Platform Engineer, Application Security

Posted 16 Days Ago
Be an Early Applicant
Berkeley, CA, USA
In-Office
328K-579K Annually
Senior level
Artificial Intelligence • Machine Learning • Security
The Role
Design and build security controls for METR’s AI evaluation platform, including sandboxing, isolation, networking, access boundaries, IAM, and agent permissions. Identify, triage, and remediate vulnerabilities across cloud infrastructure, codebases, and access systems. Conduct secure code reviews, harden production systems, automate provisioning and access reviews, and develop monitoring and guardrails for agentic systems.
Summary Generated by Built In
About METR

We are a nonprofit research organization that develops scientific methods to assess AI capabilities, risks, and mitigations, with a specific focus on threats related to AI R&D automation and misalignment.

We believe it is robustly good for policymakers and civil society to have a clear understanding of risks from AI systems, and we are extremely excited to build a team of ambitious, excellent people to tackle one of the most important challenges of our time.

About the role

    METR’s mission of enabling transparency and coordination about the risks of frontier AI requires a high degree of trust from frontier AI labs, governments, and the public. As misalignment incidents become more extreme and confidential information about models and frontier AI labs becomes more valuable, we expect to be under increasingly intense pressure from external actors and internal agents. 

    METR is looking to expand the security expertise on our platform team. This would span application security in our evaluation platform, sandboxing agents and evaluations, cloud platform security, networking, access control for both people and agents, and securing our development environments and workflows. This role will have a large engineering component: expect to write and review code, fix vulnerabilities, and design and develop secure systems.

What this role looks like

  • Securing a unique attack surface. METR's evaluation infrastructure runs frontier AI agents, including early checkpoints of unreleased models, executing untrusted, model-generated code at scale on multi-day tasks. You will design and build the isolation, networking, and permission boundaries that contain evaluated agents. 

  • Remediation and hardening. You will find, triage, and fix vulnerabilities across our cloud infrastructure and access control systems.

  • Fixing known vulnerabilities in our codebase. This includes code reviews and resolving known vulnerabilities in our backlog.

  • Identity and access as a system. You will design and implement IAM policies, least-privilege access, and automated provisioning and access review for both people and agents.

  • Securing agentic systems. You will design and implement systems to monitor and control agents, making sure they can operate securely and with appropriate permissions and guardrails.

Required skills

  • 7+ years of experience working in security engineering, software development, or an adjacent field.

  • Production software engineering. You have experience building and operating backend or infrastructure in practice.

  • Cloud and container security. You have deep familiarity with AWS (especially non-trivial IAM), Kubernetes, and infrastructure-as-code environments.

  • Vulnerability remediation. You have found and fixed security flaws in large production systems and can prioritize a remediation backlog.

  • Security fundamentals. Strong security knowledge across systems, networks, cloud, and identity, and a track record of applying it to real systems. Experienced in designing secure software and cloud architectures.

  • Code review. Reviewing and giving constructive security feedback on PRs, including from the FOSS community.

  •  

Nice to haves

  • Detection engineering at scale: Experience with detection pipelines (DataDog SIEM, AWS SecurityHub), writing and tuning detections, and threat hunting. 

  • Offensive security: Experience with red teaming, penetration testing, and/or vulnerability research.
  • AI/LLM engineering: You build with AI: agent pipelines, LLM-powered tooling, automated workflows, and understand current limitations of those tools.

  • AI security research: Familiarity with agent control, hardware security, or red teaming AI systems themselves.


  • Ideally you have experience with a portion of these technologies:

  • AWS: cloud-native software platforms

  • EKS

  • Lambda

  • ECS

  • IAM (in-depth)

  • CloudWatch

  • SecurityHub & GuardDuty

  • PostgreSQL: RLS, serverless Aurora

  • Pulumi: IaC

  • DataDog: SIEM

  • Okta: IdP

  • Google Workspace: IdP

  • Tailscale: networking

  • CrowdStrike Falcon: endpoint security


Our Culture
 
METR is a mission-driven organization. We believe our work can meaningfully shape humanity's future for the better, and we want to be the best people in the world doing this work. We have a tight-knit, collaborative research culture rooted in truth-seeking and integrity. We're fiercely committed to producing high-quality, trustworthy science. We're honest and transparent about our results, especially when they may go against the grain. We've earned trust as reliable partners who handle confidential information with care. We maintain a low-ego, drama-free environment focused on what matters.
 
Hybrid Requirements: Our technical team members are in our office in Berkeley 3-5 days/week. Please let us know in your application if this is a constraint. If you lack US work authorization and would like to work in-person (strongly preferred), we can likely sponsor a cap-exempt H-1B visa for this role.
 
We encourage you to apply even if your background may not seem like the perfect fit! We would rather review a larger pool of applications than risk missing out on a promising candidate for the position.
 
We are committed to diversity and equal opportunity in all aspects of our hiring process. We do not discriminate on the basis of race, religion, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. We welcome and encourage all qualified candidates to apply for our open positions.

Skills Required

  • 7+ years of experience in security engineering, software development, or an adjacent field
  • Production experience building and operating backend or infrastructure systems
  • Deep familiarity with AWS, including non-trivial IAM
  • Experience with Kubernetes and infrastructure-as-code environments
  • Experience finding, prioritizing, and fixing security flaws in large production systems
  • Strong security knowledge across systems, networks, cloud, and identity
  • Experience designing secure software and cloud architectures
  • Experience conducting security-focused code reviews and providing constructive feedback
  • Experience with detection pipelines, security detections, and threat hunting
  • AI or LLM engineering experience, including agent pipelines or LLM-powered tooling
  • Familiarity with agent control, hardware security, or AI red teaming
  • Experience with AWS EKS, Lambda, ECS, CloudWatch, SecurityHub, or GuardDuty
  • Experience with PostgreSQL, row-level security, or Aurora Serverless
  • Experience with Pulumi
  • Experience with DataDog SIEM
  • Experience with Okta, Google Workspace, Tailscale, or CrowdStrike Falcon
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Berkeley, CA
33 Employees
Year Founded: 2022

What We Do

METR is a nonprofit research organization that scientifically measures whether and when AI systems might threaten catastrophic harm to society. Its mission is to develop scientific methods to assess AI capabilities, risks, and mitigations, with a specific focus on threats related to autonomy, AI R&D automation, and alignment to enable informed decision-making regarding AI development.

Similar Jobs

Tapestry - Coach and Kate Spade Logo Tapestry - Coach and Kate Spade

Temporary Sales Support Associate

eCommerce • Fashion • Retail • Sales • Wearables • Design
Hybrid
Roseville, CA, USA
16000 Employees
15-20 Hourly

Tapestry - Coach and Kate Spade Logo Tapestry - Coach and Kate Spade

Seasonal Stylist

eCommerce • Fashion • Retail • Sales • Wearables • Design
Hybrid
Arvin, CA, USA
16000 Employees
15-20 Hourly

Spectrum Logo Spectrum

Account Manager

Information Technology • Internet of Things • Mobile • On-Demand • Software
In-Office
Cerritos, CA, USA
100000 Employees
69K-137K Annually

Optum Logo Optum

Associate Patient Care Coordinator

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Glendale, CA, USA
160000 Employees
16-29 Hourly

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees
Vega Thumbnail
Artificial Intelligence • Automotive • Insurance • Transportation
US
43 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account