
Real job — pulled straight from METR’s careers page · Verified August 28, 2026 · No reposts.
Job description
METR is hiring a Cyberforensics Member of Technical Staff — a full-time, based in Berkeley, CA role. Apply directly on METR's careers page below.
Member of Technical Staff, Cyberforensics
Team: Engineering & Research
Location: Berkeley
Commitment: Employee
Workplace Type: onsite
Salary:
- The office: Catered lunch and dinner daily; in-office gym and shower
- Relocation support: Stipend for moving to the Bay Area
- Time-off and leave: Unlimited PTO and 21-week parental leave for new parents
- Commuter benefit: Monthly transit/parking stipend and an annual Uber budget
- Professional development benefit: for training, courses, conferences, and AI safety education
- Mental health benefit: for therapy, medication, and other mental health expenses
- Wellness benefit: for gym memberships and other wellness expenses
- Work equipment benefit: for home office and workstation equipment expenses
About METR
We are a nonprofit research organization that develops scientific methods to assess AI capabilities, risks, and mitigations, with a specific focus on threats related to AI R&D automation and misalignment.
We believe it is robustly good for policymakers and civil society to have a clear understanding of risks from AI systems, and we are extremely excited to build a team of ambitious, excellent people to tackle one of the most important challenges of our time.
About the role
METR has started embedding researchers inside frontier labs to investigate incidents, stress-test labs’ internal agent monitoring systems, and assess loss-of-control risks from internal deployment. As agent capabilities increase, we expect this to be one of the most important sources of independent information the world has about catastrophic risks from advanced AI.
Recent incidents have involved complex multi-day cyber attacks on frontier lab internal infrastructure and external third parties. As we further develop our incident investigation and embedded stress-testing capacity, we will need talented cyberforensics researchers who can conduct embedded exercises. We expect these assessors to have deep access, and for their work to be a large part of METR's impact in the next year. We want to build on the momentum from previous exercises to further develop our risk assessments.
What this role looks like
-
Incident investigation: You'll be embedded in a frontier AI lab for up to several weeks at a time, likely alongside 1-4 other METR staff. Between exercises, you'll practice, develop the general methodology, talk to other researchers, build tooling to make future exercises go better, help us hire and scale, write up results, and plan/coordinate future exercises.
-
Red-teaming: You will attack agent monitoring and security systems, potentially embedded in labs or red-teaming METR internal infrastructure.
-
Reporting: You'd produce findings rigorous enough for lab boards, governments, and the public and contribute to METR's public incident tracking and risk reports.
-
Building AI-assisted forensic tooling: Incidents at our scale (tens of thousands of actions) often can't be read solely by hand. You'd build LLM-powered pipelines to triage transcripts, cluster behaviors, flag deception, and accelerate future investigations.
Required Skills
-
Digital forensics and incident response: You have investigated severe security incidents end to end. You have experience with evidence acquisition and preservation, log and timeline reconstruction across cloud, network, endpoint, and identity systems, attacker tradecraft analysis, and post-incident reporting.
-
Cloud and infrastructure fluency: You can follow an intrusion through AWS (CloudTrail, IAM, VPC flow logs), Kubernetes and containers, CI/CD, and package registries.
-
Understanding LLMs: You know how frontier models are trained and deployed (RL post-training, agent scaffolds, sandboxing, monitoring) well enough to reason about root causes, and you build and analyze with LLMs.
-
Attention to detail and communication: You can run rigorous investigations and write findings that hold up to scrutiny.
Nice to haves
-
Experience investigating incidents involving AI agents, or research on agent misbehavior, deception, or sandbox escapes.
-
Exploit and vulnerability analysis.
-
Experience with training-data analysis, model internals/interpretability, or running experiments on model checkpoints.
-
Formal investigation experience: NTSB/CSB-style safety investigations, law enforcement or intelligence forensics, regulatory or expert-witness work.
-
Familiarity with the tooling in our environment: DataDog, Kubernetes, CrowdStrike Falcon, Okta, Tailscale, Pulumi, PostgreSQL.
Get Cyberforensics Member of Technical Staff jobs like this→
New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.
Email me new jobsSimilar jobs




Frequently asked questions
What skills are required for Cyberforensics Member of Technical Staff at METR?
The required skills for Cyberforensics Member of Technical Staff at METR include: AWS, Kubernetes, CI/CD, LLM, Datadog, PostgreSQL.
What is the seniority level for Cyberforensics Member of Technical Staff at METR?
Cyberforensics Member of Technical Staff at METR is a Staff level position.
How do I apply for Cyberforensics Member of Technical Staff at METR?
You can view the full description and apply for Cyberforensics Member of Technical Staff at METR on EchoJobs: https://echojobs.io/job/metr-member-of-technical-staff-cyberforensics-4s7ff.