Staff + Software Security Engineer, Secure Frameworks
Anthropic · San Francisco, CA | New York City, NY | Seattle, WA
About this role
<div class="content-intro"><h2><strong>About Anthropic</strong></h2> <p>Anthropic’s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems.</p></div><h2>About the team</h2> <p>Secure Frameworks is the team in Anthropic's Security Engineering org that builds shared security libraries and frameworks the rest of the company builds on. We collaborate closely with teams and leaders across Anthropic to own critical security foundations, including workload identity and authorization, cryptographic frameworks, and the centralized access proxy that&nbsp; secures traffic to internal applications.&nbsp;</p> <p>Our mission is to make the secure thing easy and the easy thing secure by helping Anthropic engineers get secure behaviour by default and preventing entire classes of vulnerabilities through careful design. We own what we ship, help customers adopt better security practices and at times we work embedded directly in research, infrastructure or product teams.</p> <h2>About the role</h2> <p>You will design, build and run security foundations used across Anthropic's fleet, from threat model through production, on-call and adoption. Much of the work is greenfield: our infrastructure is growing quickly and the timelines are compressed, so you will help define the architecture rather than inherit it. Depending on your strengths you will focus on one or two of the areas below and contribute across the rest.</p> <ul> <li>Build critical security foundations including cryptographic frameworks, mTLS infrastructure, secure serialization, and authorization systems, designed to prevent entire classes of vulnerabilities</li> <li>Partner with product, research, infrastructure, and other security teams to ensure frameworks integrate smoothly with lower-layer security controls</li> <li>&nbsp;Scope, design and build security services and libraries end-to-end, maintain them in production, and drive through ambiguous technical problems with minimal oversight</li> <li>&nbsp;Build and operate the zero-trust access gateway that fronts Anthropic's internal services&nbsp;</li> <li>Design and roll out authorization frameworks so services enforce least privilege consistently instead of each inventing its own access controls</li> <li>Own cryptographic frameworks and libraries</li> <li>Mentor engineers, contribute to hiring, and grow security engineering culture across Anthropic</li> </ul> <h2>Minimum qualifications</h2> <ul> <li>8+ years of software engineering experience building security-relevant systems in production, including leading complex initiatives independently</li> <li>Strong programming skills in Go, Rust or Python</li> <li>Deep understanding of authentication and authorization systems: OAuth 2.0 / OIDC, JWTs, service-to-service auth, policy-based access control</li> <li>Hands-on experience with PKI, X.509, mTLS and workload identity&nbsp;</li> <li>Working knowledge of applied cryptography:...
Listing freshness
CronJobs last confirmed this listing 45m ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.