Security Engineer - Threat Intel

USD 320,000-405,000 per year
SENIOR
✅ Hybrid
✅ Visa Sponsorship

Tech Stack

AI @ 4 AWS @ 4 Data Pipelines @ 4 GCP @ 4 Kubernetes @ 4 LLM Machine Learning Python @ 4 Security

Details

Anthropic's Threat Intelligence function within the Detection & Response team produces actionable intelligence to help defend against nation-state and advanced criminal actors targeting frontier AI labs. This hands-on engineering role focuses on tracking relevant adversaries, building intelligence tooling and pipelines, and partnering with detection engineers and incident responders to operationalize intelligence.

Responsibilities

  • Research, track, and report on threat actors and campaigns targeting AI labs, cloud infrastructure, and the broader technology sector.
  • Build and maintain tooling and automated pipelines to collect, enrich, correlate, and operationalize indicators of compromise in detection and alerting systems.
  • Develop and execute intelligence-driven threat hunts across endpoint, cloud, identity, and SaaS telemetry, and turn findings into durable detections.
  • Perform technical analysis of malware, phishing infrastructure, and attacker tooling to extract indicators, tactics, techniques, procedures, and attribution signals.
  • Partner with Detection Engineering and Incident Response to translate intelligence into detection rules, hunting hypotheses, and incident context in near-real time.
  • Curate and triage intelligence from commercial feeds, open sources, government sources, and trusted peer relationships.
  • Contribute to threat models and risk assessments that inform security architecture and defensive investment.
  • Build and maintain external intelligence-sharing relationships with peer companies, ISACs, and government partners.

Requirements

  • 5+ years of hands-on experience in cyber threat intelligence, threat hunting, or intrusion analysis at an organization facing sophisticated adversaries.
  • Deep, demonstrable knowledge of specific nation-state or advanced criminal threat actors, including their tooling, infrastructure patterns, tradecraft, and targeting.
  • Production-quality Python or similar programming experience, including building automation and data pipelines.
  • Experience with malware analysis, infrastructure analysis such as passive DNS, certificate pivoting, and netflow, and log analysis.
  • Experience authoring detection logic using YARA, Sigma, Snort/Suricata, or SIEM-native queries.
  • Ability to write clear and concise intelligence products.
  • An existing network in the threat intelligence community and a track record of productive bidirectional sharing.
  • Minimum education of a bachelor's degree or an equivalent combination of education, training, and experience in a relevant field.

Preferred Qualifications

  • Experience defending cloud-native and research-heavy environments, including AWS/GCP, Kubernetes, ML infrastructure, developer tooling, and software supply chains.
  • Experience tracking sophisticated or state-sponsored adversaries where analysis directly informed detection, threat hunting, and incident response.
  • Experience applying LLMs or other AI tooling to accelerate intelligence collection, enrichment, and analysis.
  • Public research, conference talks, or open-source tooling contributions in the cyber threat intelligence space.

Benefits

Anthropic offers competitive compensation and benefits, optional equity donation matching, generous vacation and parental leave, flexible working hours, and office spaces for collaboration. Staff are currently expected to work from one of the company's offices at least 25% of the time, although some roles may require more office time. Anthropic sponsors visas and makes reasonable efforts to provide visa support with the assistance of an immigration lawyer.

More jobs at Anthropic

Similar jobs