Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 3
API @ 3
Airflow @ 3
Audit
Communication @ 6
Data Pipelines @ 6
LLM @ 3
Python @ 6
SQL @ 6
Security @ 3
dbt @ 3
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Anthropic is seeking a Threat Intelligence Engineer to join its Threat Intelligence team and build infrastructure that powers threat discovery capabilities. The role involves integrating external data sources, developing automated detection systems, and creating internal tooling that scales investigators’ impact. This is a foundational engineering role on a small, high-impact team, taking projects from proof of concept to production and working closely with investigators to understand their needs.
Responsibilities
- Build automated detection systems that use disparate signals to identify abusive behavior.
- Take systems from ideation through proof of concept to production with appropriate monitoring, documentation, and maintenance processes.
- Develop and maintain YARA rule infrastructure, including tools for writing, validating, and testing rules against real data.
- Create integrations with external threat intelligence platforms such as VirusTotal, Censys, and Urlscan via MCP servers to enable multi-source correlation during investigations.
- Build data pipelines that ingest intelligence from RSS feeds, CTI news sources, and partner sharing.
- Use Claude to extract TTPs and generate targeted hunting queries.
- Develop behavioral analytics capabilities using DBT-based frameworks.
- Create searchable audit logging infrastructure.
- Establish feedback loops with investigators to tune detection systems and reduce false positives.
- Scrape and normalize data from external sources for threat detection and enrichment workflows.
Requirements
- Strong coding proficiency in Python and SQL for detection logic, data pipelines, and automation.
- Experience with data pipeline orchestration tools such as Airflow, DBT, or similar.
- Familiarity with threat intelligence concepts, including IOCs, YARA rules, and threat correlation techniques.
- Experience integrating external APIs and building data ingestion systems.
- Ability to translate investigator needs and workflows into technical requirements.
- Comfort building initial systems and iterating based on user feedback.
- Strong communication skills for working with non-engineering stakeholders.
- A bachelor’s degree or equivalent combination of education, training, and experience. The field of study should be relevant to the role through coursework, training, or professional experience.
Preferred Qualifications
- Experience with threat intelligence sharing frameworks such as MISP and STIX/TAXII.
- Background in cyber threat intelligence, security operations, or abuse detection.
- Experience building MCP servers or similar tool integrations for AI systems.
- Familiarity with web scraping and data extraction at scale.
- Experience with behavioral analytics or anomaly detection systems.
- Understanding of LLM capabilities and how to leverage them for automation.
- Top Secret Clearance.
Benefits
Anthropic offers competitive compensation and benefits, optional equity donation matching, generous vacation and parental leave, flexible working hours, and an office space for collaboration.
More jobs at Anthropic
Marketing Analytics Lead, Enterprise Marketing
Anthropic · New York City, United States, San Francisco, United States
USD 255,000-320,000 per year
Product Designer, Safeguards
Anthropic · New York City, United States, San Francisco, United States, Seattle, United States
USD 305,000-385,000 per year
Incident Response Manager - Privacy
Anthropic · New York City, United States, San Francisco, United States
USD 290,000-365,000 per year
Staff+ Software Engineer, Account Creation
Anthropic · New York City, United States, San Francisco, United States, Seattle, United States
USD 320,000-485,000 per year
Staff+ Software Engineer, Access Programs
Anthropic · New York City, United States, San Francisco, United States, Seattle, United States
USD 320,000-485,000 per year
Similar jobs
Director, Finance Systems - Revenue Systems Engineering
Anthropic · San Francisco, United States, Seattle, United States
USD 270,000-315,000 per year
Senior AI Strategy and Operations Analyst
AppLovin · Toronto, Canada
CAD 150,000-200,000 per year
Senior Analyst, Compliance Technology
Coinbase · United States
USD 167,300-196,800 per year
Staff Workday Integration Engineer, Tech Foundations
Airbnb · United States
USD 180,000-225,000 per year
Senior Software Engineer - Integrations - AI/ML
ClickHouse · United States
USD 147,000-238,000 per year
Finance Systems Engineer, Finance and Strategy
Anthropic · San Francisco, United States
USD 205,000-270,000 per year
Senior AI Engineer
Grafana Labs · United States
USD 154,400-185,300 per year
Senior Software Engineer - Integrations - AI/ML
ClickHouse · Canada
USD 147,000-238,000 per year