Platform Engineer, Application Security
Quick Summary
Our technical team members are in our office in Berkeley 3-5 days/week. Please let us know in your application if this is a constraint.
We are a nonprofit research organization that develops scientific methods to assess AI capabilities, risks, and mitigations, with a specific focus on threats related to AI R&D automation and misalignment.
We believe it is robustly good for policymakers and civil society to have a clear understanding of risks from AI systems, and we are extremely excited to build a team of ambitious, excellent people to tackle one of the most important challenges of our time.
METR’s mission of enabling transparency and coordination about the risks of frontier AI requires a high degree of trust from frontier AI labs, governments, and the public. As misalignment incidents become more extreme and confidential information about models and frontier AI labs becomes more valuable, we expect to be under increasingly intense pressure from external actors and internal agents.
METR is looking to expand the security expertise on our platform team. This would span application security in our evaluation platform, sandboxing agents and evaluations, cloud platform security, networking, access control for both people and agents, and securing our development environments and workflows. This role will have a large engineering component: expect to write and review code, fix vulnerabilities, and design and develop secure systems.
Production software engineering. You have experience building and operating backend or infrastructure in practice.
Cloud and container security. You have deep familiarity with AWS (especially non-trivial IAM), Kubernetes, and infrastructure-as-code environments.
Vulnerability remediation. You have found and fixed security flaws in large production systems and can prioritize a remediation backlog.
Security fundamentals. Strong security knowledge across systems, networks, cloud, and identity, and a track record of applying it to real systems. Experienced in designing secure software and cloud architectures.
Code review. Reviewing and giving constructive security feedback on PRs, including from the FOSS community.
Detection engineering at scale: Experience with detection pipelines (DataDog SIEM, AWS SecurityHub), writing and tuning detections, and threat hunting.
AI/LLM engineering: You build with AI: agent pipelines, LLM-powered tooling, automated workflows, and understand current limitations of those tools.
AI security research: Familiarity with agent control, hardware security, or red teaming AI systems themselves.
Ideally you have experience with a portion of these technologies:
AWS: cloud-native software platforms
EKS
Lambda
ECS
IAM (in-depth)
CloudWatch
SecurityHub & GuardDuty
PostgreSQL: RLS, serverless Aurora
Pulumi: IaC
DataDog: SIEM
Okta: IdP
Google Workspace: IdP
Tailscale: networking
CrowdStrike Falcon: endpoint security
Location & Eligibility
Listing Details
- Posted
- July 8, 2026
- First seen
- July 29, 2026
- Last seen
- October 6, 2026
Posting Health
- Days active
- 68
- Repost count
- 0
- Trust Level
- 42%
- Scored at
- October 6, 2026
Signal breakdown
Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.