Please Accept our Privacy Policy
We are a nonprofit research organization that develops scientific methods to assess AI capabilities, risks, and mitigations, with a specific focus on threats related to AI R&D automation and misalignment.
We believe it is robustly good for policymakers and civil society to have a clear understanding of risks from AI systems, and we are extremely excited to build a team of ambitious, excellent people to tackle one of the most important challenges of our time.
METR’s mission of enabling transparency and coordination about the risks of frontier AI requires a high degree of trust from frontier AI labs, governments, and the public. As misalignment incidents become more extreme and confidential information about models and frontier AI labs becomes more valuable, we expect to be under increasingly intense pressure from external actors and internal agents.
As METR’s CISO, you will own METR’s overall security posture, proactively planning against future threats and ensuring our security strategy grows as the organization does. This includes managing penetration testing, threat modeling, incident investigation and response, and preventing our internal agents from undermining our security posture, covering both technical and administrative security. This role does not involve building or managing a large engineering team, although you will be working closely with our platform, infrastructure, and operations teams.
We expect this role to be essential as METR scales - our values, brand and mission requirements imply taking security and confidentiality very seriously. We must be justifiably viewed as secure, professional, and reliable, and are willing to impose costly actions on our staff to achieve this.
What this role looks likeSetting organizational strategy: You will set our security roadmap and our security culture, consolidating ownership of security areas that today are spread across teams and filling gaps that currently have no owner.
Advising METR leadership, engineering and operations: You will advise on the security implications of new partnerships, evaluation programs, and model access arrangements before commitments are made.
Owning incident response, red teaming and pen testing. You will lead these efforts across METR, including both computer and people security.
Deep security background. You’ve been accountable for an org’s security posture or led high-stakes security engagements in the past, including being part of or leading an IR team. Experience in an industry handling highly sensitive data (e.g., defense, healthcare) is especially desirable.
Threat modeling and red teaming experience. You can reason about defending against both insiders and sophisticated, well-resourced adversaries.
Excellent communication. You are comfortable explaining complex threat models and policies to executive leadership, and to researchers across a growing organization.
Mission-aligned. You care deeply about METR’s mission of investigating catastrophic risks for AI.
Built a security team from scratch (first security hire or founding CISO).
Led incident response end to end, including decision-making and communication to stakeholders.
Experience securing AI/ML systems or agent infrastructure.
Familiarity with the tooling in our environment: DataDog, Kubernetes, CrowdStrike Falcon, Okta, Tailscale, Pulumi, PostgreSQL.
METR also has a host of benefits:
The office: Catered lunch and dinner daily; in-office gym and shower
Relocation support: Stipend for moving to the Bay Area?
Time-off and leave: Unlimited PTO and 21-week parental leave for new parents
Commuter benefit: Monthly transit/parking stipend and an annual Uber budget
Professional development benefit: for training, courses, conferences, and AI safety education?
Mental health benefit: for therapy, medication, and other mental health expenses?
Wellness benefit: for gym memberships and other wellness expenses?
Work equipment benefit: for home office and workstation equipment? expenses
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.