Platform Security Engineering, Operating Systems
Hardens and secures the OS layer for Anthropic's AI infrastructure, designing kernel-level protections, runtime enforcement, attestation, and isolation for large-scale model training environments. Requires deep Linux kernel expertise, C/systems programming, and OS security experience.
About the job
Key Responsibilities
- Design and implement hardened OS configurations for AI workloads across diverse hardware platforms
- Minimize attack surfaces by removing as many unnecessary components as possible from kernelspace and userspace
- Develop kernel security policies using SELinux, AppArmor, and custom Linux Security Modules and runtime enforcement mechanisms
- Implement and maintain full-disk encryption solutions for diverse storage systems
- Build security infrastructure for AI systems, research environments, and production services
- Create OS-level attestation and integrity monitoring systems
- Apply security patches, develop patches for custom kernel modules, and kernel hardening configurations
- Design secure boot processes and trusted execution environments
- Work with container teams to ensure proper workload isolation at the kernel level
- Design privilege separation and mandatory access control policies
- Implement secure update mechanisms for OS components
- Build tooling for security configuration management and compliance verification
- Serve as a subject matter expert for OS security questions and designs
Minimum Qualifications
- Deep knowledge of Linux internals, including kernel subsystems and security frameworks (SELinux, AppArmor, seccomp, etc.)
- Experience with kernel hardening techniques and exploit mitigation
- Strong programming skills in C and systems programming languages
- Experience with eBPF for security monitoring and enforcement
- Understanding of virtualization and containerization security
- Track record of identifying and fixing OS-level security vulnerabilities
- Experience with security-focused Linux distributions
Preferred Qualifications
- 5+ years of experience in operating systems security or kernel development
- Kernel development experience or contributions to Linux kernel
- Experience with real-time or embedded operating systems
- Knowledge of hardware security features and their OS integration
- Experience with secure boot technologies
- Experience with confidential computing and memory encryption technologies (SEV, TDX, SGX)
- Background in vulnerability research, exploit development, or fuzzing
- Experience with formal methods for OS verification
- Knowledge of hardware security features and their OS integration (TPM, HSM, secure enclaves)
Education
- Bachelor’s degree or an equivalent combination of education, training, and/or experience in a relevant field
Skills
Linux, Kernel Hardening, Selinux, Apparmor, Seccomp, Ebpf, C, Linux Security Modules, Secure Boot, Tpm, Sev, Tdx, Sgx, Virtualization Security, Container Security
Similar jobs
Security Engineering jobsThis hands-on security engineer will research sophisticated threat actors, build intelligence pipelines, conduct threat hunts, analyze malware and infrastructure, and translate findings into durable detections. The role requires at least five years of cyber threat intelligence or related experience, strong Python engineering, and malware and detection-analysis expertise.
Senior hands-on security engineer responsible for endpoint hardening, device trust, identity and SaaS governance, and scalable corporate-security automation across a growing organization. Requires endpoint security expertise, Python scripting, IAM and zero-trust depth, and strong threat-modeling judgment.
Conduct offensive security operations, red-team engagements, penetration testing, and adversarial simulations across cloud, endpoint, and bare-metal environments. The role requires at least five years of experience, strong engineering skills, and expertise across multiple security domains.
Build and operate evaluations for cyber capabilities and safeguard robustness in AI models, analyze adversarial data, and develop cyber-abuse detection probes. The role requires hands-on cybersecurity experience, Python proficiency, evaluation expertise, and strong cross-functional communication.
Design and ship security-critical software and firmware at the boundary between policy systems and hardware-backed cryptographic protection. The role requires 5+ years of secure embedded development and deep C, C++, or Rust experience.