Skip to content
AnthropicAnthropic

Security Engineer - Threat Intel

This hands-on security engineer will research sophisticated threat actors, build intelligence pipelines, conduct threat hunts, analyze malware and infrastructure, and translate findings into durable detections. The role requires at least five years of cyber threat intelligence or related experience, strong Python engineering, and malware and detection-analysis expertise.

About the job

Responsibilities

  • Research, track, and report on threat actors and campaigns targeting AI labs, cloud infrastructure, and the technology sector.
  • Build and maintain tooling and automated pipelines to collect, enrich, correlate, and operationalize indicators of compromise into detection and alerting systems.
  • Develop and execute intelligence-driven threat hunts across endpoint, cloud, identity, and SaaS telemetry, turning findings into durable detections.
  • Perform technical analysis of malware, phishing infrastructure, and attacker tooling to extract indicators, tactics, techniques, procedures, and attribution signals.
  • Partner with Detection Engineering and Incident Response to translate intelligence into detection rules, hunting hypotheses, and incident context.
  • Curate and triage intelligence from commercial feeds, open sources, government, and trusted peers.
  • Contribute to threat models and risk assessments informing security architecture and defensive investment.
  • Build and maintain intelligence-sharing relationships with peer companies, ISACs, and government partners.

Requirements

  • 5+ years of hands-on experience in cyber threat intelligence, threat hunting, or intrusion analysis against sophisticated adversaries.
  • Deep knowledge of nation-state or advanced criminal threat actors, including tooling, infrastructure patterns, tradecraft, and targeting.
  • Production-quality Python or similar programming experience, including automation and data pipelines.
  • Experience with malware analysis, infrastructure analysis, passive DNS, certificate pivoting, NetFlow, and log analysis.
  • Experience authoring detection logic using YARA, Sigma, Snort/Suricata, or SIEM-native queries.
  • Clear and concise technical writing.
  • Existing threat intelligence community network and a track record of productive bidirectional information sharing.
  • Bachelor's degree or equivalent combination of education, training, and experience in a relevant field.

Nice-to-haves

  • Experience defending cloud-native and research-heavy environments, including AWS, Google Cloud, Kubernetes, ML infrastructure, developer tooling, and software supply chains.
  • Experience tracking sophisticated or state-sponsored adversaries where analysis informed detection, threat hunting, and incident response.
  • Experience applying LLMs or other AI tooling to intelligence collection, enrichment, and analysis.
  • Public research, conference talks, or open-source tooling contributions in cyber threat intelligence.

Compensation

  • Annual salary: $320,000–$405,000 USD

Skills

Python, Threat Intelligence, Threat Hunting, Malware Analysis, Passive Dns, Netflow, Yara, Sigma, Snort, Suricata, SIEM, AWS, GCP, Kubernetes, LLMs

Anthropic

Anthropic

San Francisco, CA
Security Engineer, Corporate Security
$320k+/yrHybrid5+ YOESecurity Engineering

Senior hands-on security engineer responsible for endpoint hardening, device trust, identity and SaaS governance, and scalable corporate-security automation across a growing organization. Requires endpoint security expertise, Python scripting, IAM and zero-trust depth, and strong threat-modeling judgment.

Anthropic

Anthropic

San Francisco, CA
Security Engineer, Offensive Security
$300k+/yrHybrid5+ YOESecurity Engineering

Conduct offensive security operations, red-team engagements, penetration testing, and adversarial simulations across cloud, endpoint, and bare-metal environments. The role requires at least five years of experience, strong engineering skills, and expertise across multiple security domains.

Anthropic

Anthropic

San Francisco, CA
Cyber Evaluations Engineer
$300k+/yrHybridSecurity Engineering

Build and operate evaluations for cyber capabilities and safeguard robustness in AI models, analyze adversarial data, and develop cyber-abuse detection probes. The role requires hands-on cybersecurity experience, Python proficiency, evaluation expertise, and strong cross-functional communication.

OpenAI

OpenAI

San Francisco, CA

Software Engineer, HSM Infrastructure Security, Consumer Devices
$347k+/yrOn-site5+ YOESecurity Engineering

Design and ship security-critical software and firmware at the boundary between policy systems and hardware-backed cryptographic protection. The role requires 5+ years of secure embedded development and deep C, C++, or Rust experience.

Fluidstack

Fluidstack

New York, NY
Security Engineer, Threat Intelligence
$220k+/yrOn-siteSecurity Engineering

The Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.