Staff+ Security Engineer, Risk Engineering

Anthropic Anthropic · AI Frontier · San Francisco, CA · Security

This role focuses on building AI-native platforms and automation for security risk management. The engineer will identify, prioritize, and drive treatment of security risks, working across various security domains. Key responsibilities include building systems for risk measurement, quantification tooling, automated intake, and observability. The role also involves designing and building AI-native risk tooling that uses Claude to classify risks, augment triage, and sense changes in the risk landscape. Experience with LLM or agent-powered tooling for security automation is preferred.

What you'd actually do

  1. Take ownership of Anthropic’s most complex security risk problems and drive them end to end with minimal oversight, turning ambiguous signals into a defensible view of severity and likelihood and seeing them through escalation, treatment decisions, and remediation
  2. Build the systems that make risk measurable and let risk work scale, including quantification tooling, automated intake and triage, and the observability that partner teams use to understand their own risk posture
  3. Work alongside Security Engineering as a calibrated technical peer who pressure tests architectures and treatment plans, translates findings into prioritized remediation roadmaps, and makes the investment case for what to fix now, what to accept and track, and what to defer
  4. Mentor engineers and risk practitioners across Security and the broader engineering organization, and help build a risk engineering culture in which teams own their risks and our team provides the visibility and judgment that supports the
  5. Design and build AI-native risk tooling that uses Claude to classify incoming risks, augment triage, and continuously sense changes in our risk landscape as teams ship

Skills

Required

  • At least 8 years of software engineering or security engineering experience, including leading and remediating complex security risks independently
  • Bachelor’s degree in a related field or equivalent experience
  • Strong programming skills in Python or at least one systems language such as Go, Rust, or C/C++
  • Broad knowledge across the core security engineering domains, with depth in at least one, including identity and secrets management, developer security and supply chain, infrastructure and cloud security, and secure frameworks
  • Calibrated risk judgment, meaning you can put a defensible severity and likelihood on an ambiguous problem and change your position when the evidence changes
  • Experience leading cross-functional security initiatives and navigating complex organizational dynamics
  • Outstanding communication skills, translating technical concepts effectively across all levels of the organization
  • A track record of bringing clarity and ownership to ambiguous technical problems and driving them to resolution
  • Low ego and high empathy, with a history of growing the engineers around you and supporting diverse, inclusive teams
  • Passion for AI safety and the role security and risk management play in building trustworthy AI systems

Nice to have

  • Owned a named security risk and driven it from discovery through remediation across multiple teams
  • Briefed executives on risk decisions and defended accept, remediate, or transfer recommendations under challenge
  • Built security automation, detection, or risk platforms adopted across an engineering organization
  • Shipped LLM or agent-powered tooling and workflows that automate security or risk activities
  • A security engine

What the JD emphasized

  • AI-native platforms
  • automation
  • risk management
  • security engineering
  • LLM or agent-powered tooling

Other signals

  • AI-native platforms
  • automation
  • risk management
  • security engineering
  • LLM or agent-powered tooling