Description
Job Overview
We're seeking an Operating Systems Security Engineer to harden and secure the OS layer of our infrastructure. You will design and implement OS-level security controls, ensuring our systems can withstand sophisticated attacks while maintaining performance for AI model training.
Key Responsibilities
- Design and implement hardened OS configurations for AI workloads across diverse hardware platforms.
- Minimize attack surfaces by removing unnecessary components from kernel space and user space.
- Develop kernel security policies using SELinux, AppArmor, and custom Linux Security Modules.
- Implement and maintain full-disk encryption solutions for diverse storage systems.
- Build security infrastructure for AI systems, research environments, and production services.
- Create OS-level attestation and integrity monitoring systems.
- Apply security patches and develop patches for custom kernel modules.
- Design secure boot processes and trusted execution environments.
- Work with container teams to ensure proper workload isolation at the kernel level.
- Design privilege separation and mandatory access control policies.
- Implement secure update mechanisms for OS components.
- Build tooling for security configuration management and compliance verification.
- Serve as a subject matter expert for OS security questions and designs.
Requirements
- Deep knowledge of Linux internals, including kernel subsystems and security frameworks.
- Experience with kernel hardening techniques and exploit mitigation.
- Strong programming skills in C and systems programming languages.
- Experience with eBPF for security monitoring and enforcement.
- Understanding of virtualization and containerization security.
- Track record of identifying and fixing OS-level security vulnerabilities.
- Experience with security-focused Linux distributions.
Preferred Qualifications
- 5+ years of experience in operating systems security or kernel development.
- Kernel development experience or contributions to Linux kernel.
- Experience with real-time or embedded operating systems.
- Knowledge of hardware security features and their OS integration.
- Experience with secure boot technologies.
- Experience with confidential computing and memory encryption technologies.
- Background in vulnerability research, exploit development, or fuzzing.
- Experience with formal methods for OS verification.
Logistics
- Annual Salary: $320,000-$405,000 USD
- Minimum education: Bachelor’s degree or an equivalent combination of education, training, and/or experience
- Required field of study: A field relevant to the role
- Location-based hybrid policy: 25% office time
- Visa sponsorship: Available
This listing is enriched and indexed by YubHub. To apply, use the employer's original posting:
https://job-boards.greenhouse.io/anthropic/jobs/5290426008