Staff+ Software Engineer, Distributed Systems

Anthropic · New York City, NY; San Francisco, CA · Safeguards (Trust & Safety) · listed September 15, 2026

The shape of it

Seniority
Staff
Experience asked
8+ years
Where
Hybrid
Stated pay
$320,000 – $485,000 USD
Requirements listed
6
Length
1,004 words

In the posting’s own words

We are looking for software engineers to help build safety and oversight mechanisms for our AI systems. As a software engineer on the Safeguards team, you will work to monitor models, prevent misuse, and ensure user well-being. This role will focus on building systems to detect unwanted model behaviors and prevent disallowed use of models. You will apply your technical skills to uphold our principles of safety, transparency, and oversight while enforcing our terms of service and acceptable use policies.

What it asks for · 6

  • Bachelor’s degree in Computer Science, Software Engineering or comparable experience
  • Proficiency in Python, Distributed Systems, and Infrastructure as Code
  • Have worked across multiple cloud providers, or built infrastructure designed to be provider-agnostic
  • Have built and operated large-scale, distributed infrastructure, such as data platforms, control planes, or job schedulers
  • Have experience with sandboxing and isolation technologies (containers, microVMs, network policy) or with a systems language such as Rust
  • Strong communication skills and ability to explain complex technical concepts to non-technical stakeholders

Also a plus

  • 8+ years of experience in a software engineering position
  • Have built systems that handle sensitive or regulated data, with requirements around access control, auditability, retention, and data residency
  • Have experience running LLM-based agents in production
  • Have experience with integrity, spam, fraud, or abuse detection and mitigation

What the job covers

  • Develop monitoring systems to detect unwanted behaviors from our API partners and potentially take automated enforcement actions; surface these in internal dashboards to analysts for manual review
  • Stand up and run deployments of those monitoring systems across multiple clouds, including inside cloud-provider partner environments where data must stay in place. Keep the deployments consistent through shared deployment pipelines, smoke tests, observability, and alerting
  • Design and harden the sandboxed runtime that AI agents execute in: isolation, network egress controls, least-privilege data access, audit logging, and insider-risk controls
  • Manage cost and capacity for large volumes of long-running agent work, and set and meet service-level objectives for the platform
  • Partner with the engineers and researchers who write and evaluate the monitoring agents, and with security, privacy, and legal teams, so new detection work can ship quickly on a platform everyone trusts

Degree language

  • Bachelor’s degree in Computer Science, Software Engineering or comparable experience

Tools and skills named

Cloud & infra
  • Distributed systems
  • Observability
Languages
  • Python
  • Rust
Security & compliance
  • Audit
  • Security
Models & research
  • LLM

Words the posting leans on

  • systems7×
  • data5×
  • experience5×
  • agents4×
  • control4×
  • software4×
  • built3×
  • deployments3×
  • engineers3×
  • infrastructure3×
  • models3×
  • partner3×
  • platform3×
  • access2×
  • behaviors2×
  • cloud2×

Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.

The posting, your resume, and the gaps between them. One click loads all three.

More open at Anthropic

every open role at Anthropic

How this page was made

An automated read of a public job posting, fetched September 15, 2026 and last changed by Anthropic on September 15, 2026. Every list above is pulled from the posting’s own sentences — nothing rewritten, nothing added, no judgment about the role or the company. Counts and seniority are read off the text by rule, so they can be wrong where the posting is unusual. The original is the only thing that binds. Openings close without warning; check the source before spending an evening on it.