# Staff+ Software Security Engineer

**Company**: Anthropic
**Location**: San Francisco, CA
**Work arrangement**: hybrid
**Experience**: staff
**Job type**: full-time
**Salary**: $405,000-$485,000 USD
**Category**: Engineering
**Industry**: Technology
**Wikidata**: https://www.wikidata.org/wiki/Q116758847

**Apply**: https://job-boards.greenhouse.io/anthropic/jobs/5120512008?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_e90aeb06-d93

## Description

## Job Overview

As a Staff+ Software Security Engineer at Anthropic, you will play a crucial role in protecting the company's AI systems and maintaining user trust. Anthropic is a public benefit corporation focused on creating reliable, interpretable, and steerable AI systems.

## Responsibilities

### Security Engineering

- Design, build, and maintain complex security systems end-to-end, addressing ambiguous technical challenges with minimal oversight.

- Identify systematic risks through threat modeling and risk assessment, and develop controls and infrastructure to mitigate them.

- Mentor engineers across the security team and broader engineering organization, contributing to hiring and growing security engineering culture.

- Enable other teams to build their own security solutions by providing design pattern guidance and expanding security ownership.

### Developer Security and Supply Chain

- Develop and advance the developer security program by integrating security practices into the software development lifecycle and workflows.

- Enhance CI/CD pipelines against supply chain attacks using isolated build environments, signed attestations, dependency verification, and automated policy enforcement.

### Identity and Secrets Management

- Architect systems to protect sensitive assets, including model weights, customer data, and training datasets.

- Build and operate credential issuance, rotation, and workload authentication across multi-cloud environments.

### Infrastructure Security

- Implement and maintain cloud security controls, including IAM, network segmentation, VPC architecture, and encryption across multi-cloud and on-prem environments.

- Contribute to cluster security controls, including RBAC policies, namespace isolation, workload identity, and pod security.

- Participate in continuous cloud security posture management using infrastructure-as-code scanning, misconfiguration detection, and automated remediation.

### Secure Frameworks

- Develop critical security foundations, including cryptographic frameworks, mTLS infrastructure, secure serialization, and authorization systems.

- Collaborate with product, research, infrastructure, and other security teams to ensure smooth integration with lower-layer security controls.

## Requirements

- At least 8 years of software engineering experience with deep security expertise, including leading complex security initiatives independently.

- Bachelor's degree in Computer Science or equivalent industry experience.

- Strong programming skills in Python or at least one systems language such as Go, Rust, or C/C++.

- Deep understanding of identity systems, cryptographic primitives, and secrets management.

- Working knowledge of Kubernetes security primitives, including RBAC, namespaces, network policies, and service accounts.

- Experience leading cross-functional security initiatives and navigating complex organizational dynamics.

- Outstanding communication skills, translating technical concepts effectively across all levels of the organization.

- A track record of bringing clarity and ownership to ambiguous technical problems and driving them to resolution.

- Low ego and high empathy, with a history of growing the engineers around you and supporting diverse, inclusive teams.

- Passion for AI safety and the role security engineering plays in building trustworthy AI systems.

## Nice to Have

- Designed or operated identity and secrets management systems for large-scale AI or cloud infrastructure.

- Built security frameworks or libraries adopted across an engineering organization.

- Led a developer security program, including supply chain security, secure build infrastructure, and SDLC integrations.

- Built or secured CI infrastructure using Nix, Bazel, or Kubernetes-based deploy systems, with depth in toolchain issues, CI/CD pipelines, and developer workflow optimization.

- Implemented machine identity or workload authentication systems using SPIFFE/SPIRE, mTLS, or equivalent.

- Understanding of Linux systems internals, including namespaces, cgroups, and seccomp, and how these underpin container and workload isolation.

- Contributed to the security architecture of multi-cloud environments, including network segmentation, data protection, and access governance.

- Experience with network security controls, including admission controllers, CNI-level policy, service mesh security, and east-west traffic enforcement.

- Experience building runtime security monitoring using eBPF or kernel security policies.

## Logistics

- Annual Salary: $405,000-$485,000 USD

- Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time.

- Visa sponsorship: We do sponsor visas and will make every reasonable effort to get you a visa if offered the role.

## Skills

### Required
- Python
- Go
- Rust
- C/C++
- identity systems
- cryptographic primitives
- secrets management
- Kubernetes security primitives

### Nice to have
- large-scale AI or cloud infrastructure
- security frameworks
- developer security program
- CI infrastructure
- machine identity or workload authentication systems
- Linux systems internals
- multi-cloud environments
- network security controls
- runtime security monitoring

---

Source: [Apply at job-boards.greenhouse.io](https://job-boards.greenhouse.io/anthropic/jobs/5120512008?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
