Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 3
API @ 3
Airflow @ 3
Audit
Communication @ 6
Data Pipelines @ 6
LLM @ 3
Python @ 6
SQL @ 6
Security @ 3
dbt @ 3
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Anthropic is seeking a Threat Intelligence Engineer to join its Threat Intelligence team and build infrastructure that powers threat discovery capabilities. The role involves integrating external data sources, developing automated detection systems, and creating internal tooling that scales investigators’ impact. This is a foundational engineering role on a small, high-impact team, taking projects from proof of concept to production and working closely with investigators to understand their needs.
Responsibilities
- Build automated detection systems that use disparate signals to identify abusive behavior.
- Take systems from ideation through proof of concept to production with appropriate monitoring, documentation, and maintenance processes.
- Develop and maintain YARA rule infrastructure, including tools for writing, validating, and testing rules against real data.
- Create integrations with external threat intelligence platforms such as VirusTotal, Censys, and Urlscan via MCP servers to enable multi-source correlation during investigations.
- Build data pipelines that ingest intelligence from RSS feeds, CTI news sources, and partner sharing.
- Use Claude to extract TTPs and generate targeted hunting queries.
- Develop behavioral analytics capabilities using DBT-based frameworks.
- Create searchable audit logging infrastructure.
- Establish feedback loops with investigators to tune detection systems and reduce false positives.
- Scrape and normalize data from external sources for threat detection and enrichment workflows.
Requirements
- Strong coding proficiency in Python and SQL for detection logic, data pipelines, and automation.
- Experience with data pipeline orchestration tools such as Airflow, DBT, or similar.
- Familiarity with threat intelligence concepts, including IOCs, YARA rules, and threat correlation techniques.
- Experience integrating external APIs and building data ingestion systems.
- Ability to translate investigator needs and workflows into technical requirements.
- Comfort building initial systems and iterating based on user feedback.
- Strong communication skills for working with non-engineering stakeholders.
- A bachelor’s degree or equivalent combination of education, training, and experience. The field of study should be relevant to the role through coursework, training, or professional experience.
Preferred Qualifications
- Experience with threat intelligence sharing frameworks such as MISP and STIX/TAXII.
- Background in cyber threat intelligence, security operations, or abuse detection.
- Experience building MCP servers or similar tool integrations for AI systems.
- Familiarity with web scraping and data extraction at scale.
- Experience with behavioral analytics or anomaly detection systems.
- Understanding of LLM capabilities and how to leverage them for automation.
- Top Secret Clearance.
Benefits
Anthropic offers competitive compensation and benefits, optional equity donation matching, generous vacation and parental leave, flexible working hours, and an office space for collaboration.
More jobs at Anthropic
Staff Software Engineer, Education
Anthropic · San Francisco, United States, New York City, United States
USD 320,000-405,000 per year
Manager, Forward Deployed Engineering
Anthropic · London, United Kingdom
GBP 0 per year
Product Marketing Operations Manager, Research
Anthropic · San Francisco, United States, New York City, United States
USD 255,000-320,000 per year
AV Engineer
Anthropic · New York City, United States
USD 285,000-325,000 per year
IT Support Engineer
Anthropic · Dublin, Ireland
EUR 125,000-165,000 per year
Similar jobs
Senior Data Engineer, People Analytics
Airbnb · United States
USD 179,000-210,000 per year
Software Engineer, Secure Development Engineering
Airbnb · United States
USD 162,000-186,000 per year
Senior Analyst, Compliance Technology
Coinbase · United States
USD 167,300-196,800 per year
Senior Software Engineer - Python and Data Ecosystem
ClickHouse · United States
USD 141,000-232,000 per year
Senior AI Engineer
Grafana Labs · United States
USD 154,400-185,300 per year
Senior AI Engineer
Grafana Labs · Canada
CAD 164,500-197,400 per year
Engineering Manager, GRC Platform
Anthropic · San Francisco, United States, New York City, United States, Seattle, United States
USD 320,000-405,000 per year
Finance Systems Engineer, Tax
Anthropic · San Francisco, United States, Seattle, United States
USD 205,000-270,000 per year