OpenAI
Cyber Operations Strategist, Critical Harm Operations
Remote role where the employee must remain based in a particular country.
Canada only
Employer listed it 4 weeks ago · Added 5 days ago
Been open since 4 weeks ago, still being checked, but it has been live a while.
Salary
$140,000 to $188,000
Location
Canada only
Timezone
Not stated
Contract
Full-time
Experience
Mid
Category
Operations
Published by the employer
Remote flexibility
Work from home
This is a remote role, but the employee must be based in Canada. It is work from home rather than work from anywhere.
What the employer says
- Source listing states candidate location: "Ontario - Remote"
- Job description states: "US-based"
What Nomaders makes of it
- Payroll and tax are likely handled in that country only
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
About the Team
Critical Harm Operations sits within User Safety & Risk Operations and builds enforcement systems for Frontier Risk and Material Harm that are accurate, fast, defensible, and built to scale. The Cyber vertical turns policy into reviewer standards, calibrated judgment, quality systems, escalation paths, and automation guardrails.
About the Role
We are looking for a senior cybersecurity practitioner and operations strategist to raise the quality, scalability, and technical rigor of our Cyber Operations. You will combine hands-on cyber judgment with systems-level operating design: resolve the hardest dual-use questions, evolve SOPs, uplift reviewers and vendors, and build practical tools and automations.
This is a senior IC role. Success is not primarily cases closed; it is durable improvement in the operating model and the reviewers who run it.
This Toronto-based role is currently remote and is expected to transition to an in-office arrangement.
In this role, you will:
Drive the Cyber Operations operating model across domain priorities, SOPs, escalation paths, quality health, vendor capability, roadmap inputs and help inform trusted access strategies.
Serve as the senior cyber expert for complex or high-risk decisions across ChatGPT, API, Codex, agents, and emerging product surfaces.
Translate policy ambiguity, quality misses, appeals, and reviewer disagreement into clear decision rules, calibration examples, training, and tooling requirements.
Build durable operating systems and quality loops: golden sets, holdouts, double-labeling, adjudication, error taxonomies, reviewer calibration, and automation evaluations.
Raise FTE and BPO capability through onboarding, certification, coaching, recurring calibration, and vendor-performance partnership.
Use quality, appeals, SLA, backlog, and disagreement signals to diagnose root causes and prioritize high-leverage fixes.
Build hands-on solutions—SQL analyses, scripts, dashboards, LLM eval workflows, evidence enrichment, routing logic, and lightweight automations—that improve decision quality and reduce manual effort.
Partner with Policy, Integrity, Safety Systems, Security, Legal, Product, Engineering, and Investigations to operationalize changes and drive launch readiness.
You might thrive in this role if you have:
Have 8+ years of hands-on cybersecurity experience in offensive security, threat intelligence, incident response, security research, red teaming, application security, DFIR, malware analysis, or a related field.
Can reason deeply about attacker tradecraft, vulnerability exploitation, credential abuse, malware, persistence, evasion, exfiltration, cloud or identity abuse, and ambiguous dual-use activity.
Have built or improved high-stakes operations, reviewer programs, QA systems, escalation workflows, or vendor/BPO programs.
Can turn complex cyber and policy judgment into reviewer-usable SOPs, decision trees, training, and concise written recommendations.
Are comfortable using SQL, Python, Python, C/C++, JavaScript, PowerShell, and Bash, APIs, LLM tooling, or automation to solve operational problems.
Understand human-in-the-loop automation, evaluations, monitoring, holdouts, and fallback paths for sensitive workflows.
Operate independently in ambiguity, communicate clearly across technical and non-technical audiences, and bring sound judgment and discretion when handling sensitive material.
Experience with trust and safety, platform abuse, cyber misuse of AI systems, or LLM safety.
Requirements
- ·Have 8+ years of hands-on cybersecurity experience in offensive security, threat intelligence, incident response, security research, red teaming, application security, DFIR, malware analysis, or a related field.
- ·Can reason deeply about attacker tradecraft, vulnerability exploitation, credential abuse, malware, persistence, evasion, exfiltration, cloud or identity abuse, and ambiguous dual-use activity.
- ·Have built or improved high-stakes operations, reviewer programs, QA systems, escalation workflows, or vendor/BPO programs.
- ·Can turn complex cyber and policy judgment into reviewer-usable SOPs, decision trees, training, and concise written recommendations.
- ·Are comfortable using SQL, Python, Python, C/C++, JavaScript, PowerShell, and Bash, APIs, LLM tooling, or automation to solve operational problems.
Benefits
No benefits package published with this listing. Ask about it at first interview.
How to apply
- 1Check the flexibility label above, work from home, matches where you plan to live and work.
- 2Tailor your CV to the role at OpenAI, mentioning your remote working experience.
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 5d ago. Last checked 23 Sept. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open operations roles with comparable remote rules.
Free to apply, no account needed.
$140,000 to $188,000 · You'll be taken to the employer's careers page.