Product Manager, Codex Security Controls & Partner Interfaces
Posted bythe hiring team· about 9 hours ago
Posted bythe hiring team· about 9 hours ago
Product Manager, Codex Security Controls & Partner Interfaces
USD 293,000 – USD 385,000
Top 7% in Product
Be among the first applicants
Verified team
HR-vetted before going live.
Transparent pay
Salary stated upfront.
Be among the first applicants
Just opened — your application stands out.
About this role
the company Cyber team works to make frontier AI safe, trusted, and transformative for developers and enterprises.
This team is building the security foundation for Codex: the native controls that govern what Codex can access and do, and the interfaces that allow customers and security partners to inspect, constrain, approve, and respond to Codex activity.
Our goal is to make Codex secure by default, governable by enterprises, and interoperable with the security products customers already trust. This extends the existing product direction around tenant-scoped tools, guarded actions, approval systems, and scalable partner interfaces.
We are looking for a deeply technical Product Manager to help build Codex security controls and the partner ecosystem around them.
This role focuses on securing Codex itself: how identity, permissions, tools, MCP servers, repositories, secrets, networks, and high-impact actions are governed across Codex products.
You will also help define standard interfaces through which authorized customer and partner systems can provide security context, inspect activity, return policy decisions, receive telemetry, and initiate bounded responses.
You will work closely with Codex product and engineering, the company Security and Safety, enterprise customers, and partners across application security, identity, cloud security, data security, infrastructure, and security operations.
Build native security controls for Codex
Partner with engineering, design, security, and safety teams to develop controls for:
Identity, roles, permissions, and tenant isolation.
Access to repositories, files, tools, MCP servers, secrets, networks, and infrastructure.
Read, write, execute, and deployment authority.
Human and policy-based approvals.
Prompt-injection and untrusted-content defenses.
Audit trails, provenance, stop conditions, revocation, and rollback.
Help establish a graduated authority model in which local, read-only, and reversible actions require less friction than actions involving production systems, credentials, sensitive data, or irreversible changes.
Define partner interfaces
Develop common, versioned interfaces that allow customer-selected security products to participate in Codex workflows.
These interfaces may support:
Sharing trusted identity, task, resource, and environment context.
Inspecting code, commands, artifacts, tool calls, or planned actions.
Returning allow, deny, constrain, or require-approval decisions.
Exporting normalized execution and security telemetry.
Pausing activity, revoking access, or requiring reauthorization.
Define clear requirements for authentication, authorization, customer consent, data minimization, latency, retries, failure behavior, auditability, and backwards compatibility.
Ensure integrations use shared platform contracts rather than creating a different Codex architecture for every partner.
Build the partner ecosystem
Work directly with security vendors and enterprise design partners to turn the interfaces into production integrations.
Create partner SDKs, reference implementations, technical documentation, test environments, conformance suites, and certification requirements.
Prioritize partners based on customer value, technical relevance, deployment readiness, and their ability to improve the shared platform—not simply logo value or launch timing.
Turn lessons from individual partner engagements into reusable product capabilities.
Shape the customer experience
Define how enterprise administrators configure and understand Codex security controls, including:
Policies by user, workspace, repository, environment, tool, or action.
Approved security providers and permitted data sharing.
Approval requirements and time-limited exceptions.
Policy inheritance and conflict resolution.
Audit, investigation, and incident-response workflows.
Ensure developers receive clear, actionable explanations when an action is blocked or requires approval, rather than an opaque policy error.
Establish evaluation and launch gates
Work with security, safety, research, and engineering teams to test whether controls work under realistic and adversarial conditions.
Evaluate risks such as permission bypass, prompt injection, malicious tools, secret exposure, cross-tenant access, stale authorization, partner outages, conflicting decisions, and incomplete audit evidence.
Help determine when new Codex capabilities have sufficient controls, reliability, and usability for broader deployment.
Have built enterprise security, developer-platform, infrastructure, or control-plane products.
Understand identity, authorization, sandboxing, secrets, tool use, APIs, and audit systems.
Think naturally in terms of trust boundaries, failure modes, and abuse paths.
Can balance security, developer productivity, latency, reliability, and customer control.
Have experience building integrations across complex enterprise systems or partner ecosystems.
Can turn conflicting partner requirements into a coherent platform.
Communicate credibly with developers, security architects, CISOs, researchers, and partner product teams.
Prefer measurable security outcomes and real adoption over demonstrations or integration announcements.
Experience in application security, identity, cloud security, data security, source control, CI/CD, SIEM, or enterprise governance.
Familiarity with RBAC, ABAC, policy-as-code, OAuth, OIDC, workload identity, or secrets management.
Experience with AI agents, MCP, sandboxed execution, prompt-injection defenses, or agent-security evaluations.
Experience building SDKs, developer platforms, integration marketplaces, or certification programs.
During your first six months, you will have helped establish:
A clear roadmap for native Codex controls and partner-extensible controls.
A common architecture for security context, policy decisions, inspection, telemetry, and response.
Initial reference integrations with a focused group of partners.
Evaluation and launch criteria for high-risk Codex capabilities.
Baseline measures for control coverage, bypass resistance, latency, reliability, and developer experience.
During your first year, you will have helped ship meaningful controls across sensitive Codex workflows, brought standardized partner interfaces into production use, and demonstrated that enterprises can grant Codex greater authority without sacrificing visibility, control, or accountability.
About the company
the company is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.
We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic.
For additional information, please see this form. No response will be provided to inquiries unrelated to job posting compliance.
We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link.
The Product Manager, Codex Security Controls & Partner Interfaces role with the hiring team offers USD 293,000–385,000 per year. Salary information is published as part of every JobRemotely listing so candidates can self-screen before applying.
Yes — the hiring team has marked this Product Manager, Codex Security Controls & Partner Interfaces role as open to candidates based in United States. Eligibility requirements are surfaced in the JobPosting structured data on the listing.
The hiring team uses the JobRemotely structured hiring pipeline: candidates apply through the listing, complete a paid test task or screening, and only then proceed to interviews. This skips the resume black hole and respects everyone's time.
Similar roles
Hand-picked from the same category.
the hiring team· Poland·Remote·about 7 hours ago
USD 70,832 – USD 75,892
Viewthe hiring team· US·Remote·about 9 hours ago
USD 130,000 – USD 148,000
Viewthe hiring team· US·Remote·about 9 hours ago
USD 190,800 – USD 262,800
Viewthe hiring team· US·Remote·about 9 hours ago
USD 199,200 – USD 355,200
ViewJob ads say a lot about where engineering is going — if you read enough of them. We went through all 335 remote engineering roles on our board, every one with a published salary, and counted what they actually ask for.