Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 4
AWS @ 4
Data Pipelines @ 4
GCP @ 4
Kubernetes @ 4
LLM
Machine Learning
Python @ 4
Security
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Anthropic's Threat Intelligence function within the Detection & Response team produces actionable intelligence to help defend against nation-state and advanced criminal actors targeting frontier AI labs. This hands-on engineering role focuses on tracking relevant adversaries, building intelligence tooling and pipelines, and partnering with detection engineers and incident responders to operationalize intelligence.
Responsibilities
- Research, track, and report on threat actors and campaigns targeting AI labs, cloud infrastructure, and the broader technology sector.
- Build and maintain tooling and automated pipelines to collect, enrich, correlate, and operationalize indicators of compromise in detection and alerting systems.
- Develop and execute intelligence-driven threat hunts across endpoint, cloud, identity, and SaaS telemetry, and turn findings into durable detections.
- Perform technical analysis of malware, phishing infrastructure, and attacker tooling to extract indicators, tactics, techniques, procedures, and attribution signals.
- Partner with Detection Engineering and Incident Response to translate intelligence into detection rules, hunting hypotheses, and incident context in near-real time.
- Curate and triage intelligence from commercial feeds, open sources, government sources, and trusted peer relationships.
- Contribute to threat models and risk assessments that inform security architecture and defensive investment.
- Build and maintain external intelligence-sharing relationships with peer companies, ISACs, and government partners.
Requirements
- 5+ years of hands-on experience in cyber threat intelligence, threat hunting, or intrusion analysis at an organization facing sophisticated adversaries.
- Deep, demonstrable knowledge of specific nation-state or advanced criminal threat actors, including their tooling, infrastructure patterns, tradecraft, and targeting.
- Production-quality Python or similar programming experience, including building automation and data pipelines.
- Experience with malware analysis, infrastructure analysis such as passive DNS, certificate pivoting, and netflow, and log analysis.
- Experience authoring detection logic using YARA, Sigma, Snort/Suricata, or SIEM-native queries.
- Ability to write clear and concise intelligence products.
- An existing network in the threat intelligence community and a track record of productive bidirectional sharing.
- Minimum education of a bachelor's degree or an equivalent combination of education, training, and experience in a relevant field.
Preferred Qualifications
- Experience defending cloud-native and research-heavy environments, including AWS/GCP, Kubernetes, ML infrastructure, developer tooling, and software supply chains.
- Experience tracking sophisticated or state-sponsored adversaries where analysis directly informed detection, threat hunting, and incident response.
- Experience applying LLMs or other AI tooling to accelerate intelligence collection, enrichment, and analysis.
- Public research, conference talks, or open-source tooling contributions in the cyber threat intelligence space.
Benefits
Anthropic offers competitive compensation and benefits, optional equity donation matching, generous vacation and parental leave, flexible working hours, and office spaces for collaboration. Staff are currently expected to work from one of the company's offices at least 25% of the time, although some roles may require more office time. Anthropic sponsors visas and makes reasonable efforts to provide visa support with the assistance of an immigration lawyer.