{"version":"0.1","company":{"name":"YubHub","url":"https://yubhub.co","jobsUrl":"https://yubhub.co/jobs/skill/control-validation"},"x-facet":{"type":"skill","slug":"control-validation","display":"Control Validation","count":2},"x-feed-size-limit":100,"x-feed-sort":"enriched_at desc","x-feed-notice":"This feed contains at most 100 jobs (the most recently enriched). For the full corpus, use the paginated /stats/by-facet endpoint or /search.","x-generator":"yubhub-xml-generator","x-rights":"Free to redistribute with attribution: \"Data by YubHub (https://yubhub.co)\"","x-schema":"Each entry in `jobs` follows https://schema.org/JobPosting. YubHub-native raw fields carry `x-` prefix.","jobs":[{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_b4f6be8b-270"},"title":"Data Center Security Engineer","description":"<p><strong>Compensation</strong></p>\n<ul>\n<li>San Francisco, Seattle or NYC $293K – $385K • Offers Equity</li>\n<li>Zone A $263.7K – $346.5K • Offers Equity</li>\n<li>Zone B $234.4K – $308K • Offers Equity</li>\n</ul>\n<p>The base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. If the role is non-exempt, overtime pay will be provided consistent with applicable laws. In addition to the salary range listed above, total compensation also includes generous equity, performance-related bonus(es) for eligible employees, and the following benefits.</p>\n<ul>\n<li>Medical, dental, and vision insurance for you and your family, with employer contributions to Health Savings Accounts</li>\n</ul>\n<ul>\n<li>Pre-tax accounts for Health FSA, Dependent Care FSA, and commuter expenses (parking and transit)</li>\n</ul>\n<ul>\n<li>401(k) retirement plan with employer match</li>\n</ul>\n<ul>\n<li>Paid parental leave (up to 24 weeks for birth parents and 20 weeks for non-birthing parents), plus paid medical and caregiver leave (up to 8 weeks)</li>\n</ul>\n<ul>\n<li>Paid time off: flexible PTO for exempt employees and up to 15 days annually for non-exempt employees</li>\n</ul>\n<ul>\n<li>13+ paid company holidays, and multiple paid coordinated company office closures throughout the year for focus and recharge, plus paid sick or safe time (1 hour per 30 hours worked, or more, as required by applicable state or local law)</li>\n</ul>\n<ul>\n<li>Mental health and wellness support</li>\n</ul>\n<ul>\n<li>Employer-paid basic life and disability coverage</li>\n</ul>\n<ul>\n<li>Annual learning and development stipend to fuel your professional growth</li>\n</ul>\n<ul>\n<li>Daily meals in our offices, and meal delivery credits as eligible</li>\n</ul>\n<ul>\n<li>Relocation support for eligible employees</li>\n</ul>\n<ul>\n<li>Additional taxable fringe benefits, such as charitable donation matching and wellness stipends, may also be provided.</li>\n</ul>\n<p>More details about our benefits are available to candidates during the hiring process.</p>\n<p>This role is at-will and OpenAI reserves the right to modify base pay and other compensation components at any time based on individual performance, team or company results, or market conditions.</p>\n<p><strong>About the Team</strong></p>\n<p>Security is foundational to OpenAI’s mission of ensuring that artificial general intelligence benefits all of humanity. As OpenAI builds and operates increasingly powerful systems, security helps make that progress durable, trustworthy, and resilient.</p>\n<p>The Security team protects OpenAI’s technology, people, and products, but our role goes beyond defense alone. We help enable the infrastructure, research, and product work that powers frontier AI, bringing deep technical judgment and hands-on operational execution to some of the most important systems being built today. Our work is grounded in impact, pragmatism, and preparing for the security challenges that come with increasingly capable technology.</p>\n<p><strong>About the Role</strong></p>\n<p>We are seeking an experienced and highly technical Data Center Security Engineer to help secure the infrastructure behind OpenAI’s rapidly expanding data center footprint. This is a chance to work on high-consequence systems at the intersection of cybersecurity, critical infrastructure, and advanced AI, where strong technical judgment and careful execution have direct, lasting impact.</p>\n<p>In this role, you will operate with substantial agency and ownership alongside a small team of data center security experts, driving security architecture, control validation, and defensive improvements across multiple, diverse environments, with particular emphasis on IT, Enterprise, ICS and Operational Technology (OT) networking. You will help define and raise the security bar for infrastructure programs already in flight while shaping how future deployments are secured from the start.</p>\n<p>This role&#39;s preferred location is one of our OpenAI offices in San Francisco, Seattle, or New York City and relocation assistance is available. We are also open to considering candidates who are remote.</p>\n<p><strong>In this role, you will:</strong></p>\n<ul>\n<li>Design and implement security controls that protect data center infrastructure across a growing global footprint, with particular focus on both OT and IT networking environments.</li>\n</ul>\n<ul>\n<li>Partner closely with a small team of data center security specialists, as well as engineering, operations, and broader security teams, to deliver resilient and practical security outcomes.</li>\n</ul>\n<ul>\n<li>Secure OT and IT networking environments through strong segmentation, access control, monitoring, hardening, and connectivity patterns suited to critical infrastructure.</li>\n</ul>\n<ul>\n<li>Contribute to security architecture and design reviews for data center systems, including OT and IT networking, network segmentation, identity and access management, provisioning workflows, hardware and firmware trust boundaries, and operational safeguards.</li>\n</ul>\n<ul>\n<li>Perform recurring audits, control assessments, and validation activities across OT and IT networking environments to ensure continued compliance against defined controls.</li>\n</ul>\n<ul>\n<li>Drive ongoing evidence collection, gap tracking, and remediation follow-through so control deficiencies are identified quickly and closed durably.</li>\n</ul>\n<ul>\n<li>Help define measurable security standards, control objectives, audit procedures, evidence requirements, and validation mechanisms for infrastructure and facility security programs.</li>\n</ul>\n<ul>\n<li>Support security monitoring, incident response, and post-incident improvement efforts for data center, OT, and IT networking environments.</li>\n</ul>\n<ul>\n<li>Work with suppliers, partners, and internal stakeholders to evaluate and reduce risks associated with third-party hardware, firmware, software, and operational dependencies.</li>\n</ul>\n<ul>\n<li>Continually evolve the security of our data centers alongside changes in adversary activity, infrastructure complexity, and the increasing demands of OpenAI’s systems.</li>\n</ul>\n<p><strong>You might thrive in this role if you have:</strong></p>\n<ul>\n<li>15+ years of experience in security, including meaningful hands-on experience securing large-scale infrastructure, industrial environments, or data center systems.</li>\n</ul>\n<ul>\n<li>Deep expertise securing OT and IT networking environments in critical infrastructure settings, including segmentation strategies, remote access controls, asset visibility, and compensating controls for operational constraints.</li>\n</ul>\n<ul>\n<li>Experience building audit or assurance programs that validate ongoing compliance with defined security controls, especially across OT and IT networking environments, rather than relying on one-time point-in-time reviews.</li>\n</ul>\n<ul>\n<li>Strong cross-functional collaboration skills including the ability to partner effectively with internal and external stakeholders while operating with a high degree of autonomy.</li>\n</ul>\n<ul>\n<li>Strong knowledge of security engineering and operations across network security, IAM and PAM, hardening, provisioning, monitoring, incident response, and secure lifecycle practices.</li>\n</ul>\n<ul>\n<li>Experience protecting hyperscale, colocation, or hybrid infrastructure environments against sophisticated adversaries.</li>\n</ul>\n<ul>\n<li>Familiarity with control and governance frameworks such as NIST, ISO 27001, or SOC 2, and the ability to translate them into concrete technical and operational requirements.</li>\n</ul>\n<ul>\n<li>The ability to operate as a high-ownership individual contributor who influences through technical judgment, collaboration, and execution.</li>\n</ul>\n<ul>\n<li>Clear written and verbal communication skills, including the ability to explain risk, controls, and tradeoffs to both technical and non-technical partners.</li>\n</ul>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_b4f6be8b-270","directApply":true,"hiringOrganization":{"@type":"Organization","name":"OpenAI","sameAs":"https://openai.com.examle.com","logo":"https://logos.yubhub.co/openai.com.examle.com.png"},"x-apply-url":"https://jobs.ashbyhq.com/openai/34d2c085-c86f-41b7-8ca2-7964161c876d","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"Full time","x-salary-range":"$293K – $385K","x-skills-required":["security","data center","networking","cybersecurity","critical infrastructure","advanced AI","security architecture","control validation","defensive improvements","OT and IT networking environments","segmentation","access control","monitoring","hardening","connectivity patterns","identity and access management","provisioning workflows","hardware and firmware trust boundaries","operational safeguards","audits","control assessments","validation activities","compliance","evidence collection","gap tracking","remediation","security standards","control objectives","audit procedures","evidence requirements","validation mechanisms","infrastructure and facility security programs","security monitoring","incident response","post-incident improvement","third-party hardware","firmware","software","operational dependencies","adversary activity","infrastructure complexity","increasing demands"],"x-skills-preferred":[],"datePosted":"2026-04-24T12:23:29.659Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"San Francisco; New York City; Remote - US; Seattle"}},"jobLocationType":"TELECOMMUTE","employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"security, data center, networking, cybersecurity, critical infrastructure, advanced AI, security architecture, control validation, defensive improvements, OT and IT networking environments, segmentation, access control, monitoring, hardening, connectivity patterns, identity and access management, provisioning workflows, hardware and firmware trust boundaries, operational safeguards, audits, control assessments, validation activities, compliance, evidence collection, gap tracking, remediation, security standards, control objectives, audit procedures, evidence requirements, validation mechanisms, infrastructure and facility security programs, security monitoring, incident response, post-incident improvement, third-party hardware, firmware, software, operational dependencies, adversary activity, infrastructure complexity, increasing demands","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":293000,"maxValue":385000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_3ad8987a-19b"},"title":"Staff Compliance Analyst - Federal","description":"<p>We are looking for a Staff Federal Security Compliance Analyst to join our Federal Security and Compliance team. As a Staff Federal Security Compliance Analyst, you will serve as a lead of our compliance strategy, safeguarding and strengthening our position as a leading IDaaS provider for the public sector. Your mission is to bridge the gap between engineering, product, and federal regulatory bodies, driving the maintenance of our FedRAMP and DoD authorizations, leading complex audits, and mentoring junior analysts to ensure a security-first culture.</p>\n<p>The responsibilities listed below represent the core functions of this role:</p>\n<ul>\n<li>Strategic Audit Leadership: Lead end-to-end FedRAMP and DoD audits, serving as the primary point of contact for external 3PAOs and government agencies.</li>\n<li>Continuous Monitoring Strategy: Oversee and evolve the continuous monitoring (ConMon) program. Design sophisticated reporting mechanisms for vulnerability management and risk posture for executive leadership.</li>\n<li>Engineering Advisory: Act as a senior consultant to Engineering and Product teams, translating complex NIST 800-53 requirements into actionable technical specifications for cloud-native environments.</li>\n<li>Impact Assessment &amp; Risk Management: Lead the assessment of high-impact changes to federal systems. Ensure that system evolutions maintain a rigorous security posture without sacrificing innovation.</li>\n<li>Cross-Functional Alignment: Drive synchronization between GRC, Security, Marketing, Sales, Engineering, and Product to ensure federal requirements are integrated into the broader corporate roadmap.</li>\n<li>Programmatic Gap Analysis: Proactively identify and lead initiatives to close gaps between current capabilities and future regulatory requirements (e.g., emerging NIST standards, new DoD mandates, or IL6 requirements).</li>\n<li>Evidence Automation &amp; FedRAMP 20x Readiness: Drive the build-out and support of automated evidence collection and control validation. Lead the transition toward &quot;FedRAMP 2.0&quot; standards (including OSCAL integration), defining and monitoring Key Security Indicators (KSIs) to provide real-time compliance visibility.</li>\n</ul>\n<p>Minimum Required Knowledge, Skills, and Abilities:</p>\n<ul>\n<li>Education: Bachelor’s degree in Computer Science, MIS, Cybersecurity, or a related technical field.</li>\n<li>Experience: 7+ years of experience in security compliance, with at least 4-5 years specifically focused on the FedRAMP/NIST 800-53 framework.</li>\n<li>Automation &amp; Compliance Engineering: Demonstrated experience with automation tools or scripting (e.g., Python, Go, or SQL) for automated evidence collection. Familiarity with API-based control validation and OSCAL-based tooling (e.g., Trestle, LULA, or similar GRC automation frameworks).</li>\n<li>Technical Depth: Deep understanding of cloud-native infrastructure (IaaS, PaaS, SaaS) and how infrastructure components (networking, OS, databases) support a distributed cloud application.</li>\n<li>Framework Mastery: Expert-level knowledge of NIST SP 800-53, FedRAMP High/Moderate, and DoD SRG (IL4, IL5, and familiarity with IL6).</li>\n<li>Operational Knowledge: Proven experience with access management, CI/CD pipelines, disaster recovery, and encryption/key management in a cloud context.</li>\n<li>Analytical Leadership: Ability to analyze complex &quot;edge-case&quot; security scenarios and provide remediation paths that align with both business goals and regulatory requirements.</li>\n<li>Communication: Exceptional presentation skills with the ability to explain technical compliance risks to non-technical executive stakeholders.</li>\n</ul>\n<p>Preferred Certifications &amp; Skills:</p>\n<ul>\n<li>Advanced Certifications: CISSP (highly preferred), CISA, or CCSK.</li>\n<li>Cloud Expertise: AWS Certified Solutions Architect or Cloud Practitioner.</li>\n<li>Tooling: Expert-level proficiency with JIRA, ServiceNow, and Okta.</li>\n<li>Technical Background: Prior experience in a DevOps, Security Engineering, or Systems Administration role is a significant plus.</li>\n</ul>\n<p>Additional requirements:</p>\n<ul>\n<li>This position requires the ability to access federal environments and/or have access to protected federal data. As a condition of employment for this position, the successful candidate must be able to submit documentation establishing U.S. Person status (e.g. a U.S. Citizen, National, Lawful Permanent Resident, Refugee, or Asylee. 22 CFR 120.15) upon hire.</li>\n</ul>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_3ad8987a-19b","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Okta","sameAs":"https://www.okta.com/","logo":"https://logos.yubhub.co/okta.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/okta/jobs/7571077","x-work-arrangement":"remote","x-experience-level":"staff","x-job-type":"full-time","x-salary-range":"$161,000-$221,000 USD","x-skills-required":["Automation & Compliance Engineering","Cloud-native infrastructure","API-based control validation","OSCAL-based tooling","NIST SP 800-53","FedRAMP High/Moderate","DoD SRG (IL4, IL5)","Access management","CI/CD pipelines","Disaster recovery","Encryption/key management"],"x-skills-preferred":["CISSP","CISA","CCSK","AWS Certified Solutions Architect","Cloud Practitioner","JIRA","ServiceNow","Okta"],"datePosted":"2026-04-18T15:45:27.832Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Washington, DC"}},"jobLocationType":"TELECOMMUTE","employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Automation & Compliance Engineering, Cloud-native infrastructure, API-based control validation, OSCAL-based tooling, NIST SP 800-53, FedRAMP High/Moderate, DoD SRG (IL4, IL5), Access management, CI/CD pipelines, Disaster recovery, Encryption/key management, CISSP, CISA, CCSK, AWS Certified Solutions Architect, Cloud Practitioner, JIRA, ServiceNow, Okta","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":161000,"maxValue":221000,"unitText":"YEAR"}}}]}