Chief Information Security Officer

Reposted 17 Days Ago
Be an Early Applicant
Berkeley, CA, USA
In-Office
493K-579K Annually
Expert/Leader
Artificial Intelligence • Machine Learning • Security
The Role
Lead METR’s organizational security function, advise leadership on security risks, set the security roadmap, build security culture, and manage security engineers and contractors. Responsibilities include incident response, infrastructure hardening, red teaming, threat modeling, partnership security requirements, and hands-on investigation of IAM, sandboxing, identity, and endpoint security. The role may also involve securing AI/ML systems and agent infrastructure.
Summary Generated by Built In
[Due to capacity constraints, we may be slow to get back to you about this role.] About METR

We are a nonprofit research organization that develops scientific methods to assess AI capabilities, risks, and mitigations, with a specific focus on threats related to AI R&D automation and misalignment.

We believe it is robustly good for policymakers and civil society to have a clear understanding of risks from AI systems, and we are extremely excited to build a team of ambitious, excellent people to tackle one of the most important challenges of our time.

About the role

    METR’s mission of enabling transparency and coordination about the risks of frontier AI requires a high degree of trust from frontier AI labs, governments, and the public. As misalignment incidents become more extreme and confidential information about models and frontier AI labs becomes more valuable, we expect to be under increasingly intense pressure from external actors and internal agents. 

    As METR’s CISO, you will own METR’s overall security posture, proactively planning against future threats and ensuring our security strategy grows as the organization does. This includes managing penetration testing, threat modeling, incident investigation and response, and preventing our internal agents from undermining our security posture, covering both technical and administrative security. This role does not involve building or managing a large engineering team, although you will be working closely with our platform, infrastructure, and operations teams. 

    We expect this role to be essential as METR scales - our values, brand and mission requirements imply taking security and confidentiality very seriously. We must be justifiably viewed as secure, professional, and reliable, and are willing to impose costly actions on our staff to achieve this.

What this role looks like

  • Setting organizational strategy: You will set our security roadmap and our security culture, consolidating ownership of security areas that today are spread across teams and filling gaps that currently have no owner. 

  • Advising METR leadership, engineering and operations: You will advise on the security implications of new partnerships, evaluation programs, and model access arrangements before commitments are made. 

  • Owning incident response, red teaming and pen testing. You will lead these efforts across METR, including both computer and people security.

Required Skills

  • Deep security background. You’ve been accountable for an org’s security posture or led high-stakes security engagements in the past, including being part of or leading an IR team. Experience in an industry handling highly sensitive data (e.g., defense, healthcare) is especially desirable.

  • Threat modeling and red teaming experience. You can reason about defending against both insiders and sophisticated, well-resourced adversaries.

  • Excellent communication. You are comfortable explaining complex threat models and policies to executive leadership, and to researchers across a growing organization.

  • Mission-aligned. You care deeply about METR’s mission of investigating catastrophic risks for AI.

Nice-to-haves

  • Built a security team from scratch (first security hire or founding CISO).

  • Led incident response end to end, including decision-making and communication to stakeholders.

  • Experience securing AI/ML systems or agent infrastructure.

  • Familiarity with the tooling in our environment: DataDog, Kubernetes, CrowdStrike Falcon, Okta, Tailscale, Pulumi, PostgreSQL.

Our Culture
 
METR is a mission-driven organization. We believe our work can meaningfully shape humanity's future for the better, and we want to be the best people in the world doing this work. We have a tight-knit, collaborative research culture rooted in truth-seeking and integrity. We're fiercely committed to producing high-quality, trustworthy science. We're honest and transparent about our results, especially when they may go against the grain. We've earned trust as reliable partners who handle confidential information with care. We maintain a low-ego, drama-free environment focused on what matters.
 
Hybrid Requirements: Our technical team members are in our office in Berkeley 3-5 days/week. Please let us know in your application if this is a constraint. If you lack US work authorization and would like to work in-person (strongly preferred), we can likely sponsor a cap-exempt H-1B visa for this role.
 
We encourage you to apply even if your background may not seem like the perfect fit! We would rather review a larger pool of applications than risk missing out on a promising candidate for the position.
 
We are committed to diversity and equal opportunity in all aspects of our hiring process. We do not discriminate on the basis of race, religion, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. We welcome and encourage all qualified candidates to apply for our open positions.

Skills Required

  • Deep security and management background, including accountability for an organization’s security posture or leadership of high-stakes security engagements
  • Experience participating in or leading an incident response team
  • Hands-on ability to investigate incidents, review cloud IAM policies, assess sandboxing designs, and configure identity and endpoint tooling
  • Threat modeling and red teaming experience defending against insiders and sophisticated adversaries
  • Strong alignment with METR’s mission of investigating catastrophic risks from AI
  • Experience building a security team from scratch
  • Experience leading incident response end to end, including stakeholder communication and decision-making
  • Experience securing AI/ML systems or agent infrastructure
  • Familiarity with DataDog, Kubernetes, CrowdStrike Falcon, Okta, Tailscale, Pulumi, and PostgreSQL
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Berkeley, CA
33 Employees
Year Founded: 2022

What We Do

METR is a nonprofit research organization that scientifically measures whether and when AI systems might threaten catastrophic harm to society. Its mission is to develop scientific methods to assess AI capabilities, risks, and mitigations, with a specific focus on threats related to autonomy, AI R&D automation, and alignment to enable informed decision-making regarding AI development.

Similar Jobs

Trustly Logo Trustly

Chief Information Security Officer

Fintech • Payments • Financial Services
In-Office
San Francisco, CA, USA
905 Employees
350K-470K Annually
Hybrid
Ukiah, CA, USA
205000 Employees
35K-63K Hourly
Hybrid
Milpitas, CA, USA
205000 Employees
38K-67K Hourly
Hybrid
San Jose, CA, USA
205000 Employees
38K-67K Hourly

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees
Vega Thumbnail
Artificial Intelligence • Automotive • Insurance • Transportation
US
43 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account