Staff Security Engineer, Detection & Response

Anthropic · Zürich, CH · Security · listed September 28, 2026

The shape of it

Seniority
Staff
Experience asked
7+ years
Where
Hybrid
Requirements listed
8
Length
866 words

In the posting’s own words

The team is early-stage, so you'll help build our detection and response capabilities from the ground up and work closely with our security and research teams.

What it asks for · 8

  • Experience handling security incidents and investigating anomalies as part of a team
  • Working knowledge of EDR, SIEM, SOAR, or similar security tooling
  • A solid understanding of cloud environments and operations
  • Experience working with engineering teams in a SaaS environment
  • Proficiency with a scripting language such as Python and query languages such as SQL
  • Strong communication and collaboration skills
  • Able to lead projects with little guidance
  • Able to pick up new languages and technologies quickly

Also a plus

  • 7+ years of software engineering experience, or 7+ years of detection engineering, incident response, or threat hunting experience
  • Security operations or investigations involving large-scale Kubernetes environments
  • Experience analyzing attack behavior and prototyping high-quality detections
  • Experience with threat intelligence, malware analysis, infrastructure as code, or forensics
  • Experience contributing to a high-growth startup environment

What the job covers

  • Lead incident response across a range of domains, from external attacks to insider threats, spanning all layers of Anthropic's technology stack
  • Build and deploy tooling, including tools that use large language models, to improve how we detect and respond to threats
  • Create and tune detections, playbooks, and workflows to catch and respond to incidents quickly
  • Review incident response metrics and procedures, and drive improvements
  • Work across security and engineering teams
  • Take part in an on-call rotation

Tools and skills named

Security & compliance
  • Security5×
Languages
  • Python
  • SQL
Cloud & infra
  • Kubernetes
Go to market
  • SaaS
Models & research
  • LLM
Product & design
  • Prototyping
Ways of working
  • On-call

Words the posting leans on

  • experience7×
  • incident6×
  • detection5×
  • security5×
  • threats5×
  • engineering4×
  • language4×
  • attack3×
  • incident response3×
  • respond3×
  • build2×
  • layer2×
  • lead2×
  • models2×
  • operations2×
  • part2×

Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.

The posting, your resume, and the gaps between them. One click loads all three.

More open at Anthropic

every open role at Anthropic →

How this page was made

An automated read of a public job posting, fetched September 28, 2026 and last changed by Anthropic on September 28, 2026. Every list above is pulled from the posting’s own sentences — nothing rewritten, nothing added, no judgment about the role or the company. Counts and seniority are read off the text by rule, so they can be wrong where the posting is unusual. The original is the only thing that binds. Openings close without warning; check the source before spending an evening on it.