Staff+ Software Security Engineer

Anthropic Anthropic · AI Frontier · San Francisco, CA · Security

Staff+ Software Security Engineer at Anthropic, focusing on protecting AI systems and infrastructure. Responsibilities include designing and building security systems, threat modeling, mentoring engineers, and advancing the developer security program. The role involves identity and secrets management, infrastructure security, and secure frameworks, with a strong emphasis on end-to-end ownership and driving through ambiguous technical challenges.

What you'd actually do

  1. Scope, design, and build complex security systems end to end, maintaining them through production and driving through ambiguous technical challenges with minimal oversight
  2. Identify systematic risks through threat modeling and risk assessment, then build the controls and infrastructure that address them
  3. Mentor engineers across the security team and broader engineering organization, contribute to hiring, and grow security engineering culture at Anthropic
  4. Enable other teams to build their own security solutions by providing design pattern guidance and expanding security ownership beyond the security team

Skills

Required

  • Python or at least one systems language such as Go, Rust, or C/C++
  • Deep understanding of identity systems, cryptographic primitives, and secrets management
  • Working knowledge of Kubernetes security primitives including RBAC, namespaces, network policies, and service accounts
  • Experience leading cross-functional security initiatives and navigating complex organizational dynamics
  • Outstanding communication skills
  • A track record of bringing clarity and ownership to ambiguous technical problems and driving them to resolution
  • Low ego and high empathy
  • growing the engineers around you and supporting diverse, inclusive teams

Nice to have

  • Designed or operated identity and secrets management systems for large-scale AI or cloud infrastructure
  • Built security frameworks or libraries adopted across an engineering organization
  • Led a developer security program including supply chain security, secure build infrastructure, and SDLC integrations
  • Built or secured CI infrastructure using Nix, Bazel, or Kubernetes-based deploy systems, with depth in toolchain issues, CI/CD pipelines, and developer workflow optimization
  • Implemented machine identity or workload authentication systems using SPIFFE/SPIRE, mTLS, or equivalent
  • Understanding of Linux systems internals including namespaces, cgroups, and seccomp, and how these underpin container and workload isolation
  • Contributed to the security architecture of multi-cloud environments including network segmentation, data protection, and access governance
  • Experience with network security controls including admission controllers, CNI-level policy, service mesh security, and east-west traffic enforcement
  • Experience building runtime security monitoring using eBPF or kernel security policies

What the JD emphasized

  • deep security expertise
  • leading complex security initiatives independently
  • track record of bringing clarity and ownership to ambiguous technical problems and driving them to resolution