Security Engineer

METRBerkeley, CA
Hybrid

About The Position

Security at METR is becoming its own dedicated team, and you would be one of its first hires. It is extremely important that we continue to be an organization that frontier AI labs, governments, and the public trust with sensitive model access and confidential information. As misalignment incidents become more extreme and confidential information about models and frontier AI labs becomes more valuable, we expect to be under increasingly heavy pressure. For us, security encompasses managing endpoints and securing development environments, cloud platform security, safely sandboxing agents and evaluations, VPN and VPC networking, application code reviews, account provisioning and access control, and helping ensure we use the best practices across all of our workflows.

Requirements

  • Deep security expertise: You have strong fundamentals across systems, networks, cloud, and identity.
  • Offensive security: You have experience acting like an attacker, whether through red teaming, penetration testing, or adversarial research.
  • AI/LLM engineering: You build with AI: agent pipelines, LLM-powered tooling, automated workflows, and understand current limitations of those tools.
  • AWS: You should know AWS very well, including a deep understanding of IAM policies.
  • We don't screen on certifications, degrees, or years of experience.

Nice To Haves

  • Detection engineering at scale: Experience with SIEM/detection pipelines, writing and tuning detections, and threat hunting.
  • Cloud and container security: AWS (especially non-trivial IAM), Kubernetes, and infrastructure-as-code environments.
  • Incident response: You've led or worked severe incidents, ideally those involving AI agents.
  • AI security research: Familiarity with prompt injection, agent containment, model supply-chain risks, or red teaming AI systems themselves.
  • Ideally you have experience with a good portion of these technologies: AWS: cloud-native software platforms EKS Lambda ECS IAM (in-depth) SQS CloudWatch SecurityHub & GuardDuty PostgreSQL: RLS, serverless Aurora Pulumi: IaC DataDog : SIEM Okta: IdP Google Workspace: IdP Tailscale: networking CrowdStrike Falcon : endpoint security

Responsibilities

  • Offensive security: You would be the first person on the team with an offensive security background. You'll run targeted red-team exercises against our own systems and build automated AI red teaming.
  • High-context detection and response: You will build AI systems that can quickly triage and respond to threats, both from internal agents and external attackers.
  • Blue-team engineering: Detection engineering, telemetry pipelines, incident response, and hardening across our cloud infrastructure, endpoints, and identity systems.
  • Securing a unique attack surface: METR's evaluation infrastructure runs frontier AI agents, including early checkpoints of unreleased models, executing untrusted, model-generated code at scale on multi-day tasks.
  • Enabling bleeding-edge research: You'll work closely with our researchers to make dangerous-capability experiments safe to run. We often face extreme reward hacking and evaluation awareness during our pre-deployment evaluations, and expect internal threats from agents to become more extreme.

Benefits

  • Catered lunch and dinner daily
  • in-office gym and shower
  • Stipend for moving to the Bay Area
  • Unlimited PTO
  • 21-week parental leave for new parents
  • Monthly transit/parking stipend and an annual Uber budget
  • Professional development benefit: for training, courses, conferences, and AI safety education
  • Mental health benefit: for therapy, medication, and other mental health expenses
  • Wellness benefit: for gym memberships and other wellness expenses
  • Work equipment benefit: for home office and workstation equipment expenses
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service