About OpenReview:
OpenReview is a nonprofit that builds and operates open peer review infrastructure for the world's leading AI and machine learning conferences — NeurIPS, ICLR, ICML, CVPR, AAAI, and more than 4,700 other venues. Our platform manages submissions, reviews, and decisions for hundreds of thousands of researchers worldwide, built on an intentionally open API. Author and reviewer anonymity is the foundation of trust in peer review; protecting it is central to our mission of advancing science through open, rigorous, and fair evaluation.
The ideal candidate:
The ideal candidate has a passion for building the application security function of a mission-driven peer review platform used by the global research community. They are excited about wearing multiple hats and introducing security review processes into a small engineering team without slowing delivery to a halt. They have built production APIs themselves — a builder, not only an auditor — in addition to their application security experience, and they treat AI tooling as a daily working method for finding vulnerabilities before anyone else does. This is a remote position which can be based anywhere in the United States.
Job Summary:
The Platform Integrity Engineer is OpenReview's application security specialist: the role ensures that every change to the OpenReview API enforces the correct permissions on data access, protecting the anonymity guarantees at the heart of the peer review process. OpenReview operates an intentionally open API serving the global research community; its most sensitive asset is not the data itself but the authorization rules that determine who may see what, and when.
This role is the platform's dedicated security function: it reviews every authorization-relevant change before it ships, builds the automated testing that catches permission regressions, audits the platform's anonymity guarantees, safeguards the venue workflow configurations that define who may read what at each stage of peer review and operates the vulnerability disclosure and incident process.
Effective review requires a working command of the API's data model and permission semantics, and building that depth is the first priority of the role; as it deepens, the role is expected to also implement new API features. The role works in close partnership with the Engineering Lead, who implements the API features, and with the Cloud Infrastructure Engineer, with whom it shares security monitoring. AI tooling — LLM-based code analysis, adversarial test generation, AI-assisted penetration testing — is a core working method across all of these responsibilities. The role's scope covers all OpenReview repositories — the API, the web client, the Python client library, and supporting services — with the API as the primary focus, since that is where permission enforcement lives; fixes routinely require companion changes across repositories, and the role owns the security outcome across all of them.
Duties/Responsibilities:
1. Security Review & Secure Development
-
Serve as the required security reviewer, across all OpenReview repositories and with the API as first priority, for every change touching authorization-relevant paths — permission evaluation, query filtering, authentication, server-side automation, and file handling — at both the design stage and code review, with primary focus on authorization logic, object-level permission checks, and the protection of anonymous identities; apply AI-assisted code analysis to every pull request in scope. Define and maintain the trigger list for what requires security review, so that routine changes are not blocked.
-
For the authorization architecture, the edit validation and schema pipeline, and input handling at the data layer, ensure that every change is reviewed before release and that the practices that keep permission leaks out of production — code coverage requirements, mandatory code review, AI-assisted analysis of pull requests — are consistently applied and continuously improved.
-
Establish and maintain the secure development lifecycle for the API: threat modeling for new features, a security checklist embedded in the definition of done, and security training and guidance for the engineering team. Own and evolve the team's AI-assisted review tooling and static analysis configuration, and evaluate emerging AI security tools for integration into the review process and CI pipeline.
2. Testing & Auditing
-
Design, build, and maintain an automated regression test suite for access control, integrated into CI, that verifies the read and write permissions of every API endpoint against the intended policy — including AI-generated adversarial test cases — so that a missing permission check fails a build rather than reaching production.
-
Conduct periodic audits of endpoints that expose identity-adjacent data (profiles, search, activity), including AI-assisted penetration testing, verifying that no combination of queries can deanonymize reviewers, authors, or area chairs.
-
Venue workflows are configured through the Python client library, and because that configuration defines who may read what at each stage of the peer review process, a misconfiguration can leak information even when the API enforces permissions correctly. Review and audit venue workflow configurations, establish safe-by-default configuration patterns for common venue setups, and build automated checks — including AI-assisted analysis — that flag configurations granting broader visibility than intended.
3. Detection & Response
-
In close collaboration with the Cloud Infrastructure Engineer, define application-level detection and alerting for anomalous access patterns, particularly unusual querying of sensitive endpoints and anonymity-relevant data, so that incidents are detected by us rather than reported to us.
-
Own dependency vulnerability management and triage; publish and maintain the project's security policy and disclosure channel; triage external security reports, coordinate fixes with the engineering team, and lead the application-level analysis (scope determination, log review) during security incidents.
4. Feature Implementation (over time)
-
As command of the data model and permission semantics deepens, implement selected new API features under the Engineering Lead's direction.
Required Education and Experience:
-
Bachelor's degree in Computer Science or a related field, or equivalent practical experience.
-
8+ years of experience designing and building production web APIs in Node.js and/or Python, including ownership of authorization and data access design — reviewing this platform effectively requires a builder's understanding of APIs, not only an auditor's.
-
Deep expertise in authorization models and their implementation, including ACL-style models where permissions are carried on the data, role- and attribute-based access control, object-level permission checks, and centralized policy enforcement.
-
Strong command of the OWASP API Security Top 10, with demonstrated ability to identify and prevent broken object-level and function-level authorization.
-
Experience building automated tests for access control and integrating security checks into CI/CD pipelines.
-
Strong working knowledge of JSON Schema and schema-driven validation (AJV or equivalent), including schemas generated at runtime from user-defined configuration.
-
Hands-on experience applying AI/LLM tooling in engineering workflows (code analysis, test generation, or security review), and demonstrated interest in using AI to find vulnerabilities.
-
Experience introducing security review processes into a small engineering team without slowing delivery to a halt.
-
Strong written communication skills: able to explain risk and remediation clearly to engineers and to non-technical leadership.
Preferred Education and Experience:
-
Experience protecting anonymity or privacy guarantees in systems with intentionally public data.
-
Experience securing server-side execution of untrusted or semi-trusted code (sandboxing, isolation boundaries, capability restriction), ideally in Node.js.
-
Familiarity with OpenReview's stack: MongoDB (document-store data models), Elasticsearch, Redis, and Google Cloud Platform.
-
Experience running or triaging a vulnerability disclosure or bug bounty program.
-
Background in academic, scientific publishing, open-source, or nonprofit platform environments.
Travel required:
Travel twice per year for the in-person team strategic planning retreats.
Physical Requirements:
Prolonged periods of sitting at a desk and working on a computer.
Other duties:
Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice.
Compensation and Benefits:
OpenReview offers competitive benefits including paid holidays, unlimited PTO, and medical, dental and vision insurance.
The salary range is $145,000 – $200,000 per year.