Security Engineer - Threat Intel
Anthropic · New York City, NY; Remote-Friendly (Travel-Required) | San Francisco, CA | Washington, DC; San Francisco, CA | New York City, NY · Security · listed April 22, 2026
The shape of it
Seniority
Senior
Experience asked
5+ years
Where
Hybrid
Stated pay
$320,000 – $405,000 USD
Requirements listed
7
Length
1,165 words
In the posting’s own words
We encourage you to apply even if you do not believe you meet every single qualification. Not all strong candidates will meet every single qualification as listed. Research shows that people who identify as being from underrepresented groups are more prone to experiencing imposter syndrome and doubting the strength of their candidacy, so we urge you not to exclude yourself prematurely and to submit an application if you're interested in this work. We think AI systems like the ones we're building have enormous social and ethical implications. We think this makes representation even more important, and we strive to include a range of diverse perspectives on our team. Your safety matters to us. To protect yourself from potential scams, remember that Anthropic recruiters only contact you from @anthropic.com email addresses. In some cases, we may partner with vetted recruiting agencies who will identify themselves as working on behalf of Anthropic. Be cautious of emails from other domains. Legitimate Anthropic recruiters will never ask for money, fees, or banking information before your first day. If you're ever unsure about a communication, don't click any links—visit anthropic.com/careers directly for confirmed position openings.
What it asks for · 7
- Have 5+ years of hands-on experience in cyber threat intelligence, threat hunting, or intrusion analysis at an organization facing sophisticated adversaries
- Have deep, demonstrable knowledge of specific nation-state or advanced criminal threat actors — their tooling, infrastructure patterns, tradecraft, and targeting
- Are a strong engineer: you write production-quality Python (or similar), have built automation and data pipelines, and don't need to hand requirements to someone else to get tooling built
- Are comfortable performing malware analysis, infrastructure analysis (passive DNS, certificate pivoting, netflow), and log analysis to develop and validate your own findings
- Have experience authoring detection logic (YARA, Sigma, Snort/Suricata, or SIEM-native queries) and understand what makes a detection durable vs. brittle
- Can write clearly and concisely — your intelligence products are read and acted on, not filed away
- Have an existing network in the threat intelligence community and a track record of productive bidirectional sharing
Also a plus
- Experience defending cloud-native and research-heavy environments (AWS/GCP, Kubernetes, ML infrastructure, developer tooling and supply chain)
- Prior work operating in a threat intelligence role tracking sophisticated or state-sponsored adversaries, where your analysis directly informed detection, threat hunting, and incident response
- Experience applying LLMs or other AI tooling to accelerate intelligence collection, enrichment, and analysis
- Public research, conference talks, or open-source tooling contributions in the CTI space
What the job covers
- Research, track, and report on threat actors and campaigns targeting AI labs, cloud infrastructure, and the broader technology sector — producing timely, actionable intelligence for Security Engineering stakeholders
- Build and maintain tooling and automated pipelines to collect, enrich, correlate, and operationalize indicators of compromise into our detection and alerting stack
- Develop and execute intelligence-driven threat hunts across endpoint, cloud, identity, and SaaS telemetry, and turn findings into durable detections
- Perform technical analysis of malware, phishing infrastructure, and attacker tooling to extract indicators, TTPs, and attribution signals
- Partner with Detection Engineering and Incident Response to translate intelligence into detection rules, hunting hypotheses, and incident context in near-real-time
- Curate and triage inbound intelligence from commercial feeds, open source, government, and trusted peer relationships — prioritizing what matters for Anthropic's threat model
- Contribute to threat models and risk assessments that inform security architecture and defensive investment across the enterprise
- Build and maintain external intelligence-sharing relationships with peer companies, ISACs, and government partners
Tools and skills named
Cloud & infra
- AWS
- GCP
- Kubernetes
Models & research
- LLM
- Machine learning
Security & compliance
- Security2×
Data
- Data pipelines
Go to market
- SaaS
Languages
- Python
Operations & finance
- Supply chain
Words the posting leans on
- threat13×
- detection10×
- tooling8×
- analysis7×
- threat intelligence6×
- infrastructure5×
- experience4×
- incident4×
- adversaries3×
- build3×
- engineer3×
- indicators3×
- pipelines3×
- track3×
- actionable intelligence2×
- advanced criminal2×
Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.
The posting, your resume, and the gaps between them. One click loads all three.
More open at Anthropic
- Account Executive, AI NativeNew York City, NY; San Francisco, CA | New York City, NY
- Account Executive - DNBSingapore
- Account Executive - Public Sector (ASEAN)Singapore
- Account Executive, StartupsSan Francisco, CA | New York City, NY
- Accounting, Revenue Internal ControlsSan Francisco, CA | Seattle, WA
- Administrative Business Partner, GTMSan Francisco, CA