Security Engineer, Detection & Response
📍 New York City, United States
📍 San Francisco, United States
📍 Seattle, United States
Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Communication @ 6
IaC
Kubernetes @ 3
LLM
Python @ 5
SQL @ 5
Security @ 5
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Anthropic is seeking a Detection and Response Engineer to build security capabilities for monitoring threats, investigating incidents, and coordinating response efforts across the technology stack. The role involves developing tooling that may leverage large language models and working with research, security, and engineering teams. Participation in an on-call rotation is required.
Responsibilities
- Lead cybersecurity incident response efforts covering external attacks, insider threats, and all layers of Anthropic’s technology stack.
- Develop and deploy tooling to improve detection, investigation, and response capabilities, potentially using large language models.
- Create and optimize detections, playbooks, and workflows for identifying and responding to incidents.
- Review incident response metrics and procedures and drive continuous improvement.
- Collaborate cross-functionally with security and engineering teams.
- Participate in an on-call rotation.
Requirements
- At least 3 years of software engineering experience, with security experience preferred, and/or at least 5 years of detection engineering, incident response, or threat hunting experience.
- Solid understanding of cloud environments and operations.
- Experience working with engineering teams in a SaaS environment.
- Strong communication and collaboration skills.
- Ability to lead projects with limited guidance.
- Ability to learn new programming languages and technologies quickly.
- Experience handling security incidents and investigating anomalies as part of a team.
- Knowledge of EDR, SIEM, SOAR, or related security tools.
- Bachelor’s degree or an equivalent combination of education, training, and experience in a field relevant to the role.
Preferred Qualifications
- Experience with security operations or investigations involving large-scale Kubernetes environments.
- Proficiency in Python and query languages such as SQL.
- Experience analyzing attack behavior and prototyping high-quality detections.
- Experience with threat intelligence, malware analysis, infrastructure as code, detection engineering, or forensics.
- Experience contributing to a high-growth startup environment.
Benefits
Anthropic offers competitive compensation and benefits, optional equity donation matching, generous vacation and parental leave, flexible working hours, and office spaces for collaboration. Staff are currently expected to work from one of the company’s offices at least 25% of the time.
Anthropic sponsors visas where possible and retains an immigration lawyer to assist with the process.