Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 4
Audit @ 6
Communication @ 7
Distributed Systems @ 6
Go @ 6
HPC @ 4
LLM
Machine Learning
Rust @ 6
Security @ 7
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Work cross-functionally with Anthropic teams and external partners to assess security features in hardware, firmware, bootloaders, operating systems, and attestation systems. The role focuses on identifying and fully eliminating vulnerabilities in security-critical platform elements and ensuring that known vulnerabilities are not reintroduced into production.
Responsibilities
- Audit secure boot chains from firmware through OS initialization across CPUs, BMCs, switches, peripherals, and embedded microcontrollers.
- Audit attestation systems that provide cryptographic proof of system state from the hardware root of trust through the application layer.
- Audit measured boot implementations and runtime integrity monitoring.
- Integrate security controls with infrastructure teams without impacting training performance.
- Validate security mechanisms before production deployment.
- Conduct firmware vulnerability assessments and penetration testing.
- Build firmware vulnerability assessment pipelines for continuous security monitoring.
- Document security architectures and maintain threat models.
- Collaborate with software and hardware vendors to ensure security capabilities meet requirements for exploit mitigation.
Requirements
- Proven track record conducting hands-on vulnerability audits of complex, security-critical systems.
- Hands-on experience with secure boot, measured boot, and attestation technologies, including TPM, Intel TXT, AMD SEV, and ARM TrustZone.
- Strong understanding of cryptographic protocols and hardware security modules.
- Experience with UEFI/BIOS or embedded firmware security, bootloader hardening, and chain-of-trust implementation.
- Proficiency in low-level programming languages such as C and Assembly, as well as systems programming.
- Knowledge of firmware vulnerability assessment and threat modeling.
- Ability to work effectively across hardware and software boundaries.
- Strong communication and cross-functional collaboration skills.
- Track record assessing security architectures for complex, distributed systems.
- Preferred: 8+ years of experience in systems security, including at least 5 years focused on low-level security involving firmware, bootloaders, and OS kernel-level security.
- Preferred: Ability to audit logic bugs in Rust or Go code.
- Preferred: Experience finding vulnerabilities through reverse engineering of binary-only software.
- Preferred: Experience with fault injection and side-channel analysis attacks on hardware.
- Preferred: Experience auditing silicon roots of trust, confidential computing technologies, and hardware-based TEEs.
- Preferred: Background in formal verification or security proof techniques.
- Preferred: Five or more first-author talks at top-tier security conferences.
- Preferred: Experience using LLMs to automate security assessments, including tooling creation.
- Preferred: Experience securing large-scale HPC or cloud infrastructure and AI/ML infrastructure.
Education And Experience
- Minimum education: Bachelor’s degree or an equivalent combination of education, training, and/or experience.
- Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience.
- Minimum years of experience correlate with the internal job level requirements for the position.
Compensation
- Annual salary: $320,000–$405,000 USD.
Benefits And Logistics
- Hybrid policy requiring staff to work from one of the company’s offices at least 25% of the time; some roles may require more office time.
- Visa sponsorship is available, although sponsorship cannot be guaranteed for every role or candidate. Anthropic retains an immigration lawyer to provide assistance.
- Competitive compensation and benefits, optional equity donation matching, generous vacation and parental leave, flexible working hours, and office collaboration space.
More jobs at Anthropic
Staff Software Engineer, Claude Code
Anthropic · San Francisco, United States, New York City, United States, Seattle, United States
USD 320,000-625,000 per year
Applied AI Architect, Enterprise Tech
Anthropic · San Francisco, United States, New York City, United States
USD 240,000-315,000 per year
Finance Systems Engineer, Tax
Anthropic · San Francisco, United States, Seattle, United States
USD 205,000-270,000 per year
AI Fluency Education Lead
Anthropic · San Francisco, United States, New York City, United States
USD 270,000-365,000 per year
Staff+ Software Engineer, Infrastructure (Distributed Systems)
Anthropic · San Francisco, United States, New York City, United States, Seattle, United States
USD 320,000-485,000 per year
Similar jobs
Security Controls Assurance Lead
Anthropic · Washington, United States, New York City, United States, San Francisco, United States
USD 270,000-345,000 per year
Senior Software Engineer, AI Inference Systems
Nvidia · Santa Clara, United States
USD 184,000-356,500 per year
Member of Technical Staff (Software Engineer, GPU Cluster Infrastructure)
Perplexity AI · United States, San Francisco, United States, New York City, United States, Seattle, United States
USD 250,000-485,000 per year
Forward Deployed Engineer - Physical AI Cloud Platform
Nebius · United States, Austin, United States
USD 179,500-224,300 per year
Principal Engineer - Enterprise Content and AI Data Platform
Nvidia · Santa Clara, United States
USD 248,000-391,000 per year
Resident Solutions Architect
Glean · United States
USD 170,000-240,000 per year
Senior Platform AI Engineer
Nvidia · Santa Clara, United States
USD 184,000-356,500 per year
Senior Security Engineer, AI Security
Reddit · United States
USD 190,800-267,100 per year