Security Engineer, Corporate Security

Anthropic · San Francisco, CA | Seattle, WA | New York City, NY | Washington, DC · Security · listed August 21, 2026

The shape of it

Seniority
Not stated
Where
Hybrid
Stated pay
$320,000 – $405,000 USD
Requirements listed
5
Length
1,329 words

In the posting’s own words

Corporate Security protects the environment Anthropic's people work in every day: their laptops and phones, their identities, the tools they collaborate in and the company data that flows through all of it. Everything that makes Claude what it is sits behind that environment. We keep company access on devices we manage, make those devices hard to compromise and right-size what any one of them can reach, while caring a great deal about the day-to-day experience of the people using them. The company is growing quickly and this team is growing with it, so we treat the work as an engineering discipline: controls as code and automation over queues, built to scale with headcount rather than strain against it.

What it asks for · 5

  • Hands-on endpoint security engineering on macOS, Windows, Linux, or ChromeOS, such as MDM and declarative device management profile engineering, application allowlisting or binary authorization, system extensions and endpoint security frameworks, or their platform equivalents
  • Proficiency in Python and scripting languages generally; you architect and build integrations, automation, and internal tooling as a normal part of the job, and can write a detection when the work calls for it
  • Working depth in identity and access management, SaaS security, and zero-trust access
  • Threat-modeling judgment that finds the problems worth solving and the ability to scope them, define "done," and drive them to completion
  • Care for Anthropic's mission and the part corporate security plays in it

Also a plus

  • Experience defining the scope and choosing the tooling for a security program rather than inheriting it
  • Experience shipping an enforcement change to a large user population: using data to find what will break before it does, staging the rollout, building the alternative path for affected workflows, and moving people onto it ahead of enforcement
  • Endpoint depth across more than one of macOS, Windows, Linux, and ChromeOS, with the judgment to harden for the threats that matter rather than to a checklist
  • Mobile security across managed and BYOD contexts, including protecting people and devices in higher-risk settings such as international travel
  • Experience bringing security governance to a modern SaaS environment, including third-party integrations, delegated access, and the long tail of internally built and AI-generated apps, in a way that speeds decisions up rather than slowing them down
  • Configuration-as-code, infrastructure-as-code, and CI/CD applied to corporate infrastructure
  • LLM-assisted security tooling you built that materially changed what a team could cover, and the judgment to know which work to hand to a model, which to keep, and how to combine the two
  • A track record of getting security controls adopted across an organization through influence and partnership rather than authority

What the job covers

  • Drive endpoint hardening across macOS, Windows, Linux, and ChromeOS, including device management configuration, application allowlisting, patching, and browser policy, favoring controls that are versioned, reviewable, and repeatable over one-off configuration
  • Extend device-trust and zero-trust access controls so company systems are reached from managed devices bound to the right person and carrying the right level of access, treating the experience of fellow employees as a design constraint rather than an afterthought
  • Build the automation and integrations that let the team scale with the company: joiner/mover/leaver automation across identity and device management, exception and expiry workflows, posture-driven policy, and Claude-assisted triage of review queues
  • Lead SaaS and identity governance, including third-party OAuth grants, delegated admin access, chat-platform apps, browser extensions, and software security reviews, turning recurring decisions into policy and tooling
  • Partner across the wider Security team, IT, and Engineering on telemetry, detections, and shared standards, and help define how a company that increasingly runs on AI agents does so securely and at scale

Tools and skills named

Security & compliance
  • Security13×
  • IAM
Cloud & infra
  • Linux3×
  • CI/CD
Go to market
  • SaaS3×
Languages
  • Python
Models & research
  • LLM

Words the posting leans on

  • security13×
  • access7×
  • devices7×
  • rather7×
  • controls5×
  • experience5×
  • tooling5×
  • automation4×
  • endpoint4×
  • engineering4×
  • find4×
  • people4×
  • built3×
  • chromeos3×
  • device management3×
  • drive3×

Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.

The posting, your resume, and the gaps between them. One click loads all three.

More open at Anthropic

every open role at Anthropic

How this page was made

An automated read of a public job posting, fetched August 25, 2026 and last changed by Anthropic on August 21, 2026. Every list above is pulled from the posting’s own sentences — nothing rewritten, nothing added, no judgment about the role or the company. Counts and seniority are read off the text by rule, so they can be wrong where the posting is unusual. The original is the only thing that binds. Openings close without warning; check the source before spending an evening on it.