Staff+ Software Security Engineer

Anthropic · San Francisco, CA | New York City, NY | Seattle, WA · Security · listed February 13, 2026

The shape of it

Seniority
Staff
Experience asked
8+ years
Where
Not stated
Stated pay
$405,000 – $485,000 USD
Requirements listed
10
Length
1,314 words

In the posting’s own words

The team works across several areas that collaborate closely: identity and secrets management, developer security and supply chain, infrastructure security, and secure frameworks. You will own one or two of these areas and contribute to others, with your focus shaped by your strengths and the team's priorities. This is largely greenfield work, and you will help define the architecture.

What it asks for · 10

  • At least 8 years of software engineering experience with deep security expertise, including leading complex security initiatives independently
  • Bachelor's degree in Computer Science or equivalent industry experience
  • Strong programming skills in Python or at least one systems language such as Go, Rust, or C/C++
  • Deep understanding of identity systems, cryptographic primitives, and secrets management
  • Working knowledge of Kubernetes security primitives including RBAC, namespaces, network policies, and service accounts
  • Experience leading cross-functional security initiatives and navigating complex organizational dynamics
  • Outstanding communication skills, translating technical concepts effectively across all levels of the organization
  • A track record of bringing clarity and ownership to ambiguous technical problems and driving them to resolution
  • Low ego and high empathy, with a history of growing the engineers around you and supporting diverse, inclusive teams
  • Passion for AI safety and the role security engineering plays in building trustworthy AI systems

Also a plus

  • Designed or operated identity and secrets management systems for large-scale AI or cloud infrastructure
  • Built security frameworks or libraries adopted across an engineering organization
  • Led a developer security program including supply chain security, secure build infrastructure, and SDLC integrations
  • Built or secured CI infrastructure using Nix, Bazel, or Kubernetes-based deploy systems, with depth in toolchain issues, CI/CD pipelines, and developer workflow optimization
  • Implemented machine identity or workload authentication systems using SPIFFE/SPIRE, mTLS, or equivalent
  • Understanding of Linux systems internals including namespaces, cgroups, and seccomp, and how these underpin container and workload isolation
  • Contributed to the security architecture of multi-cloud environments including network segmentation, data protection, and access governance
  • Experience with network security controls including admission controllers, CNI-level policy, service mesh security, and east-west traffic enforcement

Degree language

  • Bachelor's degree in Computer Science or equivalent industry experience

Tools and skills named

Security & compliance
  • Security35×
  • IAM
  • Threat modeling
Cloud & infra
  • CI/CD2×
  • Kubernetes2×
  • Linux
Languages
  • C++
  • Go
  • Python
  • Rust
Operations & finance
  • Supply chain4×
Ways of working
  • Cross-functional

Words the posting leans on

  • security35×
  • systems11×
  • build9×
  • infrastructure9×
  • engineering7×
  • identity6×
  • developer security5×
  • experience5×
  • frameworks5×
  • architecture4×
  • contribute4×
  • network4×
  • secrets management4×
  • secure4×
  • security controls4×
  • supply chain4×

Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.

The posting, your resume, and the gaps between them. One click loads all three.

More open at Anthropic

every open role at Anthropic

How this page was made

An automated read of a public job posting, fetched August 24, 2026 and last changed by Anthropic on August 21, 2026. Every list above is pulled from the posting’s own sentences — nothing rewritten, nothing added, no judgment about the role or the company. Counts and seniority are read off the text by rule, so they can be wrong where the posting is unusual. The original is the only thing that binds. Openings close without warning; check the source before spending an evening on it.