Researcher, Agent Safety, Oversight and System Mitigations
About the Team
The Agent Safety team works to ensure that increasingly capable AI agents act safely, exercise sound judgment, and remain aligned with user intent. Our mission is to reduce the probability of severe unintended outcomes from increasingly capable AI agents while preserving their ability to act effectively and autonomously.
Our work spans three areas:
- Training: Create training methods, environments and data that teach agents to make better decisions in consequential situations. We turn real-world failures into training signals that prevent similar incidents, and identify precursor behaviors and mitigations to address emerging risks.
- Measurements: Build evaluations and production metrics that identify emerging risks and measure whether our interventions work.
- Oversight: Develop oversight and system mitigation mechanisms that reduce harmful actions while preserving useful agent autonomy (for example future versions of https://alignment.openai.com/auto-review/).
About the Role
This role focuses on oversight and system-level mitigations that enable increasingly capable agents to operate safely and autonomously in real environments. We prioritize building oversight systems that are used in practice today, both internally and externally (see our recent work on action monitoring for codex https://alignment.openai.com/auto-review/ and former code review https://alignment.openai.com/scaling-code-verification/). We also study longer-term questions about how increasingly capable agentis systems can be supervised, constrained, and corrected.
We’re looking for a safety&security minded researcher or engineer who can reason rigorously about security boundaries and agent behavior, then build and test practical mitigations. A background in AI control or security is welcome but not required.
This role is based in San Francisco, CA. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees.
In this role, you will:
- Design, build, and evaluate system-level controls for agent actions like agent-based review. Plan how they fit in a broader system including sandboxing with process isolation and permission boundaries.
- Work closely with a Codex harness engineering team to productionize the AI controls.
- Red-team end-to-end agentic systems to measure whether controls prevent data exfiltration, unsafe tool use, and other harmful outcomes.
- Improve the safety–productivity tradeoff by measuring and reducing missed harmful actions, unnecessary blocks, approval burden, and latency.
You might thrive in this role if you:
- Have strong systems or security instincts and can reason concretely about isolation boundaries, permissions, attack surfaces, and failure modes in complex systems.
- Enjoy turning ambiguous safety questions into concrete threat models, reproducible experiments, and practical mitigations, and revising your approach based on evidence from deployment.
- Can build robust experimental infrastructure and design evaluations that distinguish promising mitigations from brittle ones.
- Are deeply interested in frontier AI alignment, safety and control.