Security Engineer, Corporate Security
📍 New York City, United States
📍 San Francisco, United States
📍 Seattle, United States
Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 4
CI/CD @ 4
ChromeOS @ 4
IaC
LLM @ 4
Linux @ 4
OAuth
Python @ 6
Security @ 7
macOS @ 4
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Corporate Security protects Anthropic’s laptops, phones, identities, collaboration tools, and company data. The team treats corporate security as an engineering discipline, emphasizing controls as code, automation, scalability, and a strong employee experience.
This is a senior, hands-on individual contributor role responsible for driving significant parts of the corporate security program end to end, setting technical direction, shipping tooling, threat-modeling the environment, fixing security issues, and producing evidence to guide prioritization.
Responsibilities
- Drive endpoint hardening across macOS, Windows, Linux, and ChromeOS, including device management configuration, application allowlisting, patching, and browser policy.
- Build controls that are versioned, reviewable, and repeatable rather than relying on one-off configuration.
- Extend device-trust and zero-trust access controls so company systems are accessed from managed devices associated with the correct person and access level.
- Build automation and integrations for joiner, mover, and leaver workflows across identity and device management.
- Develop exception and expiry workflows, posture-driven policy, and Claude-assisted triage of review queues.
- Lead SaaS and identity governance, including third-party OAuth grants, delegated administrator access, chat-platform applications, browser extensions, and software security reviews.
- Partner with Security, IT, and Engineering on telemetry, detections, and shared standards.
- Help define how a company increasingly using AI agents can operate securely and at scale.
Requirements
- Hands-on endpoint security engineering experience on macOS, Windows, Linux, or ChromeOS.
- Experience with MDM and declarative device management profile engineering, application allowlisting or binary authorization, system extensions, endpoint security frameworks, or equivalent platform technologies.
- Proficiency in Python and general scripting languages, including the ability to build integrations, automation, internal tooling, and detections.
- Working-depth knowledge of identity and access management, SaaS security, and zero-trust access.
- Threat-modeling judgment and the ability to scope problems, define completion criteria, and drive work to completion.
- Care for Anthropic’s mission and the role corporate security plays in it.
- A bachelor’s degree or equivalent combination of education, training, and experience. The field of study must be relevant to the role through coursework, training, or professional experience.
Preferred Qualifications
- Experience defining the scope and selecting tooling for a security program.
- Experience shipping enforcement changes to large user populations, including impact analysis, staged rollouts, alternative workflows, and adoption planning.
- Endpoint security depth across multiple operating systems, including macOS, Windows, Linux, and ChromeOS.
- Mobile security experience across managed and BYOD environments, including higher-risk settings such as international travel.
- Experience applying security governance to modern SaaS environments, including third-party integrations, delegated access, internally built applications, and AI-generated applications.
- Experience with configuration as code, infrastructure as code, and CI/CD applied to corporate infrastructure.
- Experience building LLM-assisted security tooling that materially expanded team coverage.
- A track record of getting security controls adopted through influence and partnership.
Benefits
Anthropic offers competitive compensation and benefits, optional equity donation matching, generous vacation and parental leave, flexible working hours, and an office environment for collaboration. Staff are currently expected to work from one of the company’s offices at least 25% of the time, although some roles may require more office time. Anthropic sponsors visas and makes reasonable efforts to assist with visa processing, using an immigration lawyer.