Platform Security Engineer, OpenBMC
Anthropic · San Francisco, CA | New York City, NY | Seattle, WA · Security · listed June 19, 2026
The shape of it
Seniority
Senior
Experience asked
5–8 years
Where
Hybrid
Stated pay
$320,000 – $405,000 USD
Requirements listed
10
Length
1,007 words
In the posting’s own words
Security is a first-class constraint in everything you ship: you'll write firmware to a high security bar and partner closely with our firmware security and hardware engineers on secure boot, signing, and attestation.
What it asks for · 10
- Strong technical cross-functional leadership skills, direction setting
- Hands-on OpenBMC/BMC firmware experience on x86 and/or Arm, from bring-up through production with hands-on D-Bus/sdbusplus
- Strong C/C++ and Python, deep Linux user-space/kernel fundamentals, and Yocto/OpenEmbedded proficiency
- A security mindset applied to firmware, not bolted on afterward
- Upstream contributions to OpenBMC, U-Boot, DMTF, or OCP
- Working knowledge of out-of-band and in-band management, the relevant DMTF specs, and the device interfaces they run over
- Strong debugging and a track record of shipping reliable, well-tested code.
- Clear communication across internal teams and external vendors
- Ability to work effectively across hardware and software boundaries
- Knowledge of NIST firmware security guidelines and hardware security frameworks, specifically SP 800-193 and 800-147/155
Also a plus
- 8+ years of experience in systems security, with at least 5 years focused on firmware and hardware security (firmware, bootloaders, and OS-level security)
- Hardware roots of trust and attestation: Caliptra, OCP S.A.F.E., TPM/HRoT, SPDM
- Memory-safe systems code in Rust or Zig
- Firmware vulnerability research, reverse-engineering, or fuzzing
- Previous work with AI/ML infrastructure security
What the job covers
- Design, build, and ship OpenBMC firmware and manageability features for x86 and Arm (including GPU) platforms, from bring-up through production, using Yocto/OpenEmbedded
- Build the management stack on DMTF/OCP standards (MCTP, PLDM, SPDM, Redfish, RDE) and IPMI/KCS: sensors, telemetry, inventory, logging, RAS
- Implement BMC-to-BIOS/host communications, eSPI/LPC, thermal/fan/power management (PMBus)
- Work the hardware/firmware boundary: I2C/I3C, SPI, PCIe, SMBus, device trees, U-Boot, Linux
- Own the BMC security posture: secure and measured boot, root of trust, attestation (SPDM), authenticated update (PLDM FW Update), rollback protection, attack-surface reduction
- Lead threat modeling and secure design reviews; run coordinated vulnerability disclosure with vendors and the upstream community
- Build verification tooling: static analysis, fuzzing, firmware extraction, CI gating
Tools and skills named
Security & compliance
- Security12×
- Threat modeling
Languages
- C++
- Python
- Rust
Cloud & infra
- Linux2×
Models & research
- GPU
- Machine learning
Ways of working
- Cross-functional
Words the posting leans on
- firmware13×
- security12×
- hardware5×
- production5×
- management4×
- attestation3×
- bring-up3×
- build3×
- secure3×
- spdm3×
- arm2×
- boot2×
- code2×
- communication2×
- design2×
- device2×
Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.
The posting, your resume, and the gaps between them. One click loads all three.
More open at Anthropic
- Account Executive, AI NativeNew York City, NY; San Francisco, CA | New York City, NY
- Account Executive - DNBSingapore
- Account Executive, Public SectorSydney, Australia
- Account Executive - Public Sector (ASEAN)Singapore
- Account Executive, StartupsSan Francisco, CA | New York City, NY
- Accounting, Revenue Internal ControlsSan Francisco, CA | Seattle, WA