Next steps: Apply to roles
Unit 6 has walked you from "I finished a course" to "I have a focus and a one-pager." This chapter is where the abstraction ends and URLs begin. It exists because the most common failure mode at this exact point is not rejection — it is never applying, on the theory that six more months of reading will make you legible. The chapter's implicit claim is that the field is small enough and young enough that legibility comes from doing, and the fastest way to do is to get hired by one of the roughly two dozen organisations that already have the funding and the problems.
Why "not ready" is usually the wrong diagnosis
The single link in the chapter's body text is a survey BlueDot ran across more than ten safety organisations, asking what they were actually short of. The answer was not "people with alignment PhDs." It was people who can take a poorly-specified problem, own it end to end, and not need a manager to convert it into tickets — plus genuine, non-performative concern about the risk. That combination is rare in any field. It is not, however, a thing you acquire by reading more papers.
"Given that relatively few people can claim 5+ years of direct AI safety experience, orgs are looking for the next best thing"— We asked 10+ AI safety orgs about their hiring needs, Li-Lian Ang (2026)
The corollary is the useful part. If the scarce thing is ownership rather than domain tenure, then your five years of distributed-systems work, or your track record of shipping production ML, or your experience running a government programme, is not a handicap you have to apologise for in a cover letter. It is the qualification. What you are missing is the field's vocabulary and its open questions — the survey names context as the real barrier:
"The biggest barrier for capable talent entering the field is context"— We asked 10+ AI safety orgs about their hiring needs, Li-Lian Ang (2026)
Context is what a course, a weekend replication, and a careful reading of one org's last three papers buys you. It is measured in weeks. Deciding to wait for it costs you a hiring cycle.
The field is not one kind of employer
Reading the twelve organisations below as a flat list hides the most decision-relevant thing about them: they are funded differently, and funding shapes what the job feels like day to day. Five rough shapes, and the list maps onto them cleanly.
Philanthropically funded nonprofits — METR, Redwood, Epoch, FAR.AI, CivAI, MATS, AI Digest. Freedom to work on things with no buyer; the flip side is that the work is only as durable as the next grant cycle, and headcount moves in steps rather than smoothly. Compensation at the larger ones is nonetheless competitive with industry: METR publishes technical-staff bands starting in the low-to-mid six figures.
Venture-backed companies whose product is safety research — Goodfire, and to a different degree Apollo, which sells a security product alongside its scheming research. The bet here is commercial-incentive alignment: if customers pay for interpretability, the company gets to do more interpretability. Worth stress-testing in interviews — ask what happens to the research agenda when a large customer wants something adjacent to it.
Liability and assurance plays — AIUC. This is the least AI-safety-shaped org on the list and arguably the most interesting structural bet: if agents cannot be deployed at scale until someone underwrites the downside, then the underwriter's audit standard becomes a de facto safety regulation with a market behind it.
Government — the UK AI Security Institute. Different currency entirely: statutory access to frontier models pre-deployment, and a research output (Inspect) that half the field now runs its evals on. You trade equity upside and speed for reach.
Profit-subsidised research — AE Studio, which funds an in-house alignment team from consulting revenue. The unusual property is that the research team is not fundraising, so it can chase directions nobody else will fund.
What a strong application looks like from the other side of the table
Most of these teams are between 3 and 50 people. There is no requisition machinery, no keyword screen, and frequently the person reading your application is the person you would report to. Three practical consequences.
First, specificity beats enthusiasm. "I care about AI risk" is the baseline, not a differentiator — every applicant writes it. "Your time-horizons methodology assumes X, and I think the assumption breaks for agentic coding tasks because Y" is a differentiator, and it takes an afternoon.
Second, artefacts beat claims. A small public replication, a plot, a short writeup, a merged PR against an open eval harness — anything that lets a reader verify your reasoning without trusting you. Unit 6's one-pager exercise is the minimum version of this; a repo is the better one.
Third, apply broadly and in parallel. The variance between orgs on what they select for is enormous — Redwood is hiring for one role at extreme seniority, Apollo has fourteen open across governance, security engineering and control research, FAR.AI is hiring red-teamers remotely and researchers on-site. Self-rejecting from the whole list because you do not fit the first entry is a category error.
Readings, linked
The course budgets no fixed reading time here — it is a directory, and the intended use is to skim all twelve, pick three, and apply. Read the hiring-needs survey first; it calibrates everything below. Org descriptions are the course's; role counts, locations and salary bands were checked against each employer's live job board in September 2026 and are marked as such, because these change weekly.
- Apollo Research — independent research org on scheming and strategic deception in frontier models · London, with staff also in San Francisco; ~28 people · careers — builds evals and monitoring that frontier labs run pre-deployment, so the work has an immediate consumer. As of Sept 2026 the board shows ~14 openings across Scheming Research (evaluations, science of scheming), Product (control research, red-team engineering, full-stack), Infrastructure & Security, and Governance; visa sponsorship offered on eligible roles. Course note: CEO Marius Hobbhahn is a BlueDot alumnus — background interview: Inside Apollo: Science of Scheming & AGI safety products (BlueDot Impact).
- Goodfire — VC-backed mechanistic interpretability company; Anthropic's first corporate investment, ~$209M raised, ~50 people · careers — the commercial thesis is that reverse-engineering foundation models produces sellable science, which points the revenue and the interpretability in the same direction. Openings as of Sept 2026 span research (Research Scientist, Research Lead — Training), engineering (ML, product, forward-deployed, security architecture) and a large go-to-market function; roles are San Francisco-based and in-person five days a week, with a Research Scientist post in London and ML roles listing New York. Co-founder Dan Balsam is a BlueDot alumnus — background interview: Inside Goodfire: Building safer AI systems with interpretability (BlueDot Impact). Note: the course links
goodfire.ai, which now redirects togoodfire.com. - AI Underwriting Company (AIUC) — certification and insurance for AI agents; San Francisco, $15M seed led by Nat Friedman · team & open roles — the bet is that enterprise agent adoption is gated on unresolved liability, so an independent standard (AIUC-1) plus underwriting unblocks it. Openings as of Sept 2026 are founding-team shaped: AIUC-1 Security, AIUC-1 Standard, Deployment Strategist, Enterprise GTM, Content Lead, all San Francisco. Founding team draws from Anthropic, METR, CAIS and McKinsey's insurance practice; co-founder Rajiv Dattani is a BlueDot alumnus and METR's former COO. Best fit if you want safety work with a commercial forcing function rather than a grant cycle.
- Epoch AI — nonprofit tracking the empirical trajectory of AI: compute, data, algorithmic progress, benchmarks · global/remote, ~27 people · careers — their datasets are the numbers everyone else's arguments are built on, which makes this unusually high-leverage for a data-shaped person. Sept 2026 openings include Researcher / Senior Researcher, Software Engineer (Benchmarking), part-time Data Scientist, plus media and operations roles. Note the course's link (
epoch.ai/careers) now redirects to/about/careers. Good entry point if your strength is measurement and communication rather than model internals. - METR — nonprofit measuring whether frontier models can autonomously do dangerous things: cyber operations, self-replication, evading oversight · Berkeley, ~35 people · careers — they run pre-deployment evaluations with OpenAI and Anthropic, so the work is on the critical path of actual release decisions. Sept 2026 postings include Member of Technical Staff in Evaluation Execution, Security Engineering, Embedded Assessments and Cyberforensics (Berkeley, mostly on-site, published bands roughly $328K–$687K), plus a remote Task Development Engineer contractor role at $150–300/hr — that contractor path is the lowest-friction way onto this list for a strong engineer who cannot relocate.
- CivAI — nonprofit that demonstrates AI risk to policymakers through live, interactive software rather than papers · Berkeley and DC, small team · jobs — 100+ briefings delivered since 2023, including to NIST and around the Paris AI Action Summit, with coverage in the NYT, WaPo and Reuters. Sept 2026 openings: R&D Member of Technical Staff (Berkeley), Policy Director and Policy Analyst (Berkeley or DC), Product Designer (Berkeley), Program Manager (Berkeley); they also run a $3,000 referral bounty. The rare place where front-end and design skill is a safety qualification rather than a side interest.
- FAR.AI — nonprofit running four things at once: in-house alignment research, global events, a Berkeley co-working space for safety researchers, and a ~$12M grantmaking programme · ~40 people, $30M+ in 2025 commitments · careers — the breadth means the org hires people who are not researchers as readily as people who are. Sept 2026 openings include Research Scientist / Research Engineer / Research Lead (Berkeley, on-site) and a distinctly separate remote-international red team — Jailbreaking Lead, Engineering Manager (Red Team), Technical Project Manager (Red Team) — plus operations, events and people roles remote in the US. The remote red-team roles are one of the few genuinely location-flexible technical openings in the field.
- MATS — nonprofit running the field's largest AI safety research talent pipeline · Berkeley and London · careers — the point the course is making is that MATS also hires staff, not just fellows, and the staff jobs are the ones with real leverage over who enters the field. Sept 2026 openings with stated deadlines: Research Manager (Berkeley / London / DC, 1 Oct 2026); Program Manager — Mentor Selection, Program Coordinator, and Impact Analyst (20 Nov 2026). Also General Counsel, Head of Finance, Community Manager and executive roles. Headcount is ~65 and growing — the course's "~44 staff, planning to double" is already stale in the right direction. Co-led by Ryan Kidd, a BlueDot alumnus. (Applying to the fellowship is the next chapter.)
- Redwood Research — nonprofit that defined the AI control agenda: making systems safe given that they may be misaligned, rather than by assuming they are not · Berkeley, ~14 people · careers — small, senior, and unusually influential per head; the alignment-faking work with Anthropic and the control safety case with UK AISI both came from here. As of Sept 2026 they list essentially a single opening, Member of Technical Staff in Berkeley, with a published band of $350K–$850K. Highest bar on this list; apply anyway if control is your thing, because there is nowhere else to do exactly this.
- AE Studio — software consultancy that funds its own alignment research out of client revenue · Los Angeles plus US and Brazil remote, ~150 people · join us — the alignment team explores neglected directions precisely because it is not grant-dependent; recent work includes a collaboration with Anthropic on CBRN misuse mitigation. Sept 2026 openings include Alignment Scientist/Engineer and Alignment Research Manager (fully remote, US), plus applied data science and product engineering. The most accessible entry on this list for someone who wants to keep shipping product while moving toward safety work, and one of very few fully-remote alignment research jobs anywhere.
- AI Digest — interactive demos and explainers that make AI progress legible to non-specialists; run by the nonprofit Sage · remote, ~3 people · hiring — best known for AI Village, where frontier agents pursue long-horizon goals in a shared environment on a daily livestream. The course notes a Member of Technical Staff opening; as of Sept 2026 that has expanded to Engineer, Research Scientist and Design Engineer (all remote, ~$150–350K) plus part-time video roles. A three-person team means enormous scope per person and no scaffolding — good if you are self-directing, bad if you are not. Director Adam Binks is a BlueDot alumnus.
- UK AI Security Institute — government research organisation inside DSIT that tests frontier models for dangerous capabilities before release · London, with hybrid options in Birmingham, Bristol, Cardiff, Darlington, Edinburgh and Salford; 100+ technical staff · careers — they built and open-sourced Inspect, now a default evals framework across the field, and 10+ BlueDot facilitators and alumni work there. Technical hiring sponsors visas for almost all nationalities; non-technical roles are bound by civil service nationality rules. Compensation is base salary plus a "technical talent allowance." Timing note: the careers page showed no open roles when checked in Sept 2026 — AISI hires in waves, so register interest and watch rather than concluding it is closed. The org's formal name is now the AI Security Institute (it was the AI Safety Institute until early 2025).
Exercises
The course sets no exercises on this page — it is a resource directory, and the intended action is simply to apply. The three below are field map extras, built so that finishing them leaves you with something you can attach to an application.
- The five-column shortlist (field map extra) — Take all twelve organisations above and put them in a table with five columns: what they'd hire me to do, funding model (grant / VC / revenue / government), location constraint, what I'd have to learn in month one, and one specific thing I disagree with or don't understand about their work. Fill the last column from their own writing, not from summaries. Then cut to three and apply this week. What a good answer has: a last column that is specific enough to be wrong — "I don't see how METR's time-horizon metric handles tasks where the bottleneck is tool latency rather than reasoning" beats "I'd like to understand their methodology better." That column is your cover letter's opening paragraph, and it is the part a hiring manager cannot skim past.
- Ship one verifiable artefact code (field map extra) — Pick one org from your shortlist and produce a small public artefact aimed at its actual problem: a mini-eval, a probe, a replicated plot, a red-team transcript. Target a weekend, not a quarter. What a good answer has: a public repo with a README stating the question, the method, the result, and — critically — what the result does not show; a plot or table someone can read in ten seconds; and honest limitations. Reviewers trust a small clean negative result far more than a sprawling positive one. Start here: (1) install Inspect (
pip install inspect-ai) — it is the framework AISI built and much of the field uses, so the code itself is a signal; (2) pick a narrow capability question you can score automatically, e.g. "does the model follow an injected instruction embedded in a tool result?"; (3) write 30–50 task samples by hand or generate and then hand-check them; (4) run against a small open model you can host on a laptop or free Colab — Qwen3-4B or Llama-3.2-3B viatransformersorollama— plus one frontier API model if you have credits, so you have a contrast; (5) plot the two, write 300 words on why they differ; (6) publish and link it in the application. If interpretability is your target instead, swap Inspect for TransformerLens and replicate a single figure from a Goodfire or Anthropic paper. - The rejection budget (field map extra) — Decide, in writing and before you send anything, how many rejections you will collect before you change strategy. Then send that many applications. What a good answer has: a number greater than one and a written trigger — "after eight rejections with no first-round interview, the problem is my artefact, not my targeting; after eight first-rounds with no offer, it is the interview." This exercise exists because the failure this chapter is written against is not being rejected; it is applying once, treating a single "no" as evidence about the field, and quietly stopping.
Go deeper
- We asked 10+ AI safety orgs about their hiring needs — Li-Lian Ang, BlueDot (Feb 2026). The chapter's only body link and the argument underneath the whole page: what orgs are short of, broken down by engineering, research, comms and policy.
- 80,000 Hours job board — the widest curated listing of high-impact roles, filterable by AI safety and technical. Covers everything on this page plus frontier-lab safety teams, think tanks and government posts the course does not name.
- AISafety.com jobs — community-maintained and updated faster than any editorial board; the right cross-check for whether an org that looks quiet is actually hiring.
- AI safety technical research — career review — 80,000 Hours' long-form treatment of the path: what the day job is at each org type, what backgrounds convert well, and the honest case against.
- Inspect — AISI's open-source evals framework. Worth an afternoon regardless of where you apply: it is the shared vocabulary of the evals half of this field, and building something small in it is the cheapest legible signal available.