Member of Technical Staff, Cyberforensics

METR

Berkeley (CA)

Hybrid

USD 402,000 - 579,000

Full time

13 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Catered lunch
Relocation stipend
Unlimited PTO
Parental leave
Transit stipend
Uber budget
Professional development
Mental health support
Wellness stipend
Home office equipment

Job summary

METR in Berkeley seeks cyberforensics researchers to embed in frontier labs to investigate incidents, stress-test monitoring, and assess risk from AI deployment.

You will build LL-powered pipelines, perform red-teaming, and produce rigorous findings for lab boards and public reporting, with flexible hybrid work in the Bay Area.

Qualifications

  • Experience investigating severe security incidents end to end and preserving evidence.
  • Fluent with AWS, Kubernetes, CI/CD, and cloud log analysis.
  • Ability to reason about root causes of frontier model deployments.
  • Strong written reporting capable for boards, governments, and the public.

Responsibilities

  • Incident investigation: embed in frontier AI labs for multi-week assessments.
  • Red-teaming: test agent monitoring and security systems, including lab environments.
  • Reporting: produce findings suitable for boards, governments, and public risk reports.
  • Tooling: build AI-assisted forensic pipelines to triage transcripts and detect deception.

Skills

Digital forensics
Incident response
Cloud & infra fluency
LLMs understanding
Attention to detail & communication

Tools

DataDog
Kubernetes
CrowdStrike Falcon
Okta
Tailscale
Pulumi
PostgreSQL

Job description

About METR

We are a nonprofit research organization that develops scientific methods to assess AI capabilities, risks, and mitigations, with a specific focus on threats related to AI R&D automation and misalignment.

We believe it is robustly good for policymakers and civil society to have a clear understanding of risks from AI systems, and we are extremely excited to build a team of ambitious, excellent people to tackle one of the most important challenges of our time.

About the role

METR has started embedding researchers inside frontier labs to investigate incidents, stress-test labs' internal agent monitoring systems, and assess loss-of-control risks from internal deployment. As agent capabilities increase, we expect this to be one of the most important sources of independent information the world has about catastrophic risks from advanced AI.

Recent incidents have involved complex multi-day cyber attacks on frontier lab internal infrastructure and external third parties. As we further develop our incident investigation and embedded stress-testing capacity, we will need talented cyberforensics researchers who can conduct embedded exercises. We expect these assessors to have deep access, and for their work to be a large part of METR's impact in the next year. We want to build on the momentum from previous exercises to further develop our risk assessments.

What this role looks like
  • Incident investigation: You'll be embedded in a frontier AI lab for up to several weeks at a time, likely alongside 1-4 other METR staff. Between exercises, you'll practice, develop the general methodology, talk to other researchers, build tooling to make future exercises go better, help us hire and scale, write up results, and plan/coordinate future exercises.

  • Red-teaming: You will attack agent monitoring and security systems, potentially embedded in labs or red-teaming METR internal infrastructure.

  • Reporting: You'd produce findings rigorous enough for lab boards, governments, and the public and contribute to METR's public incident tracking and risk reports.

  • Building AI-assisted forensic tooling: Incidents at our scale (tens of thousands of actions) often can't be read solely by hand. You'd build LLM-powered pipelines to triage transcripts, cluster behaviors, flag deception, and accelerate future investigations.

Required Skills
  • Digital forensics and incident response: You have investigated severe security incidents end to end. You have experience with evidence acquisition and preservation, log and timeline reconstruction across cloud, network, endpoint, and identity systems, attacker tradecraft analysis, and post-incident reporting.

  • Cloud and infrastructure fluency: You can follow an intrusion through AWS (CloudTrail, IAM, VPC flow logs), Kubernetes and containers, CI/CD, and package registries.

  • Understanding LLMs: You know how frontier models are trained and deployed (RL post-training, agent scaffolds, sandboxing, monitoring) well enough to reason about root causes, and you build and analyze with LLMs.

  • Attention to detail and communication: You can run rigorous investigations and write findings that hold up to scrutiny.

Nice to haves
  • Experience investigating incidents involving AI agents, or research on agent misbehavior, deception, or sandbox escapes.

  • Exploit and vulnerability analysis.

  • Experience with training-data analysis, model internals/interpretability, or running experiments on model checkpoints.

  • Formal investigation experience: NTSB/CSB-style safety investigations, law enforcement or intelligence forensics, regulatory or expert-witness work.

  • Familiarity with the tooling in our environment: DataDog, Kubernetes, CrowdStrike Falcon, Okta, Tailscale, Pulumi, PostgreSQL.

$402,048 - $578,583 a year

Benefits
  • The office: Catered lunch and dinner daily; in-office gym and shower
  • Relocation support: Stipend for moving to the Bay Area
  • Time-off and leave: Unlimited PTO and 21-week parental leave for new parents
  • Commuter benefit: Monthly transit/parking stipend and an annual Uber budget
  • Professional development benefit: for training, courses, conferences, and AI safety education
  • Mental health benefit: for therapy, medication, and other mental health expenses
  • Wellness benefit: for gym memberships and other wellness expenses
  • Work equipment benefit: for home office and workstation equipment expenses
Our Culture

METR is a mission-driven organization. We believe our work can meaningfully shape humanity's future for the better, and we want to be the best people in the world doing this work. We have a tight-knit, collaborative research culture rooted in truth-seeking and integrity. We're fiercely committed to producing high-quality, trustworthy science. We're honest and transparent about our results, especially when they may go against the grain. We've earned trust as reliable partners who handle confidential information with care. We maintain a low-ego, drama-free environment focused on what matters.

Hybrid Preferred: Our technical team members are in our office in Berkeley 3-5 days/week. We would ideally like for you to be in person too, but we are happy to be flexible here. If you lack US work authorization and would like to work in-person, we can likely sponsor a cap-exempt H-1B visa for this role.

We encourage you to apply even if your background may not seem like the perfect fit! We would rather review a larger pool of applications than risk missing out on a promising candidate for the position.

We are committed to diversity and equal opportunity in all aspects of our hiring process. We do not discriminate on the basis of race, religion, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. We welcome and encourage all qualified candidates to apply for our open positions.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Member of Technical Staff, Embedded Assessments
Member of Technical Staff, Embedded Assessments

METR • Berkeley (CA)

Hybrid
USD 402,000 - 688,000
Catered lunch and dinner daily
Relocation stipend
Unlimited PTO
+6
Member of Technical Staff, Security Engineering
Member of Technical Staff, Security Engineering

Metr • Berkeley (CA)

Hybrid
USD 180,000 - 260,000
Hybrid work in Berkeley
Visa sponsorship (cap-exempt H-1B)
Diversity and equal opportunity
Member of Technical Staff
Member of Technical Staff

Metr • Berkeley (CA)

On-site
USD 250,000 - 450,000
Catered lunch and dinner daily
Unlimited PTO
Relocation support
+4
System Administrator
System Administrator

METR • Berkeley (CA)

Hybrid
USD 261,000 - 472,000
Catered meals
Relocation stipend
Unlimited PTO
+7
Member of Technical Staff, Evaluation Execution
Member of Technical Staff, Evaluation Execution

METR • Berkeley (CA)

On-site
USD 285,548 - 503,116
Catered lunch and dinner daily
In-office gym and shower
Unlimited PTO
+6
General Counsel
General Counsel

METR • Berkeley (CA)

On-site
USD 328,000 - 402,000
Catered lunches and in-office gym
Relocation stipend to Bay Area
Unlimited PTO
+7
Senior Research Engineer
Senior Research Engineer

Aisafety • Berkeley (CA)

Hybrid
USD 150,000 - 250,000
Catered lunch and dinner
Visa sponsorship for in-person employees
Work-related travel expenses covered
Research Engineer
Research Engineer

Aisafety • Berkeley (CA)

Hybrid
USD 100,000 - 190,000
Catered lunch and dinner
Potential for remote work
Sponsorship for work-related travel
Cyber Systems Engineer
Cyber Systems Engineer

Metrea • Maryland

On-site
USD 110,000 - 140,000
Medical plan
Dental and vision coverage
401(k) match
+6
Cyber Operations Lead, Critical Harm Operations
Cyber Operations Lead, Critical Harm Operations

United States Digital Space LLC • United States

Hybrid
USD 180,000 - 240,000
Relocation assistance
Hybrid work model