Security Engineer - Threat Intel

Anthropic Anthropic · AI Frontier · San Francisco, CA · Security

This role focuses on threat intelligence for an AI company, building tooling and pipelines to operationalize indicators of compromise and drive detections. It involves researching threat actors, performing technical analysis, and partnering with security teams. While the company develops AI, the role itself is in cybersecurity and does not directly build AI models.

What you'd actually do

  1. Research, track, and report on threat actors and campaigns targeting AI labs, cloud infrastructure, and the broader technology sector — producing timely, actionable intelligence for Security Engineering stakeholders
  2. Build and maintain tooling and automated pipelines to collect, enrich, correlate, and operationalize indicators of compromise into our detection and alerting stack
  3. Develop and execute intelligence-driven threat hunts across endpoint, cloud, identity, and SaaS telemetry, and turn findings into durable detections
  4. Perform technical analysis of malware, phishing infrastructure, and attacker tooling to extract indicators, TTPs, and attribution signals
  5. Partner with Detection Engineering and Incident Response to translate intelligence into detection rules, hunting hypotheses, and incident context in near-real-time

Skills

Required

  • cyber threat intelligence
  • threat hunting
  • intrusion analysis
  • Python
  • automation
  • data pipelines
  • malware analysis
  • infrastructure analysis
  • log analysis
  • detection logic (YARA, Sigma, Snort/Suricata, SIEM-native queries)

Nice to have

  • defending cloud-native and research-heavy environments (AWS/GCP, Kubernetes, ML infrastructure, developer tooling and supply chain)
  • applying LLMs or other AI tooling to accelerate intelligence collection, enrichment, and analysis
  • public research, conference talks, or open-source tooling contributions in the CTI space

What the JD emphasized

  • hands-on experience in cyber threat intelligence
  • deep, demonstrable knowledge of specific nation-state or advanced criminal threat actors
  • strong engineer: you write production-quality Python (or similar), have built automation and data pipelines
  • comfortable performing malware analysis, infrastructure analysis (passive DNS, certificate pivoting, netflow), and log analysis
  • experience authoring detection logic (YARA, Sigma, Snort/Suricata, or SIEM-native queries)