Platform Security Engineer, DRTM / Secure Launch
Anthropic · San Francisco, CA | New York City, NY | Seattle, WA · Security · listed August 25, 2026
The shape of it
Seniority
Not stated
Where
Hybrid
Stated pay
$320,000 – $405,000 USD
Requirements listed
7
Length
1,206 words
In the posting’s own words
The work sits at the lowest layers of the stack: firmware, bootloaders, kernel, and the silicon features underneath them. It is also unusually public. We expect the DRTM work done here to land upstream, and the person in this role will be a visible participant in the Linux and firmware communities rather than a consumer of them.
What it asks for · 7
- Deep hands-on experience with measured boot and roots of trust: DRTM (Intel TXT, AMD SKINIT, ARM equivalents), SRTM, TPM 1.2/2.0, and the measurement chains built on them
- Strong C and assembly, with deep Linux kernel and early-boot fundamentals (bootloaders, UEFI, ACPI, SMM)
- A record of landing non-trivial work upstream in Linux, TianoCore, GRUB, or a comparable community
- Comfort at the hardware/firmware boundary and with the debugging that comes with it: JTAG, serial, platform-level bring-up, silicon errata
- Strong technical cross-functional leadership and direction setting, including with external vendors and OEMs
- Clear written communication: this role produces specifications, design docs, and public technical writing
- Working knowledge of NIST firmware security guidance, particularly SP 800-193 and 800-147/155
Also a plus
- 8+ years in systems security, with at least 5 years focused on firmware, bootloader, and OS-level security
- Existing maintainership or subsystem ownership in Linux, or standing in the TCG, UEFI Forum, or OCP communities
- Confidential computing implementation experience: TDX, SEV-SNP, ARM CCA, and their attestation flows
- Hardware roots of trust and attestation beyond the TPM: Caliptra, OCP S.A.F.E., SPDM
- Memory-safe systems code in Rust
- Firmware vulnerability research, reverse engineering, or fuzzing
- Previous work with AI/ML infrastructure security
What the job covers
- Own adoption and integration of DRTM hardware security features across Anthropic infrastructure, on both x86 and ARM platforms
- Implement attestation services and the additional security and privacy capabilities that DRTM presence enables
- Design and implement a bootloader-agnostic solution for initiating and relaunching DRTM sessions
- Investigate further hardening of existing DRTM solutions: PPAM to isolate SMM on x86, VMM features to isolate UEFI runtime services, ACPI handling and hardening in DRTM environments
- Interface with vendor and OEM partners on their DRTM solutions: refine requirements jointly and determine which changes are desirable and feasible
- Publish relevant DRTM work upstream and help carry Linux Secure Launch maintainership as tboot is retired
- Act as technical lead in architecture and design, and disseminate the work through technical papers, conference talks, and community engagement
- Assist other Anthropic teams with their own open source efforts and upstream interactions
- Build and harden other platform security features, including confidential computing solutions such as TDX and SEV
- Support custom operating system artifacts, implement device drivers for custom hardware and features, and do firmware diagnosis and enhancement work
- Debug and diagnose kernel and system-level issues on production hardware
- Take on investigative work in new technical areas and old unsolved ones (for example, the distinct security problems in dTPMs and fTPMs)
Tools and skills named
Security & compliance
- Security11×
Cloud & infra
- Linux5×
Ways of working
- Cross-functional
- Technical writing
Languages
- Rust
Models & research
- Machine learning
Words the posting leans on
- drtm13×
- security11×
- firmware7×
- features5×
- hardware5×
- linux5×
- platform5×
- technical5×
- upstream5×
- arm4×
- attestation4×
- design4×
- hardening4×
- solutions4×
- vendor4×
- bootloaders3×
Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.
The posting, your resume, and the gaps between them. One click loads all three.
More open at Anthropic
- Account Executive, AI NativeNew York City, NY; San Francisco, CA | New York City, NY
- Account Executive - DNBSingapore
- Account Executive - Public Sector (ASEAN)Singapore
- Account Executive, StartupsSan Francisco, CA | New York City, NY
- Accounting, Revenue Internal ControlsSan Francisco, CA | Seattle, WA
- AI Engineer, GTM ClaudificationRemote-Friendly (Travel-Required) | San Francisco, CA | Seattle, WA