JobTarget Logo

Cybersecurity Engineer (Research Infrastructure) in BERKELEY, California at MATS Research, Inc.

NewJob Function: Information Technology
MATS Research, Inc.
BERKELEY, California, 94704, United States
Posted on
New job! Apply early to increase your chances of getting hired.

Explore Related Opportunities

Job Description

About the organization

MATS finds and trains talented individuals for what we see as the world's most urgent and talent-constrained problem: reducing risks from unaligned artificial intelligence. We believe ambitious researchers from a variety of backgrounds have the potential to meaningfully contribute to alignment, control, security, and governance research. Through our research fellowship, we provide mentorship, training, professional network, and financial support to accelerate their careers and increase their impact.

Since 2021, we have trained over 630 researchers. 75% of pre-2026 fellows continue to work in AI alignment. 10% have co-founded organizations. Our fellows have produced 215+ research papers with 17,000+ citations. And we are just getting started: in the coming year we will expand our program to support even more researchers.


About the role

You are the security architect for our research pipeline. You will define how we securely conduct research across our compute cluster and cloud environments, partnering closely with our compute team and engineers to make CI/CD, automated research agents, and large-scale compute secure by default. You will build a hardened environment where researchers and agents iterate at speed without risking data leakage, supply-chain compromise, model exfiltration, or lateral movement between research environments.

We think about security in two closely related areas. The first is research and infrastructure security — the machine-operational attack surface: the compute cluster, CI/CD pipelines, cloud infrastructure, and model artefacts and pipelines, including potentially dual-use processes and artefacts. The second is IT security — the human-operational attack surface of accounts, devices, email, and vendors. This role focuses on the former. We grow the security team one hire at a time. Depending on hiring order, your initial responsibilities may span both areas, biased toward the research infrastructure side, until a second engineer joins.

Good security here is not a brake. It is what lets us say "yes, safely" to ambitious research, and what makes deeper lab partnerships possible. You will be working at the frontier of how automated alignment research is actually done — building the security primitives for a new way of doing science, where humans and machines collaborate on the most important problem of the 21st century.

What you'll do
  • Harden DevSecOps and CI/CD. Build security guardrails directly into our pipelines so that every deployment (manual or agent-driven) is automatically scanned, verified, and compliant. Establish workflows where agents can test their own code and infrastructure changes against security policies before reaching production. Lead the implementation of "compliance as code," automating the auditing and enforcement of security configurations across our AWS, GCP, and neocloud footprints in Terraform. Establish and harden the source-control environment for research code (e.g. GitHub): secret scanning, dependency and code scanning, and branch protections. Issue short-lived cloud credentials from CI rather than long-lived keys.
  • Secure the software supply chain. In an environment that relies heavily on automated coding agents, build systems that establish the provenance of code and dependencies: robust signing, SBOM generation (Sigstore, cosign), dependency and container scanning (Snyk, Trivy), and automated vulnerability management.
  • Define agent sandboxing and least-privilege execution. Set and enforce the security models for our research agents. Determine what an agent can compile, deploy, or call from inside the cluster, ensuring agents hold only the access required to run experiments while remaining isolated from sensitive IP and credentials.
  • Own multi-cloud and cluster security. Manage the security architecture for our high-compute research environments: consistent zero-trust network segmentation, role-based access control, FIDO, and cluster identity management across cloud providers and the cluster including the access model across the fellow cohort lifecycle (how cluster access is granted, reviewed, and reliably revoked at cohort end), using policy-as-code (OPA) where it fits. As MATS consolidates model and compute access across many providers into a unified layer, own its security design.
  • Harden the research cluster. Own Linux OS and node security across our SLURM cluster: kernel/CVE patching, the privileged-access (sudoers/PAM) model, multi-tenant isolation, and host-based detection.
  • Protect research data and model weights. Develop and maintain the data-handling and classification protocols needed for pre-publication research and potentially sensitive model weights, including how weights are stored, accessed, and moved.
  • Secure our research-data infrastructure. MATS is building infrastructure to capture, store, and share research and experiment data, including agent-trajectory data. Design the controls that keep it safe end-to-end: data classification and provenance, access control on shared datasets, privacy and consent handling for opt-in contributors, and secure adoption of tooling built with external research partners.
  • Monitoring and detection. Audit-log ingestion to our SIEM, anomaly detection on identity and workload behaviour, and egress monitoring across the cluster and the unified layer, so misuse or exfiltration attempts surface early enough to act on.
  • Enable frontier access. Partner with AI labs to navigate security audits, bridging our "move fast" research culture and the high-bar requirements of frontier model providers, so that compliance accelerates the research agenda rather than slowing it.
  • Own the cluster-side incident response capability. When something happens to the compute cluster, CI/CD pipelines, or model artefacts — a credential leak, a suspicious training job, an anomalous egress event, a supply-chain compromise alert — you are the first responder. That includes the cluster-specific IR playbook, coordinating with the IT Security Engineer on cross-cutting incidents, running tabletop exercises for cluster scenarios, and partnering with our external IR retainer firm for depth and after-hours coverage.
Essential skills and experience

We expect to hire someone who has all of the following:

  • Deep Linux systems-security experience on multi-user/HPC infrastructure (kernel/OS hardening, privileged access, host isolation, host-based detection). You also work fluently with Terraform and CI/CD systems (GitHub Actions, GitLab CI) writing the infrastructure-as-code that enforces your security model.
  • Experience securing cloud-native environments (AWS, GCP, and/or neoclouds), including the nuances of ephemeral, high-compute workloads.
  • Hands-on experience operating and securing an HPC scheduler; our cluster runs SLURM. Kubernetes is a plus.
  • The ability to threat-model against sophisticated adversaries and build systems robust against them.
  • A pragmatic approach to software supply-chain security and to the specific risks of AI-driven, agent-assisted development.
  • The ability to explain security trade-offs to researchers and leadership and to find the safe path to "yes."
  • Experience designing sandboxing and least-privilege execution for agent-driven or automated workloads.
Desired skills and experience

We expect highly competitive applicants to have some of the following:

  • Experience with the kind of stack we run or expect to run: model registries (MLflow, Weights & Biases); container and dependency scanners (Snyk, Trivy); policy-as-code (OPA); supply-chain tooling (Sigstore, cosign); and SBOM generators.
  • Experience with model-weight handling and the classification of sensitive or dual-use research artefacts.
  • A background that combines infrastructure engineering with security, from either direction.
  • Curiosity and genuine interest in MATS's mission. You don't need to be an AI safety expert, but you should care about the work and be motivated by its importance.
  • Experience with strongly segmented or air-gapped model-weight handling, hardware security modules, or FIPS-validated cryptographic controls.
  • Experience running continuous threat-hunting or red-team exercises against cloud and cluster infrastructure, or designing compartmentalised research environments where teams work behind separately-credentialed boundaries.
Your first year

A successful first year looks concrete: the cluster has a documented identity and access model; CI/CD is hardened against supply-chain attacks; dependency scanning catches issues pre-deploy; pre-publication research artefacts are classified and access-controlled; and we can credibly show frontier labs that our research infrastructure meets a recognised security bar (e.g. ISO 27001-equivalent) and their standards for sensitive partnerships.

About you

You are an infrastructure engineer who codes frequently and has built real security depth — or a security engineer with strong infrastructure-as-code experience. You are comfortable threat-modelling against sophisticated, potentially state-level adversaries and IP theft, and you write the IaC that encapsulates the model. You take a pragmatic view of modern software supply chains and understand the unique risks of AI-driven development and how to mitigate them without killing velocity. You can explain complex security trade-offs to lead researchers and scientists, saying "yes, safely" rather than just "no." You are willing to use AI tools aggressively in your own workflow, with appropriate care not to get fooled.

About the Compensation
  • MATS provides in-office, catered lunches and dinners to employees on workdays.
  • Paid work trips, including staff retreats, business trips, and relevant conferences.
  • Funding and support for professional development.
  • Flexible PTO for Berkeley-based employees.
  • Flexibility for hybrid work (but not for fully remote work).
  • Collaborative and intellectually stimulating work environment.
  • Medical, dental, vision, and life insurance.
  • Pension Scheme for London-based candidates, or both Roth and Traditional 401(k) for Berkeley-based candidates.

We can sponsor visas for exceptional candidates where feasible.

Working hours and location

40 hours per week. Successful candidates can expect to spend most of their time working in person from either our Berkeley office or London office. We are open to hybrid working arrangements for exceptional candidates.

Note while applying

If you use an LLM chatbot or other AI tools in this application, please follow the norms here. Applications will be reviewed on a rolling basis. MATS uses LLMs to help draft job descriptions, identify candidates to source, and transcribe interviews.

MATS is committed to fostering a diverse and inclusive work environment at the forefront of our field. We encourage applications from individuals of all backgrounds and experiences.

Join us in shaping the future of AI safety & security research!


The pay range for this role is:
155,000 - 220,000 GBP per year(Fora (London MATS Office))
250,000 - 340,000 USD per year(Berkeley MATS Office)

Job Location

BERKELEY, California, 94704, United States

Frequently asked questions about this position

Similar Jobs In BERKELEY, California

Urgently Hiring

Quality Assurance Technician II

RIX INDUSTRIES
Benicia, California
Hot Job

Crystal Optics Fabrication Technician

Gooch & Housego Pal Alto
Fremont, California

Diesel Technician/Mechanic II: $5,000 Sign-0n Bonus

Penske Truck Rental
SOUTH SAN FRANCISCO, California

Join Our Talent Network - California

Sigma Design
Burlingame, California
Apply For This Position

Apply Now