Platform Engineer, Application Security
Quick facts
- Pay
- USD 328,380 - 578,583 per year
- Type
- Full-time
- Location
- Berkeley, California
- Experience
- 7+ years
- Skills
- Kubernetes, AWS
- Industry
- Research and Science — 76 open jobs
- Visa in listing
- H-1B
- Apply
- Free to apply — never pay anyone for a job offer or visa sponsorship
Job description
About METR
We are a nonprofit research organization that develops scientific methods to assess AI capabilities, risks, and mitigations, with a specific focus on threats related to AI R&D automation and misalignment.
We believe it is robustly good for policymakers and civil society to have a clear understanding of risks from AI systems, and we are extremely excited to build a team of ambitious, excellent people to tackle one of the most important challenges of our time.
About the role
METR’s mission of enabling transparency and coordination about the risks of frontier AI requires a high degree of trust from frontier AI labs, governments, and the public. As misalignment incidents become more extreme and confidential information about models and frontier AI labs becomes more valuable, we expect to be under increasingly intense pressure from external actors and internal agents.
METR is looking to expand the security expertise on our platform team. This would span application security in our evaluation platform, sandboxing agents and evaluations, cloud platform security, networking, access control for both people and agents, and securing our development environments and workflows. This role will have a large engineering component: expect to write and review code, fix vulnerabilities, and design and develop secure systems.
What this role looks like
Securing a unique attack surface. METR's evaluation infrastructure runs frontier AI agents, including early checkpoints of unreleased models, executing untrusted, model-generated code at scale on multi-day tasks. You will design and build the isolation, networking, and permission boundaries that contain evaluated agents.
Remediation and hardening. You will find, triage, and fix vulnerabilities across our cloud infrastructure and access control systems.
Fixing known vulnerabilities in our codebase. This includes code reviews and resolving known vulnerabilities in our backlog.
Identity and access as a system. You will design and implement IAM policies, least-privilege access, and automated provisioning and access review for both people and agents.
Securing agentic systems. You will design and implement systems to monitor and control agents, making sure they can operate securely and with appropriate permissions and guardrails.
Required skills
7+ years of experience working in security engineering, software development, or an adjacent field.
Production software engineering. You have experience building and operating backend or infrastructure in practice.
Cloud and container security. You have deep familiarity with AWS (especially non-trivial IAM), Kubernetes, and infrastructure-as-code environments.
Vulnerability remediation. You have found and fixed security flaws in large production systems and can prioritize a remediation backlog.
Security fundamentals. Strong security knowledge across systems, networks, cloud, and identity, and a track record of applying it to real systems. Experienced in designing secure software and cloud architectures.
Code review. Reviewing and giving constructive security feedback on PRs, including from the FOSS community.
Nice to haves
Detection engineering at scale: Experience with detection pipelines (DataDog SIEM, AWS SecurityHub), writing and tuning detections, and threat hunting.
- Offensive security: Experience with red teaming, penetration testing, and/or vulnerability research.
AI/LLM engineering: You build with AI: agent pipelines, LLM-powered tooling, automated workflows, and understand current limitations of those tools.
AI security research: Familiarity with agent control, hardware security, or red teaming AI systems themselves.
Ideally you have experience with a portion of these technologies:
AWS: cloud-native software platforms
EKS
Lambda
ECS
IAM (in-depth)
CloudWatch
SecurityHub & GuardDuty
PostgreSQL: RLS, serverless Aurora
Pulumi: IaC
DataDog: SIEM
Okta: IdP
Google Workspace: IdP
Tailscale: networking
CrowdStrike Falcon: endpoint security
Our Culture
METR is a mission-driven organization. We believe our work can meaningfully shape humanity's future for the better, and we want to be the best people in the world doing this work. We have a tight-knit, collaborative research culture rooted in truth-seeking and integrity. We're fiercely committed to producing high-quality, trustworthy science. We're honest and transparent about our results, especially when they may go against the grain. We've earned trust as reliable partners who handle confidential information with care. We maintain a low-ego, drama-free environment focused on what matters.
Hybrid Preferred: Our technical team members are in our office in Berkeley 3-5 days/week. We would ideally like for you to be in person too, but we are happy to be flexible here. If you lack US work authorization and would like to work in-person, we can likely sponsor a cap-exempt H-1B visa for this role.
We encourage you to apply even if your background may not seem like the perfect fit! We would rather review a larger pool of applications than risk missing out on a promising candidate for the position.
We are committed to diversity and equal opportunity in all aspects of our hiring process. We do not discriminate on the basis of race, religion, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. We welcome and encourage all qualified candidates to apply for our open positions.
Visa sponsorship record: Model Evaluation and Threat Research Inc.
Sponsors actively| Fiscal year | H-1B LCAs | USCIS approvals | USCIS denials | PERM |
|---|---|---|---|---|
| FY2026 | 2 | 2 | 0 | — |
| FY2025 | 6 | 4 | 0 | — |
| FY2024 | 2 | — | — | — |
This exact kind of role (Software Developers) isn't among the roles Model Evaluation and Threat Research Inc. sponsored most often.
Roles they sponsor most
- machine learning researcher2 LCAs · median $296k
- member of technical2 LCAs · median $249k
- member of technical machine learning researcher2 LCAs · median $236k
- chief of1 LCA · median $150k
- chief operating officer1 LCA · median $209k
Full sponsorship history of Model Evaluation and Threat Research Inc. →
Which visas can work for this job
Occupation: Software Developers (SOC 15-1252).
- Mentioned in the listing
H-1B
- H-1B cap-exempt employer
Regular cap-subject employer — a new H-1B needs to win the lottery in March (unless you already hold cap-counted H-1B status).
- TN (citizens of Canada and Mexico)
This kind of role may fit the USMCA profession “Computer Systems Analyst (or Engineer, for engineering-degree holders)” — it depends on the actual duties. No lottery, no cap; you need the matching degree or license.
- E-3 (Australia) and H-1B1 (Chile, Singapore)
Same degree requirement as H-1B, but no lottery and a separate quota that is rarely filled.
- O-1 (extraordinary ability)
For candidates with awards, publications, press, a high salary or critical roles at distinguished organizations. No cap, no lottery; the employer files a petition.
- STEM OPT extension (F-1 students)
Requires an E-Verify employer. We didn't find this company in the E-Verify list — ask HR.
Salary vs prevailing wage
Software Developers · San Francisco-Oakland-Fremont, CA. Annual prevailing wages set by the Department of Labor (OFLC).
| Level | Prevailing wage | H-1B lottery odds* |
|---|---|---|
| Level I | $137,093 | ~15% |
| Level II | $165,131 | ~31% |
| Level III | $193,149 | ~46% |
| Level IV | $221,187 | ~61% |
The listing has no salary, so we can't place it on a wage level. Ask the employer which wage level they'd file at: Level III–IV registrations get 3–4 entries in the H-1B lottery.
* Odds are DHS projections for the FY2027 wage-weighted lottery (actual results vary by year and employer). Since the FY2027 cap season the H-1B lottery is weighted by wage level: Level I = 1 entry, II = 2, III = 3, IV = 4. The level is set by the offered wage against the prevailing wage for the occupation and worksite. Separately, a $100,000 fee for new H-1B petitions for workers outside the US was announced in 2025; as of September 2026 a federal court ruling keeps it unenforceable while appeals continue — check the current status.
Sources: U.S. Department of Labor OFLC disclosure data (H-1B/H-1B1/E-3 LCA, PERM), OFLC prevailing wage data, USCIS H-1B Employer Data Hub, E-Verify participating employers. Data loaded: LCA FY2024–FY2026, PERM, USCIS Data Hub, OFLC wages; updated 2026-10-03. Employers are matched by name, so records of companies with similar names can occasionally be mixed up. This is general information, not legal advice — talk to an immigration attorney about your case.