Jobs › California › San Francisco Bay Area › Cybersecurity & Technology Audit Leader
Cybersecurity & Technology Audit Leader
OpenAI is hiring for the role of Cybersecurity & Technology Audit Leader, San Francisco, CA (On-site). This is an Audit role in the governance, risk, and compliance field. Review the full details below and apply directly with OpenAI.
About the Team
The OpenAI Audit Team is on a mission to build the future of internal audit from the ground up. Our ambition will be powered by a high-energy, technically exceptional team with the judgment, intellectual curiosity, and creativity to harness the latest advances in AI and design a truly next-generation audit function.
As AI reshapes how work is performed across the enterprise, Internal Audit will use AI, automation, and data analytics to identify and assess the most significant and emerging risks across the business, including technology, cybersecurity, finance, compliance, operations, and data.
We will build trusted partnerships at every level—from the Board of Directors and senior leadership to the teams delivering on OpenAI’s mission every day. We will operate as both an independent assurance provider and a trusted advisor, bringing an objective and pragmatic perspective to critical decisions. By engaging closely with management while preserving our independence, we will help the business innovate responsibly, move with confidence, and manage risk without creating unnecessary barriers.
About the Role
As the Cybersecurity & Technology Audit Leader, you will help shape the strategy, methodology, technology, and culture of a new audit function. You will lead complex audits and advisory reviews of cybersecurity, technology, data, and AI-related risks while advising leaders on practical ways to strengthen governance, resilience, and risk management.
You are an experienced, hands-on professional who combines deep technical expertise with strong business judgment. You can quickly move between executive-level governance questions and detailed technical analysis, use data to identify and assess risk, and form clear, well-supported conclusions in fast-moving or ambiguous situations.
You will have meaningful influence over how the function develops, including how we apply AI, automation, and analytics to audit planning, testing, monitoring, and reporting. This is an opportunity to help build a state-of-the-art capability rather than inherit a traditional audit model.
This role is based in San Francisco, CA. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees.
In this role, you will:
- Build and execute a risk-based audit and advisory strategy across cybersecurity, infrastructure, systems architecture, cloud environments, data, software development, change management, operational resilience, and AI.
- Drive strong governance and oversight of critical technology programs and emerging AI risks, including model governance, data provenance and quality, privacy, security, responsible AI, third-party dependencies, monitoring, and human oversight.
- Assess complex technical environments and control effectiveness across areas—such as architecture, access models, system logs, code repositories, cloud controls, vulnerability data, and security monitoring—with a focus on distinguishing material risks from lower-value compliance issues.
- Translate complex technical findings into clear business implications and practical recommendations that enable innovation while supporting effective risk management.
- Build advanced audit capabilities using data analytics, automation, and AI to improve risk assessment, audit scoping, testing, continuous monitoring, and reporting, including identifying anomalies, control weaknesses, and emerging risks.
- Build trusted relationships across the organization and support clear, effective reporting to executive management, regulators, and the Board.
- Monitor developments in technology, threat activity, regulation, and industry practices to keep the audit approach current and forward-looking.
- Coach colleagues, share technical expertise, and contribute to a culture of high standards, sound judgment, curiosity, ownership, and continuous learning.
You might thrive in this role if you have:
- 12-15+ years of relevant experience in cybersecurity, technology audit, technology risk, security engineering, data risk, cloud security, or a related field.
- Strong technical expertise across several areas, such as cloud platforms, identity and access management, application security, infrastructure, networks, vulnerability management, incident response, security operations, data platforms, or software development.
- Strong knowledge of data architecture, provenance, lineage, quality, governance, access, and analytics, includ
Location and market context
This role is based in San Francisco on-site. Local candidates benefit from being close to OpenAI's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.
About internal audit roles
Internal audit gives independent assurance over controls and risk. Technology, data, and AI audit skills are in rising demand as programs modernize. Roles like this one are typically evaluated against frameworks such as IIA standards, COSO, NIST AI RMF, and IT and data audit practices.
How to position yourself for this internal audit role
Strong candidates emphasize risk-based audit planning, control testing and evidence, clear findings and remediation tracking, and technology, data, or AI audit depth. In your resume and outreach, tie your experience to how OpenAI would apply IIA standards, COSO, NIST AI RMF, and IT and data audit practices, and lead with concrete outcomes rather than duties.
Similar GRC roles
- Internal Audit Manager · Lyft · San Francisco, CA
- Chief Audit Officer · Mercury · San Francisco, CA, New York · Remote
- Data Governance Lead · Reflection AI · San Francisco, CA
- Security Compliance Analyst, Privacy · LangChain · San Francisco, CA
- Governance, Risk & Compliance · Runway · San Francisco, CA, WA
- Tech Governance - Security Compliance Engineer · OKX · San Francisco, CA
Want to be next in a role like this?
Roles like Cybersecurity & Technology Audit Leader in San Francisco, CA open regularly. Be first to know — privately. No current employer ever sees you looking.
Employer, or see something wrong with this posting? Report this posting and we will review it promptly.