--- title: 'Member of Technical Staff, Cyberforensics at METR' canonical: 'https://feeny.ai/job/member-of-technical-staff-cyberforensics-metr-berkeley-kxzz3emzx9gj' type: 'job' last_seen: '2026-09-07' --- # Member of Technical Staff, Cyberforensics at METR - **Company:** METR - **Location:** Berkeley, CA - **Compensation:** $402k–$579k - **Work type:** onsite - **Posted:** 2026-08-26 - **Last confirmed live:** 2026-09-07 - **Apply:** https://jobs.lever.co/metr/b1a2f73f-f927-4f8b-b1b3-b2e57604b5fd ## Job description ## About METR We are a nonprofit research organization that develops scientific methods to assess AI capabilities, risks, and mitigations, with a specific focus on threats related to AI R&D automation and misalignment. We believe it is robustly good for policymakers and civil society to have a clear understanding of risks from AI systems, and we are extremely excited to build a team of ambitious, excellent people to tackle one of the most important challenges of our time. ## About the role METR has started embedding researchers inside frontier labs to [investigate incidents](https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/),  [stress-test labs’ internal agent monitoring systems](https://metr.org/blog/2026-03-25-red-teaming-anthropic-agent-monitoring/), and assess loss-of-control risks from [internal deployment](https://metr.org/blog/2026-05-19-frontier-risk-report/). As agent capabilities increase, we expect this to be one of the most important sources of independent information the world has about catastrophic risks from advanced AI. Recent incidents have involved complex multi-day cyber attacks on frontier lab internal infrastructure and external third parties. As we further develop our incident investigation and embedded stress-testing capacity, we will need talented cyberforensics researchers who can conduct embedded exercises. We expect these assessors to have deep access, and for their work to be a large part of METR's impact in the next year. We want to build on the momentum from previous exercises to further develop our risk assessments. What this role looks like - Incident investigation: You'll be embedded in a frontier AI lab for up to several weeks at a time, likely alongside 1-4 other METR staff. Between exercises, you'll practice, develop the general methodology, talk to other researchers, build tooling to make future exercises go better, help us hire and scale, write up results, and plan/coordinate future exercises. - Red-teaming: You will attack agent monitoring and security systems, potentially embedded in labs or red-teaming METR internal infrastructure. - Reporting: You'd produce findings rigorous enough for lab boards, governments, and the public and contribute to METR's public incident tracking and risk reports. - Building AI-assisted forensic tooling: Incidents at our scale (tens of thousands of actions) often can't be read solely by hand. You'd build LLM-powered pipelines to triage transcripts, cluster behaviors, flag deception, and accelerate future investigations. Required Skills - Digital forensics and incident response: You have investigated severe security incidents end to end. You have experience with evidence acquisition and preservation, log and timeline reconstruction across cloud, network, endpoint, and identity systems, attacker tradecraft analysis, and post-incident reporting. - Cloud and infrastructure fluency: You can follow an intrusion through AWS (CloudTrail, IAM, VPC flow logs), Kubernetes and containers, CI/CD, and package registries. - Understanding LLMs: You know how frontier models are trained and deployed (RL post-training, agent scaffolds, sandboxing, monitoring) well enough to reason about root causes, and you build and analyze with LLMs. - Attention to detail and communication: You can run rigorous investigations and write findings that hold up to scrutiny. Nice to haves - Experience investigating incidents involving AI agents, or research on agent misbehavior, deception, or sandbox escapes. - Exploit and vulnerability analysis. - Experience with training-data analysis, model internals/interpretability, or running experiments on model checkpoints. - Formal investigation experience: NTSB/CSB-style safety investigations, law enforcement or intelligence forensics, regulatory or expert-witness work. - Familiarity with the tooling in our environment: DataDog, Kubernetes, CrowdStrike Falcon, Okta, Tailscale, Pulumi, PostgreSQL. Our Culture METR is a mission-driven organization. We believe our work can meaningfully shape humanity's future for the better, and we want to be the best people in the world doing this work. We have a tight-knit, collaborative research culture rooted in truth-seeking and integrity. We're fiercely committed to producing high-quality, trustworthy science. We're honest and transparent about our results, especially when they may go against the grain. We've earned trust as reliable partners who handle confidential information with care. We maintain a low-ego, drama-free environment focused on what matters. Hybrid Requirements: Our technical team members are in our office in Berkeley 3-5 days/week. Please let us know in your application if this is a constraint. If you lack US work authorization and would like to work in-person (strongly preferred), we can likely sponsor a cap-exempt H-1B visa for this role. We encourage you to apply even if your background may not seem like the perfect fit! We would rather review a larger pool of applications than risk missing out on a promising candidate for the position. We are committed to diversity and equal opportunity in all aspects of our hiring process. We do not discriminate on the basis of race, religion, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. We welcome and encourage all qualified candidates to apply for our open positions. ## About METR ## Company Overview - **One-liner**: METR (pronounced "meter") is a non-profit research organization that develops scientific methods to assess catastrophic risks from advanced AI systems by evaluating their autonomous capabilities. - **Entity Type**: Non-profit (funded by donations, not a typical private company; no equity) - **Headquarters**: Berkeley, California, USA - **Founded**: Not explicitly stated, but founded by Beth Barnes; likely ~2021–2022 - **Founders**: Beth Barnes (Founder, CEO) ## Core Business - **Primary industry**: AI safety research and evaluation - **Target customers**: AI developers (e.g., OpenAI, Anthropic, Google DeepMind, Meta, Amazon), governments, and the broader public - **Mission or purpose**: "Develop scientific methods to assess catastrophic risks stemming from AI systems’ autonomous capabilities and enable good decision-making about their development." ## Products & Services - **Frontier AI Capability Evaluations**: Systematic assessments of how autonomously AI systems can perform tasks (e.g., conducting research, developing apps, cyberattacks, self‑hardening). Published as open research. - **Risk Assessments & Safety Policies**: Advises AI developers and governments on risk assessment methodologies, including the "Responsible Scaling Policies" approach adopted by nine leading AI labs. - **Time‑Horizon Research**: Open‑source analysis showing that the length of tasks AI agents can complete doubles every ~7 months, a key input for forecasting transformative AI timelines. - **Evaluation Platform**: An open‑source platform built on Inspect AI for running AI agent evaluations at scale. - **Monitorability Evaluations**: Research on detecting AI agents attempting to evade monitoring or perform side tasks, including datasets of "reward hacking" and "sandbagging" behaviors. - **Productivity RCT**: A randomized controlled trial with experienced open‑source developers measuring how much AI tools actually boost productivity (finding systematic overestimation). ## Market Standing - **Valuation/Market Cap**: Not applicable (non‑profit) - **Key Metric**: Funding – METR is supported by donations from major foundations and individuals. Notable donors include The Audacious Project (TED), Jane Street, Sijbrandij Foundation, Pew Charitable Trusts, Schmidt Sciences, Packard Foundation, and others. Small part of income from a technical assistance contract with the European AI Office. **No funding from AI companies** (maintains independence). - **Notable Investors/Partners**: Partners with OpenAI, Anthropic, Google DeepMind, Meta, Amazon (pilot risk assessments); member of NIST AI Safety Institute Consortium, California Cybersecurity Task Force, UK AI Security Institute; technical assistance to European AI Office. - **Growth Signals**: Growing team (multiple open roles), expanding into cyberforensics and embedded assessments, research cited widely in AI safety policy, and adoption of their Responsible Scaling Policies by major developers. ## Competitive Advantages - **Independence**: No funding from AI companies, enabling unbiased, transparent research. - **Scientific Rigor**: Publishes all research openly; uses empirical methods (RCTs, time‑horizon analysis) rather than speculation. - **Policy Influence**: Their frameworks (e.g., Responsible Scaling Policies) are now industry standards, and they advise governments globally. - **Deep Technical Expertise**: Team of researchers and engineers building state‑of‑the‑art evaluations for autonomous capabilities, including security‑relevant evaluations. ## Strategic Focus - **Current priorities**: Developing methodologies to track AI loss‑of‑control risk, improving monitorability evaluations, expanding cyberforensics capabilities, and scaling the team to meet growing demand for independent evaluations. - **Direction for growth**: Increasing influence on AI governance, deepening partnerships with governments and companies, and building tools for continuous risk assessment. ## Why Work Here - **Mission‑driven**: Direct contribution to aligning AI development with public safety, working on one of the most critical problems of our time. - **Compensation**: Highly competitive with top AI labs (salary ranges $328K–$687K for technical staff, $150–$300/hr for contractors), plus benefits like medical/dental/vision, wellness ($1,500/yr), mental health ($6,000/yr), professional development ($5,250/yr), unlimited PTO. - **Work environment**: Small, fast‑moving, mission‑driven team based in Berkeley. On‑site preferred for technical roles (at least a few days a week), but hybrid and remote (including international) can be accommodated. Operations roles require in‑person. - **Hiring process**: Unique focus on work tests (1–3 take‑home tasks) and a 1–2 day paid work trial (travel and lodging reimbursed). Interviews are given substantially less weight. Commitment to diversity and equal opportunity. - **Culture**: Open, transparent, and empirical; values rigor and independence. Visa sponsorship available for technical roles. ## Sources 1. [metr.org](https://metr.org/) 2. [metr.org/about](https://metr.org/about#our-team) 3. [metr.org/careers](https://metr.org/careers) 4. [metr.org/hiring](https://metr.org/hiring) 5. [jobs.lever.co/metr](https://jobs.lever.co/metr) ## Other roles at METR - [General Counsel](https://feeny.ai/job/general-counsel-metr-berkeley-4s59mgfhjagg) — Berkeley, CA - [System Administrator](https://feeny.ai/job/system-administrator-metr-berkeley-87zqbgq2ffsv) — Berkeley, CA - [Task Development Engineer](https://feeny.ai/job/task-development-engineer-metr-remote-5cbf872b6d7w) - [Member of Technical Staff, Embedded Assessments](https://feeny.ai/job/member-of-technical-staff-embedded-assessments-metr-berkeley-jsprvy2fdmqy) — Berkeley, CA - [Member of Technical Staff, Security Engineering](https://feeny.ai/job/member-of-technical-staff-security-engineering-metr-berkeley-w44zdwnsrdma) — Berkeley, CA - [Member of Technical Staff, Evaluation Execution](https://feeny.ai/job/member-of-technical-staff-evaluation-execution-metr-berkeley-rtt64jwna58y) — Berkeley, CA - [General Expression of Interest](https://feeny.ai/job/general-expression-of-interest-metr-berkeley-avs3pft13sf0) — Berkeley, CA