Staff+ Security Engineer, Risk Engineering

USD 320,000-405,000 per year
SENIOR
✅ Hybrid
✅ Visa Sponsorship

Tech Stack

AI @ 6 Communication @ 6 Data Pipelines Go @ 7 LLM @ 4 Observability @ 4 Prioritization @ 6 Python @ 7 Rust @ 7 Security @ 7

Details

Anthropic is rebuilding security risk management as an engineering function through automation and AI-native platforms. The Security Risk team identifies, prioritizes, and drives treatment of the company’s most important security risks across areas including authorization primitives, cryptographic foundations, identity and secrets management, developer security and supply chain, infrastructure security, cloud security, and secure frameworks.

The role involves greenfield development of the architecture, systems, and discipline needed to make security risk measurable and scalable, with direct visibility into CISO-level decisions.

Responsibilities

  • Own complex security risk problems end to end with minimal oversight, including severity and likelihood assessment, escalation, treatment decisions, and remediation.
  • Build quantification tooling, automated intake and triage systems, and observability that enables partner teams to understand their risk posture.
  • Work as a technical peer with Security Engineering to pressure-test architectures and treatment plans, translate findings into prioritized remediation roadmaps, and support investment decisions.
  • Mentor engineers and risk practitioners across Security and the broader engineering organization.
  • Develop expertise across security domains including identity and secrets management, developer security and supply chain, infrastructure security, and secure frameworks.
  • Perform threat modeling and structured assessments, calibrate severity, and lead escalation discussions.
  • Apply calibrated estimation and Monte Carlo simulation when quantitative analysis can improve resource or treatment decisions.
  • Design and build AI-native risk tooling using Claude to classify incoming risks, augment triage, and detect changes in the risk landscape.
  • Create dashboards and data pipelines that provide engineering and product teams with real-time visibility into risk posture.
  • Partner with Security Engineering and risk owners on remediation roadmaps covering sequencing, ownership, and investment.
  • Measure outcomes based on decisions made and risk reduced rather than activity.

Requirements

  • At least 8 years of software engineering or security engineering experience, including independently leading and remediating complex security risks.
  • Bachelor’s degree in a related field or equivalent experience.
  • Strong programming skills in Python or at least one systems language such as Go, Rust, or C/C++.
  • Broad knowledge of core security engineering domains, with depth in at least one of identity and secrets management, developer security and supply chain, infrastructure and cloud security, or secure frameworks.
  • Strong risk judgment, including the ability to assess ambiguous problems, assign defensible severity and likelihood, and update conclusions as evidence changes.
  • Experience leading cross-functional security initiatives and navigating complex organizational dynamics.
  • Outstanding communication skills and the ability to translate technical concepts across organizational levels.
  • A record of bringing clarity and ownership to ambiguous technical problems and driving them to resolution.
  • Low ego, high empathy, and experience developing engineers and supporting diverse, inclusive teams.
  • Passion for AI safety and the role of security and risk management in building trustworthy AI systems.

Preferred Qualifications

  • Experience owning a named security risk from discovery through remediation across multiple teams.
  • Experience briefing executives on risk decisions and defending accept, remediate, or transfer recommendations.
  • Experience building security automation, detection, or risk platforms adopted across an engineering organization.
  • Experience shipping LLM- or agent-powered tooling and workflows for security or risk activities.
  • Security engineering, detection engineering, or offensive security background with a risk-based prioritization mindset.
  • Experience operating a quantified security risk program using FAIR-style decomposition, Monte Carlo simulation, or loss exceedance analysis.
  • Familiarity with SOC 2, ISO 27001, or FedRAMP.

Compensation

Annual salary: $320,000–$405,000 USD.

Logistics

  • Minimum education: Bachelor’s degree or an equivalent combination of education, training, and/or experience.
  • Location-based hybrid policy: Staff are expected to work from an Anthropic office at least 25% of the time, although some roles may require more office time.
  • Anthropic sponsors visas and will make every reasonable effort to obtain a visa for an offer recipient, with support from an immigration lawyer.

Benefits

Anthropic offers competitive compensation and benefits, optional equity donation matching, generous vacation and parental leave, flexible working hours, and office space for collaboration.

More jobs at Anthropic

Similar jobs