Platform Engineer

METR LLC
United States
4 days ago
Apply on startup.jobs
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Artificial Intelligence Amazon Web Services Computing Platforms Cloud Computing Code Review Hardware Security Module Identity and Access Management Intrusion Detection and Prevention PostgreSQL Security Information and Event Management Software Engineering
+13 more
Software Vulnerability Management Datadog Pulumi Cloud Platform System Okta Large Language Models Software Security Backend Kubernetes Cybercrime Gsuite Cloudwatch Serverless Computing

Job description

METR’s mission of enabling transparency and coordination about the risks of frontier AI requires a high degree of trust from frontier AI labs, governments, and the public. As misalignment incidents become more extreme and confidential information about models and frontier AI labs becomes more valuable, we expect to be under increasingly intense pressure from external actors and internal agents., * Securing a unique attack surface. METR’s evaluation infrastructure runs frontier AI agents, including early checkpoints of unreleased models, executing untrusted, model-generated code at scale on multi-day tasks. You will design and build the isolation, networking, and permission boundaries that contain evaluated agents.

  • Remediation and hardening. You will find, triage, and fix vulnerabilities across our cloud infrastructure and access control systems.
  • Fixing known vulnerabilities in our codebase. This includes code reviews and resolving known vulnerabilities in our backlog.
  • Identity and access as a system. You will design and implement IAM policies, least-privilege access, and automated provisioning and access review for both people and agents.
  • Securing agentic systems. You will design and implement systems to monitor and control agents, making sure they can operate securely and with appropriate permissions and guardrails.

Requirements

  • 7+ years of experience working in security engineering, software development, or an adjacent field.
  • Production software engineering. You have experience building and operating backend or infrastructure in practice.
  • Cloud and container security. You have deep familiarity with AWS (especially non-trivial IAM), Kubernetes, and infrastructure-as-code environments.
  • Vulnerability remediation. You have found and fixed security flaws in large production systems and can prioritize a remediation backlog.
  • Security fundamentals. Strong security knowledge across systems, networks, cloud, and identity, and a track record of applying it to real systems. Experienced in designing secure software and cloud architectures.
  • Code review. Reviewing and giving constructive security feedback on PRs, including from the FOSS community., * Detection engineering at scale: Experience with detection pipelines (DataDog SIEM, AWS SecurityHub), writing and tuning detections, and threat hunting.
  • AI/LLM engineering: You build with AI: agent pipelines, LLM-powered tooling, automated workflows, and understand current limitations of those tools.
  • AI security research: Familiarity with agent control, hardware security, or red teaming AI systems themselves. Ideally you have experience with a portion of these technologies:

  • AWS: cloud-native software platforms
  • EKS
  • Lambda
  • ECS
  • IAM (in-depth)
  • CloudWatch
  • SecurityHub & GuardDuty
  • PostgreSQL: RLS, serverless Aurora
  • Pulumi: IaC
  • DataDog: SIEM
  • Okta: IdP
  • Google Workspace: IdP

About the company

We are a nonprofit research organization that develops scientific methods to assess AI capabilities, risks, and mitigations, with a specific focus on threats related to AI R&D automation and misalignment.

We believe it is robustly good for policymakers and civil society to have a clear understanding of risks from AI systems, and we are extremely excited to build a team of ambitious, excellent people to tackle one of the most important challenges of our time., METR is a mission-driven organization. We believe our work can meaningfully shape humanity’s future for the better, and we want to be the best people in the world doing this work. We have a tight-knit, collaborative research culture rooted in truth-seeking and integrity. We’re fiercely committed to producing high-quality, trustworthy science. We’re honest and transparent about our results, especially when they may go against the grain. We’ve earned trust as reliable partners who handle confidential information with care. We maintain a low-ego, drama-free environment focused on what matters. Hybrid Preferred: Our technical team members are in our office in Berkeley 3-5 days/week. We would ideally like for you to be in person too, but we are happy to be flexible here. If you lack US work authorization and would like to work in-person, we can likely sponsor a cap-exempt H-1B visa for this role. We encourage you to apply even if your background may not seem like the perfect fit! We would rather review a larger pool of applications than risk missing out on a promising candidate for the position.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on startup.jobs
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

1:55 min

Contrasting Terraform with Pulumi and cloud-specific tools

Devlin Duldulao · LIVE

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

2:14 min

Solving complex platform architecture challenges at an enterprise scale

Maria Apazoglou · Coffee With Developers

3:20 min

Overview of infrastructure as code tools

Alexander Bubeck · World Congress 2023

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · World Congress 2023

Videos

See all

Related articles

See all