Offensive Hardware Security Engineer, Platform Security

Anthropic · San Francisco, CA | New York City, NY | Seattle, WA · Security · listed July 10, 2026

The shape of it

Seniority
Senior
Experience asked
5–8 years
Where
Hybrid
Stated pay
$320,000 – $405,000 USD
Requirements listed
9
Length
1,066 words

In the posting’s own words

We're seeking a vulnerability assessment candidate for platform security. You'll work cross functionally with teams across Anthropic and our partners to assess security features in hardware, firmware, bootloaders, operating systems, and attestation systems to identify and remove vulnerabilities from the ground up.

What it asks for · 9

  • Proven track record of conducting hands-on vulnerability auditing on complex, security-critical systems
  • Hands-on experience with secure boot, measured boot, and attestation technologies (TPM, Intel TXT, AMD SEV, ARM TrustZone)
  • Strong understanding of cryptographic protocols and hardware security modules
  • Experience with UEFI/BIOS or embedded firmware security, bootloader hardening, and chain of trust implementation
  • Proficiency in low-level programming languages (C, Assembly) and systems programming
  • Knowledge of firmware vulnerability assessment and threat modeling
  • Ability to work effectively across hardware and software boundaries
  • Strong communication and cross functional collaboration skills
  • Track record of assessing security architectures for complex, distributed systems

Also a plus

  • 8+ years of experience in systems security, with at least 5 years focused on low-level security (firmware, bootloaders, and OS kernel-level security)
  • Capacity to audit for logic bugs in code written in Rust or Go
  • Ability to find vulnerabilities via reverse engineering in software that is provided only in binary form
  • Experience performing fault injection & side-channel analysis attacks on hardware
  • Experience auditing silicon root of trust implementations
  • Experience auditing confidential computing technologies and hardware-based TEEs
  • Background in formal verification or security proof techniques
  • 5 or more talks at top-tier security conferences with candidate listed as first author

What the job covers

  • Audit secure boot chains from firmware through OS initialization for diverse hardware platforms (CPUs, BMCs, switches, peripherals, and embedded microcontrollers)
  • Audit attestation systems that provide cryptographic proof of system state from hardware root of trust through application layer
  • Audit measured boot implementations and runtime integrity monitoring
  • Integrate security controls with infrastructure teams without impacting training performance
  • Validate security mechanisms before production deployment
  • Conduct firmware vulnerability assessments and penetration testing
  • Build firmware vulnerability assessment pipelines for continuous security monitoring
  • Document security architectures and maintain threat models
  • Collaborate with software and hardware vendors to ensure security capabilities meet our requirements for exploit mitigation

Tools and skills named

Security & compliance
  • Security20×
  • Audit8×
  • Penetration testing
  • Threat modeling
Languages
  • Go
  • Rust
Models & research
  • LLM
  • Machine learning
Ways of working
  • Cross-functional
  • Testing
Cloud & infra
  • Distributed systems

Words the posting leans on

  • security18×
  • systems9×
  • experience8×
  • firmware7×
  • hardware7×
  • audit5×
  • boot4×
  • production4×
  • firmware vulnerability3×
  • implementations3×
  • infrastructure3×
  • low-level3×
  • platform3×
  • software3×
  • vulnerabilities3×
  • vulnerability assessment3×

Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.

The posting, your resume, and the gaps between them. One click loads all three.

More open at Anthropic

every open role at Anthropic

How this page was made

An automated read of a public job posting, fetched August 25, 2026 and last changed by Anthropic on August 21, 2026. Every list above is pulled from the posting’s own sentences — nothing rewritten, nothing added, no judgment about the role or the company. Counts and seniority are read off the text by rule, so they can be wrong where the posting is unusual. The original is the only thing that binds. Openings close without warning; check the source before spending an evening on it.