Platform Security Engineer, DRTM / Secure Launch

USD 320,000-405,000 per year
SENIOR
✅ Hybrid
✅ Visa Sponsorship

Tech Stack

AI @ 6 Communication @ 6 Debugging @ 4 Leadership @ 7 Linux @ 7 Machine Learning Rust @ 4 SMM @ 7 Security @ 4

Details

Anthropic is building the platform security foundation for the infrastructure that trains and serves frontier models. This role owns Dynamic Root of Trust for Measurement (DRTM) across the fleet, including deployment on x86 and ARM, attestation and isolation capabilities, and hardening of platform components not covered by DRTM.

The work operates at the firmware, bootloader, kernel, and silicon layers. The role is expected to contribute upstream and participate visibly in the Linux and firmware communities. You will partner with firmware security, hardware, and OS hardening engineers, as well as vendor and OEM partners.

Responsibilities

DRTM Adoption and Integration

  • Own adoption and integration of DRTM hardware security features across Anthropic infrastructure on x86 and ARM platforms.
  • Implement attestation services and the additional security and privacy capabilities enabled by DRTM.
  • Design and implement a bootloader-agnostic solution for initiating and relaunching DRTM sessions.
  • Investigate further hardening of existing DRTM solutions, including PPAM to isolate SMM on x86, VMM features to isolate UEFI runtime services, and ACPI handling and hardening in DRTM environments.

Vendors and Upstream Contributions

  • Interface with vendor and OEM partners on DRTM solutions, jointly refining requirements and determining desirable and feasible changes.
  • Publish relevant DRTM work upstream and help maintain Linux Secure Launch as tboot is retired.
  • Act as a technical lead in architecture and design.
  • Disseminate work through technical papers, conference talks, and community engagement.
  • Assist other Anthropic teams with open-source efforts and upstream interactions.

Broader Low-Level Platform Work

  • Build and harden other platform security features, including confidential computing solutions such as TDX and SEV.
  • Support custom operating system artifacts, implement device drivers for custom hardware and features, and perform firmware diagnosis and enhancement work.
  • Debug and diagnose kernel and system-level issues on production hardware.
  • Investigate new technical areas and unresolved problems, including distinct security issues in dTPMs and fTPMs.

Requirements

Minimum Qualifications

  • Deep hands-on experience with measured boot and roots of trust, including DRTM such as Intel TXT, AMD SKINIT, and ARM equivalents; SRTM; TPM 1.2/2.0; and the measurement chains built on them.
  • Strong C and assembly skills, with deep Linux kernel and early-boot fundamentals, including bootloaders, UEFI, ACPI, and SMM.
  • A record of landing non-trivial work upstream in Linux, TianoCore, GRUB, or a comparable community.
  • Experience at the hardware and firmware boundary, including JTAG, serial debugging, platform-level bring-up, and silicon errata.
  • Strong technical cross-functional leadership and direction-setting skills, including work with external vendors and OEMs.
  • Clear written communication skills for producing specifications, design documents, and public technical writing.
  • Working knowledge of NIST firmware security guidance, particularly SP 800-193 and SP 800-147/155.

Preferred Qualifications

  • Eight or more years in systems security, including at least five years focused on firmware, bootloader, and OS-level security.
  • Existing maintainership or subsystem ownership in Linux, or standing in the TCG, UEFI Forum, or OCP communities.
  • Confidential computing implementation experience with TDX, SEV-SNP, ARM CCA, and related attestation flows.
  • Experience with hardware roots of trust and attestation beyond TPM, including Caliptra, OCP S.A.F.E., and SPDM.
  • Experience writing memory-safe systems code in Rust.
  • Firmware vulnerability research, reverse engineering, or fuzzing experience.
  • Previous work with AI/ML infrastructure security.

Education and Experience

  • Minimum education: Bachelor's degree or an equivalent combination of education, training, and/or experience.
  • Required field of study: A field relevant to the role, as demonstrated through coursework, training, or professional experience.
  • Required years of experience correlate with the internal job-level requirements for the position.

Benefits and Logistics

  • Annual salary: $320,000–$405,000 USD.
  • Location-based hybrid policy: Staff are expected to be in one of the company's offices at least 25% of the time, although some roles may require more office time.
  • Anthropic sponsors visas and states that it will make every reasonable effort to obtain a visa for an offer recipient, with immigration lawyer support.
  • Anthropic offers competitive compensation and benefits, optional equity donation matching, generous vacation and parental leave, flexible working hours, and office space for collaboration.

More jobs at Anthropic

Similar jobs