip: Research the company culture and values, and be prepared to discuss how you align with them and can contribute to the team's success.
This is a remote position listed on WFA Digital, the platform for professionals who work from anywhere. Browse more remote jobs across all categories.