Security Engineer, Detection & Response

Anthropic Anthropic · AI Frontier · San Francisco, CA · Security

This role focuses on leading cybersecurity Incident Response efforts, developing and deploying tooling (potentially leveraging LLMs) to enhance detection and investigation, and creating/optimizing detections and workflows. It is an engineering role within a general domain, with a moderate AI score due to the potential use of LLMs in tooling.

What you'd actually do

  1. Lead cybersecurity Incident Response efforts covering diverse domains from external attacks to insider threats involving all layers of Anthropic’s technology stack
  2. Develop and deploy novel tooling that may leverage Large Language Models to enhance detection, investigation, and response capabilities
  3. Create and optimize detections, playbooks, and workflows to quickly identify and respond to potential incidents
  4. Review Incident Response metrics and procedures and drive continuous improvement
  5. Work cross functionally with other security and engineering teams

Skills

Required

  • 3+ years of software engineering experience
  • 5+ years of detection engineering, incident response, or threat hunting experience
  • A solid understanding of cloud environments and operations
  • Experience working with engineering teams in a SaaS environment
  • Exceptional communication and collaboration skills
  • An ability to lead projects with little guidance
  • The ability to pick up new languages and technologies quickly
  • Experience handling security incidents and investigating anomalies as part of a team
  • Knowledge of EDR, SIEM, SOAR, or related security tools

Nice to have

  • Experience performing security operations or investigations involving large-scale Kubernetes environments
  • A high level of proficiency in Python and query languages such as SQL
  • Experience analyzing attack behavior and prototyping high quality detections
  • Experience with threat intelligence, malware analysis, infrastructure as code, detection engineering, or forensics
  • Experience contributing to a high growth startup environment

What the JD emphasized

  • security experience a plus
  • detection engineering
  • incident response
  • threat hunting experience
  • security incidents
  • investigating anomalies
  • security operations
  • investigations