Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 4
API @ 6
Bash @ 6
ChatGPT
Codex
JavaScript @ 6
LLM @ 4
PowerShell @ 6
Python @ 6
QA @ 4
SQL @ 6
Security @ 7
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Critical Harm Operations sits within User Safety & Risk Operations and builds enforcement systems for Frontier Risk and Material Harm that are accurate, fast, defensible, and built to scale. The Cyber vertical turns policy into reviewer standards, calibrated judgment, quality systems, escalation paths, and automation guardrails.
This senior individual contributor role combines hands-on cybersecurity judgment with systems-level operating design. The successful candidate will resolve complex dual-use questions, evolve standard operating procedures, improve reviewer and vendor capabilities, and build practical tools and automations. Success is measured by durable improvements to the operating model and the reviewers who run it.
The Toronto-based role is currently remote and is expected to transition to an in-office arrangement.
Responsibilities
- Drive the Cyber Operations operating model across domain priorities, SOPs, escalation paths, quality health, vendor capability, roadmap inputs, and trusted access strategies.
- Serve as the senior cyber expert for complex or high-risk decisions across ChatGPT, API, Codex, agents, and emerging product surfaces.
- Translate policy ambiguity, quality misses, appeals, and reviewer disagreement into clear decision rules, calibration examples, training, and tooling requirements.
- Build durable operating systems and quality loops, including golden sets, holdouts, double-labeling, adjudication, error taxonomies, reviewer calibration, and automation evaluations.
- Raise FTE and BPO capability through onboarding, certification, coaching, recurring calibration, and vendor-performance partnership.
- Use quality, appeals, SLA, backlog, and disagreement signals to diagnose root causes and prioritize high-leverage fixes.
- Build hands-on solutions, including SQL analyses, scripts, dashboards, LLM evaluation workflows, evidence enrichment, routing logic, and lightweight automations, to improve decision quality and reduce manual effort.
- Partner with Policy, Integrity, Safety Systems, Security, Legal, Product, Engineering, and Investigations to operationalize changes and drive launch readiness.
Requirements
- 8+ years of hands-on cybersecurity experience in offensive security, threat intelligence, incident response, security research, red teaming, application security, DFIR, malware analysis, or a related field.
- Deep understanding of attacker tradecraft, vulnerability exploitation, credential abuse, malware, persistence, evasion, exfiltration, cloud or identity abuse, and ambiguous dual-use activity.
- Experience building or improving high-stakes operations, reviewer programs, QA systems, escalation workflows, or vendor/BPO programs.
- Ability to turn complex cybersecurity and policy judgment into reviewer-usable SOPs, decision trees, training, and concise written recommendations.
- Comfort using SQL, Python, C/C++, JavaScript, PowerShell, Bash, APIs, LLM tooling, or automation to solve operational problems.
- Understanding of human-in-the-loop automation, evaluations, monitoring, holdouts, and fallback paths for sensitive workflows.
- Ability to operate independently in ambiguity, communicate clearly across technical and non-technical audiences, and exercise sound judgment and discretion when handling sensitive material.
- Experience with trust and safety, platform abuse, cyber misuse of AI systems, or LLM safety.
Nice to Have
- Experience with golden sets, classifier or prompt evaluations, and reviewer-quality programs.
- Experience enabling global vendor reviewer operations.
Benefits
- Base salary of CA$140,000–CA$188,000.
- Equity.
- Medical, dental, and vision insurance for employees and their families.
- Paid parental leave of up to 24 weeks for birth parents and 20 weeks for non-birthing parents.
- Paid time off accruing at 20 days per calendar year.
- 12+ paid company holidays, paid coordinated company office closures, and paid sick time.