Staff + Software Security Engineer, Labs

Anthropic · San Francisco, CA | New York City, NY | Seattle, WA · Security · listed October 5, 2026

The shape of it

Seniority
Staff
Where
Not stated
Stated pay
$320,000 – $485,000 USD
Requirements listed
10
Length
1,760 words

In the posting’s own words

This team is intentionally scrappy and ambitious. We're intentionally iterating fast on high-risk research bets and we expect a meaningful fraction not to land. If a 30% project success rate sounds uncomfortable, or uncharted and chaotic territory isn’t both frightening and exciting, this probably isn't the right fit. There are other places in Anthropic Security doing important work with more structure, less risk, and more certain paths to positive outcomes.

What it asks for · 10

  • Genuinely care about where AI is heading and want to work on the security problems that determine whether it goes well. This is the most important thing on this list
  • Have real depth in at least one area most software engineers don't touch (e.g. firmware or hardware security, applied cryptography, OS / kernel / hypervisor internals, formal methods and verification, reverse engineering and exploit development, or high-assurance / cross-domain systems)
  • Have built and shipped things under your own direction. Maybe you founded a company or research group, maintained an open-source project other people depend on, or shipped research that changed how people in your field work. We weight this far more than where you've worked or for how long
  • Have a track record of choosing the problem yourself and seeing it through, rather than only executing a plan someone else handed you
  • Are comfortable jumping between domains and layers of the stack when the problem calls for it, and have actually done so
  • Have run prototypes or experiments where the goal was answering a hard question rather than shipping a permanent system, including ones that didn't pan out
  • Write clearly enough to turn weeks of work into a couple of pages someone can act on
  • Change your mind when the evidence says to, and are fine being the least-expert person in a room full of specialists
  • Care about defense. Plenty of folks here come from offense and that background is valuable, but what you actually want to spend your time on now is making systems hold up
  • Are a strong programmer (Python plus at least one of Rust, Go, or C/C++) and can stand up real infrastructure without that being the interesting part of your week

Also a plus

  • Experience inside airgapped or high-side environments (classified networks, cross-domain solutions, ICS/SCADA, financial trading infrastructure) and the operational realities of working in them
  • A background in offensive security, red teaming, or vulnerability research, with calibrated intuitions for which threats actually matter
  • Familiarity with ML infrastructure (training pipelines, distributed schedulers, inference serving, accelerator hardware) sufficient for grounded conversations with researchers about what their workloads actually need
  • A history of working in environments built around rapid iteration rather than rigid change control: startups, applied research groups, independent consulting, small security shops

What the job covers

  • Own Security Labs projects end to end. You'll scope the bet, build the prototype, run it against real workloads, and bring it to either a hand-off or a documented exit
  • Stand up novel security infrastructure fast (isolated clusters, attestation chains, hypervisor and runtime work, verification tooling) optimizing for what we learn rather than for permanence
  • Find the receiving team early, bring them along while you build, and hand them something they actually want to own
  • Work embedded with research and infrastructure teams (Pretraining, RL, Inference, Compute) to test whether their workflows survive what you're proposing, and document precisely where they don't
  • Turn experimental results into short writeups that shape Anthropic's long-term security architecture, and into costed contingency plans we could execute on short notice
  • Help pick the next round of bets and influence the industry to get better along the way

Tools and skills named

Security & compliance
  • Security16×
  • Cryptography2×
  • Threat modeling
Models & research
  • Inference3×
  • Machine learning2×
Languages
  • C++
  • Go
  • Python
  • Rust

Words the posting leans on

  • security16×
  • research9×
  • actually7×
  • project7×
  • rather7×
  • bets6×
  • infrastructure5×
  • run5×
  • systems5×
  • thing5×
  • workloads5×
  • build4×
  • end4×
  • engineers4×
  • hardware4×
  • people4×

Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.

The posting, your resume, and the gaps between them. One click loads all three.

More open at Anthropic

every open role at Anthropic →

How this page was made

An automated read of a public job posting, fetched October 6, 2026 and last changed by Anthropic on October 5, 2026. Every list above is pulled from the posting’s own sentences — nothing rewritten, nothing added, no judgment about the role or the company. Counts and seniority are read off the text by rule, so they can be wrong where the posting is unusual. The original is the only thing that binds. Openings close without warning; check the source before spending an evening on it.