Staff+ Software Security Engineer
- york and north yorkshire, england, United Kingdom
- Permanent·On-site
- Full time
- £120 - £180 Per Month
Job Description
- The Security Engineering team protects Anthropic’s AI systems and maintains the trust of our users and society
- We define the authentication architecture for our training infrastructure, design the cryptographic foundations that protect model weights and training data, and drive the developer security program that shapes how engineers build and ship software
- The team works across several areas that collaborate closely: identity and secrets management, developer security and supply chain, infrastructure security, and secure frameworks
- You will own one or two of these areas and contribute to others, with your focus shaped by your strengths and the team’s priorities
- This is largely greenfield work, and you will help define the architecture
- Scope, design, and build complex security systems end to end, maintaining them through production and driving through ambiguous technical challenges with minimal oversight
- Identify systematic risks through threat modeling and risk assessment, then build the controls and infrastructure that address them
- Mentor engineers across the security team and broader engineering organization, contribute to hiring, and grow security engineering culture at Anthropic
- Enable other teams to build their own security solutions by providing design pattern guidance and expanding security ownership beyond the security team
- Build and advance our developer security program by embedding security practices into the software development lifecycle and developer workflows
- Harden CI/CD pipelines against supply chain attacks through isolated build environments, signed attestations, dependency verification, and automated policy enforcement
- Architect systems that protect sensitive assets including model weights, customer data, and training datasets
- Build and operate credential issuance, rotation, and workload authentication across our multi-cloud environments
- Implement and maintain cloud security controls including IAM, network segmentation, VPC architecture, and encryption across our multi-cloud and on-prem environments
- Contribute to cluster security controls including RBAC policies, namespace isolation, workload identity, and pod security
- Contribute to continuous cloud security posture management using infrastructure-as-code scanning, misconfiguration detection, and automated remediation
- Build critical security foundations including cryptographic frameworks, mTLS infrastructure, secure serialization, and authorization systems, designed to prevent entire classes of vulnerabilities and empower engineering teams to work securely without becoming security experts themselves
- Partner with product, research, infrastructure, and other security teams to ensure frameworks integrate smoothly with lower-layer security controls
Benefits
- Comprehensive health, dental, and vision insurance for you and your dependents
- Inclusive fertility benefits via Carrot Fertility
- 22 weeks of paid parental leave
- Flexible paid time off and absence policies
- Mental health support for you and your dependents
- Competitive salary and equity packages
- Optional equity donation matching at a 1:1 ratio, up to 25% of your equity grant
- Retirement plans with competitive matching
- Life and income protection plans
- $500/month flexible wellness and time saver stipend
- Commuter benefits
- Annual education stipend
- Home office stipends
- Relocation support for those moving for Anthropic
- Daily meals and snacks in the office
Outstanding communication skills, translating technical concepts effectively across all levels of the organizationLow ego and high empathy, with a history of growing the engineers around you and supporting diverse, inclusive teamsDeep understanding of identity systems, cryptographic primitives, and secrets managementStrong programming skills in Python or at least one systems language such as Go, Rust, or C/C++Experience leading cross-functional security initiatives and navigating complex organizational dynamicsWorking knowledge of Kubernetes security primitives including RBAC, namespaces, network policies, and service accountsBachelor’s degree in Computer Science or equivalent industry experiencePassion for AI safety and the role security engineering plays in building trustworthy AI systemsA track record of bringing clarity and ownership to ambiguous technical problems and driving them to resolutionAt least 8 years of software engineering experience with deep security expertise, including leading complex security initiatives independentlyLed a developer security program including supply chain security, secure build infrastructure, and SDLC integrationsImplemented machine identity or workload authentication systems using SPIFFE/SPIRE, mTLS, or equivalentExperience building runtime security monitoring using eBPF or kernel security policiesEducation requirements: We require at least a Bachelor’s degree in a related field or equivalent experienceBuilt or secured CI infrastructure using Nix, Bazel, or Kubernetes-based deploy systems, with depth in toolchain issues, CI/CD pipelines, and developer workflow optimizationExperience with network security controls including admission controllers, CNI-level policy, service mesh security, and east-west traffic enforcementBuilt security frameworks or libraries adopted across an engineering organizationDesigned or operated identity and secrets management systems for large-scale AI or cloud infrastructureContributed to the security architecture of multi-cloud environments including network segmentation, data protection, and access governanceUnderstanding of Linux systems internals including namespaces, cgroups, and seccomp, and how these underpin container and workload isolationWe encourage you to apply even if you do not believe you meet every single qualification. Not all strong candidates will meet every single qualification as listed. Research shows that people who identify as being from underrepresented groups are more prone to experiencing imposter syndrome and doubting the strength of their candidacy, so we urge you not to exclude yourself prematurely and to submit an application if you’re interested in this work
#J-18808-Ljbffr

