Skip to content
AnthropicAnthropic

Threat Collections Engineer

Builds threat detection infrastructure, data pipelines, and tooling for threat intelligence team. Requires strong Python/SQL skills, experience with orchestration tools, YARA rules, and external API integrations.

About the job

Responsibilities

  • Build automated detection systems using disparate signals to identify abusive behavior.
  • Take systems from idea to proof-of-concept to production-grade with monitoring, documentation, and maintenance.
  • Develop and maintain YARA rule infrastructure, including tools for writing, validating, and testing rules.
  • Create integrations with external threat intelligence platforms (e.g. VirusTotal, Censys, Urlscan) via MCP servers.
  • Build data pipelines ingesting intelligence from RSS feeds, CTI news, and partners, using Claude for TTP extraction and hunting queries.
  • Develop behavioral analytics using DBT-based frameworks and searchable audit logging.
  • Establish feedback loops with investigators to tune detections and reduce false positives.
  • Scrape and normalize data from external sources for threat detection workflows.

You may be a good fit if you:

  • Strong coding proficiency in Python and SQL for detection logic, data pipelines, and automation.
  • Experience with data pipeline orchestration tools (Airflow, DBT, or similar).
  • Familiarity with threat intelligence concepts including IOCs, YARA rules, and threat correlation.
  • Experience integrating external APIs and building data ingestion systems.
  • Can translate investigator needs into technical requirements.
  • Comfortable building v0 systems and iterating on feedback.
  • Strong communication skills for non-engineering stakeholders.

Strong candidates may also have:

  • Experience with threat intelligence sharing frameworks (MISP, STIX/TAXII).
  • Background in cyber threat intelligence, security operations, or abuse detection.
  • Experience building MCP servers or similar AI tool integrations.
  • Familiarity with web scraping and data extraction at scale.
  • Experience with behavioral analytics or anomaly detection.
  • Understanding of LLM capabilities for automation.
  • Top Secret Clearance.

Annual Salary: $300,000—$320,000 USD

Skills

Python, SQL, Yara, dbt, Airflow, Virustotal, Censys, Urlscan, Misp, Stix/Taxii

Anthropic

Anthropic

San Francisco, CA
Security Engineer, Offensive Security
$300k+/yrHybrid5+ YOESecurity Engineering

Conduct offensive security operations, red-team engagements, penetration testing, and adversarial simulations across cloud, endpoint, and bare-metal environments. The role requires at least five years of experience, strong engineering skills, and expertise across multiple security domains.

Anthropic

Anthropic

San Francisco, CA
Cyber Evaluations Engineer
$300k+/yrHybridSecurity Engineering

Build and operate evaluations for cyber capabilities and safeguard robustness in AI models, analyze adversarial data, and develop cyber-abuse detection probes. The role requires hands-on cybersecurity experience, Python proficiency, evaluation expertise, and strong cross-functional communication.

Anthropic

Anthropic

New York, NY
Security Engineer - Threat Intel
$320k+/yrHybrid5+ YOESecurity Engineering

This hands-on security engineer will research sophisticated threat actors, build intelligence pipelines, conduct threat hunts, analyze malware and infrastructure, and translate findings into durable detections. The role requires at least five years of cyber threat intelligence or related experience, strong Python engineering, and malware and detection-analysis expertise.

Anthropic

Anthropic

San Francisco, CA
Security Engineer, Corporate Security
$320k+/yrHybrid5+ YOESecurity Engineering

Senior hands-on security engineer responsible for endpoint hardening, device trust, identity and SaaS governance, and scalable corporate-security automation across a growing organization. Requires endpoint security expertise, Python scripting, IAM and zero-trust depth, and strong threat-modeling judgment.

OpenAI

OpenAI

San Francisco, CA

Software Engineer, HSM Infrastructure Security, Consumer Devices
$347k+/yrOn-site5+ YOESecurity Engineering

Design and ship security-critical software and firmware at the boundary between policy systems and hardware-backed cryptographic protection. The role requires 5+ years of secure embedded development and deep C, C++, or Rust experience.