Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 4
Communication @ 7
HPC @ 4
Hiring @ 6
Linux @ 6
Security @ 8
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Platform Security Engineering is part of Data Center Security Engineering and is responsible for the security controls required to operate Anthropic training and inference workloads across owned facilities, colocation environments, partner sites, and bare-metal infrastructure. The team focuses on firmware integrity, boot-chain verification, platform trust, host hardening, and the technical controls supporting AI Safety Level commitments.
This hands-on management role will lead platform security engineers working across firmware research, OS and kernel hardening, platform trust integration, and server manageability firmware. The manager will own the group’s roadmap, grow the team, and be accountable for the security posture of Anthropic’s compute platforms, including hardware roots of trust, secure and measured boot, attestation, firmware supply chain security, and host integrity. The role partners with infrastructure, fleet, and compute teams, as well as silicon vendors, OEMs, and compute providers.
Responsibilities
- Lead and grow the platform security engineering group, including hiring, onboarding, development, performance management, and prioritization.
- Coordinate contractor and vendor engineers working alongside full-time engineers.
- Own the platform security roadmap and delivery across hardware roots of trust, attestation, secure and measured boot for CPUs, BMCs, accelerators, and peripheral firmware, OS and kernel hardening, and host-side attestation pipelines.
- Own firmware supply chain security, including SBOMs, reference integrity manifests, authenticated updates, rollback protection, and vendor remediation relationships.
- Drive platform risk assessments for new compute platforms and providers and make evidence-based go/no-go recommendations.
- Partner with infrastructure, fleet, compute, and detection and response teams to deploy platform controls without degrading training or inference performance.
- Manage relationships with silicon vendors, OEMs, and cloud and bare-metal compute providers regarding security requirements, vulnerability management, disclosure, remediation timelines, and standards engagement with TCG, OCP, and IETF.
- Run design reviews, threat modeling, platform-layer incident participation, and written status reporting for security and infrastructure leadership.
Requirements
- 10+ years of experience in systems security, including at least 5 years focused on firmware, hardware, or OS-level security.
- 5+ years as a people manager of security or systems engineers, including hiring and developing senior and staff-level engineers.
- Ability to reason from architecture through implementation details involving secure boot, measured boot, TPM and other roots of trust, SPDM, DICE, remote attestation, UEFI, BMC firmware, and Linux kernel and OS hardening.
- Experience owning technical roadmaps end to end and prioritizing trade-offs among security, performance, and delivery timelines.
- Experience working directly with silicon vendors, OEMs, cloud providers, or bare-metal providers on security requirements and remediation.
- Strong written communication skills for design reviews, risk assessments, and executive status updates.
- Ability to build an early-stage team and its processes with scope broader than current headcount.
- Bachelor’s degree or equivalent combination of education, training, and experience in a relevant field.
Preferred Qualifications
- Experience managing mixed teams of full-time engineers, contractors, and vendor engineers while retaining design authority in-house.
- Hands-on experience with OpenBMC or other server management firmware, DRTM or secure launch, or confidential computing primitives such as TDX, SEV-SNP, or ARM CCA.
- Upstream contributions or maintainership in Linux, OpenBMC, or a comparable community, or participation in TCG, the UEFI Forum, or OCP.
- Experience securing large-scale HPC or AI training infrastructure.
- Firmware vulnerability research, reverse engineering, or fuzzing experience.
- Experience running coordinated vulnerability disclosure with hardware or firmware vendors.
Benefits
Anthropic offers competitive compensation and benefits, optional equity donation matching, generous vacation and parental leave, flexible working hours, and office space for collaboration. Staff are expected to work from one of the company’s offices at least 25% of the time. Anthropic explicitly states that it sponsors visas and will make reasonable efforts to support visa applications with an immigration lawyer.