Cybersecurity Engineer (IT Security) in BERKELEY, California at MATS Research, Inc.
Explore Related Opportunities
Job Description
MATS finds and trains talented individuals for what we see as the world's most urgent and talent-constrained problem: reducing risks from unaligned artificial intelligence. We believe ambitious researchers from a variety of backgrounds have the potential to meaningfully contribute to alignment, control, security, and governance research. Through our research fellowship, we provide mentorship, training, professional network, and financial support to accelerate their careers and increase their impact.
Since 2021, we have trained over 630 researchers. 75% of pre-2026 fellows continue to work in AI alignment. 10% have co-founded organizations. Our fellows have produced 215+ research papers with 17,000+ citations. And we are just getting started: in the coming year we will expand our program to support even more researchers.
This is a build role, and a founding one. As our first dedicated IT Security hire, you will stand up and own the corporate IT and security function: the endpoint, identity, and collaboration scaffolding a distributed research organization runs on, in combination with the compliance frameworks that unlock lab partnerships.
We think about security in two closely related areas. The first is IT and security — the human-operational attack surface: accounts, devices, email, office networks, vendors, and the SaaS suite that staff and fellows use every day. The second is research and infrastructure security — the machine-operational attack surface of our compute cluster, CI/CD pipelines, and model artefacts. This role focuses on the former. We expect to grow the security team one hire at a time. Depending on hiring order, in your first few months you will inevitably wear both hats, biased toward the IT side, while keeping the research infrastructure side functioning until a second engineer joins.
Good security here is not overhead. It is what makes deeper lab partnerships possible, and it is a core part of how MATS earns access to sensitive models and data. You will be accountable for getting researchers and staff the tools they need to move fast, while maintaining a posture that external partners can trust.
You should be comfortable getting into the weeds of configuration and implementation, but you understand that the ultimate goal is to enable world-class research through secure operations.
What you'll do- Build the secure-by-default environment. Design and deploy endpoint security (MDM/EDR) for a hybrid, two-country fleet spanning in-person teams in London and Berkeley and remote collaborators. Researchers and staff should be able to work with high-value code and data safely, without sacrificing velocity.
- Own identity and access management. Define the lifecycle of identities for staff, collaborators, fellows, and the automated service accounts that touch MATS systems. Advance our identity toward a robust Zero-Trust architecture (SSO, least-privilege, and hardware-key MFA), and set the boundary between what AI agents can do on our behalf and what requires human authorization. Run rigorous access control that balances our open-science publication goals against the sensitivity of pre-publication research.
- Secure communications and email. You will implement advanced email security, DMARC progression, phishing protection, and secure collaborative workflows, and governance of how AI tools are used across the organization. You will run a phishing simulation and training programme that shows measurable improvement in detection and response over time.
- Turn compliance into acceleration. Act as the primary bridge between our research needs and the security requirements of external AI labs. Lead MATS through the audits required to gain and maintain frontier-model access (e.g. SOC 2, ISO 27001, Cyber Essentials), and systematically manage vendor security reviews. MATS operates across the UK and US, so you will also handle the compliance that follows in both jurisdictions: data-protection obligations (UK GDPR, CCPA) and breach-notification timelines.
- Run the security programme. Operate the day-to-day function: quarterly access reviews, backup verification, regulatory incident-reporting, vendor SOC 2 reviews, audit-evidence preparation, and the policy iterations that hold it all together. As MATS shares research data with external partners, own the privacy and data-processing side: consent handling, data-processing agreements, and retention.
- Own the corporate-side incident response capability. You are the first responder when something happens to staff accounts, devices, email, or vendors. That includes maintaining the IR runbook, running quarterly tabletop exercises, coordinating with our external IR retainer firm for after-hours and depth, handling regulatory notification decisions with leadership and legal, and preparing post-incident reviews.
- Stand up security for the fellowship. Design and operate the controls that bring 100–120 fellows per cohort into MATS's security perimeter and out again at cohort end: Fellowship Acceptable Use Policy, security onboarding, fellow data classification, segregated accounts and networks, and a reliable cohort-end off-boarding flow, ideally automated through SSO/SCIM to handle provisioning and revocation at cohort scale.
A successful first year looks concrete: MATS passes its first external audit; all staff are on hardware keys; MDM is operational and verifiable; vendor reviews are systematic; the phishing simulation programme shows measurable improvement; and we can credibly show frontier labs that we meet a recognised security bar.
About youYou are a security generalist who has stood up an IT and security function from scratch and can operate with autonomy in an early-stage, ambiguous environment. You understand the threat model of a high-stakes research organization — phishing, account takeover, off-boarding gaps, vendor compromise, business-email compromise, and the targeted attention that comes with frontier-relevant work — and you can balance extreme security against an AI lab's "move fast" requirements. You can translate technical security requirements into plain English for researchers, theorists, and leadership. You are willing to use AI tools aggressively in your own workflow, with appropriate care not to get fooled.
Essential skills and experienceWe expect to hire someone who has all of the following:
- Demonstrated experience building an IT and/or security function from scratch, operating with autonomy and ambiguity in an early-stage organization.
- A hands-on, technical background: you are comfortable configuring systems, scripting automation, and personally setting up the stack. Operating the security programme is the core of the job; scripting supports it.
- Familiarity with compliance frameworks — SOC 2, ISO 27001, and/or Cyber Essentials — and with partner-lab security requirements.
- The ability to translate security requirements into plain English for non-technical colleagues.
- Sound judgment in balancing the sensitivity of frontier-relevant research against an organization's need to move quickly.
- Comfortable standing up and operating a SIEM.
We expect highly competitive applicants to have some of the following:
- Experience from security-mature tech companies, fintech, or other AI safety / research organizations.
- Hands-on experience with the kind of stack we run or expect to run: Rippling MDM; EDR (CrowdStrike, SentinelOne, or Defender); SIEM (Panther, Sumo, or Datadog); Workspace admin; IAM tooling; training platforms (KnowBe4, Hoxhunt); and compliance tooling (Vanta, Drata, Secureframe).
- Experience defining identity lifecycle and least-privilege access for automated service accounts and AI agents.
- Curiosity and genuine interest in MATS's mission. You don't need to be an AI safety expert, but you should care about the work and be motivated by its importance.
- Experience designing or operating an insider-threat or personnel-security programme — background screening, separation of duties, and need-to-know access — in research, government-adjacent, or IP-sensitive environments.
- Background in mature SOC operations: 24/7 alert triage, threat hunting, penetration testing or red-team / purple-team exercises.
- The essential skills listed above contain the basic requirements, and align with the lower end of this range.
- MATS provides in-office, catered lunches and dinners to employees on workdays.
- Paid work trips, including staff retreats, business trips, and relevant conferences.
- Funding and support for professional development.
- Flexible PTO for Berkeley-based employees.
- Flexibility for hybrid work (but not for fully remote work).
- Collaborative and intellectually stimulating work environment.
- Medical, dental, vision, and life insurance.
- Both Roth 401(k) and Traditional 401(k) for US-based employees.
40 hours per week. Successful candidates can expect to spend most of their time working in person from our main office in Berkeley, California or our London office. We are open to hybrid working arrangements for exceptional candidates.
Note while applyingIf you use an LLM chatbot or other AI tools in this application, please follow the norms here. Applications will be reviewed on a rolling basis. MATS uses LLMs to help draft job descriptions, identify candidates to source, and transcribe interviews.
MATS is committed to fostering a diverse and inclusive work environment at the forefront of our field. We encourage applications from individuals of all backgrounds and experiences.
Join us in shaping the future of AI safety & security research!
The pay range for this role is:
130,000 - 180,000 GBP per year(Fora (London MATS Office))
210,000 - 290,000 USD per year(Berkeley MATS Office)