Design and build security foundations for Anthropic's AI systems, ensuring secure behavior by default.
Posted by employer 22 hours ago
First seen on Joblaze 1 hour ago
Last verified on the company career page 1 hour ago
Joblaze summary
In this role, the Staff Software Security Engineer will design and implement security frameworks that underpin Anthropic's AI systems, focusing on areas like cryptographic frameworks and authorization systems. Proficiency in programming languages such as Go, Rust, or Python, along with a strong grasp of authentication protocols and applied cryptography, is essential. This position is suited for experienced engineers with a background in security-relevant systems and a passion for AI safety. The role involves collaboration across various teams, emphasizing a culture of security engineering within the organization.
Quick facts
- Is the Staff + Software Security Engineer, Secure Frameworks role remote?
- It's hybrid — Anthropic expects some on-site time in San Francisco, CA, United States.
- What's the salary range?
- Anthropic lists $32,000–$485,000 for this role.
- How much experience is required?
- At least 8 years of relevant experience for this Staff + Software Security Engineer, Secure Frameworks role.
- Where is the role based?
- Anthropic is hiring for this position in San Francisco, CA, United States.
- What's the tech stack?
- Joblaze extracted these technologies from the posting: Go, JWT, Kubernetes, OAuth 2.0, OIDC, PKI.
- Does Anthropic sponsor work visas for this role?
- Yes — the posting indicates visa sponsorship is available for the right candidate.
- What seniority level is this role?
- Anthropic targets staff-level candidates for this position.
- Is this full-time or contract?
- Full-time for this Staff + Software Security Engineer, Secure Frameworks role at Anthropic.
From the original posting
About Anthropic
About the team
Secure Frameworks is the team in Anthropic's Security Engineering org that builds shared security libraries and frameworks the rest of the company builds on. We collaborate closely with teams and leaders across Anthropic to own critical security foundations, including workload identity and authorization, cryptographic frameworks, and the centralized access proxy that secures traffic to internal applications.
Our mission is to make the secure thing easy and the easy thing secure by helping Anthropic engineers get secure behaviour by default and preventing entire classes of vulnerabilities through careful design. We own what we ship, help customers adopt better security practices and at times we work embedded directly in research, infrastructure or product teams.
About the role
You will design, build and run security foundations used across Anthropic's fleet, from threat model through production, on-call and adoption. Much of the work is greenfield: our infrastructure is growing quickly and the timelines are compressed, so you will help define the architecture rather than inherit it. Depending on your strengths you will focus on one or two of the areas below and contribute across the rest.
- Build critical security foundations including cryptographic frameworks, mTLS infrastructure, secure serialization, and authorization systems, designed to prevent entire classes of vulnerabilities
- Partner with product, research, infrastructure, and other security teams to ensure frameworks integrate smoothly with lower-layer security controls
- Scope, design and build security services and libraries end-to-end, maintain them in production, and drive through ambiguous technical problems with minimal oversight
- Build and operate the zero-trust access gateway that fronts Anthropic's internal services
- Design and roll out authorization frameworks so services enforce least privilege consistently instead of each inventing its own access controls
- Own cryptographic frameworks and libraries
- Mentor engineers, contribute to hiring, and grow security engineering culture across Anthropic
Minimum qualifications
- 8+ years of software engineering experience building security-relevant systems in production, including leading complex initiatives independently
- Strong programming skills in Go, Rust or Python
- Deep understanding of authentication and authorization systems: OAuth 2.0 / OIDC, JWTs, service-to-service auth, policy-based access control
- Hands-on experience with PKI, X.509, mTLS and workload identity
- Working knowledge of applied cryptography: choosing and composing primitives correctly, key management, and the ways libraries fail in practice
- Experience shipping and operating high-reliability services on Kubernetes across cloud and on-prem environments, including being on call for them
- A track record of bringing clarity and ownership to ambiguous technical problems and driving them to resolution across teams
- A strong sense of developer experience
- Clear communication across all levels of the organization
- Passion for AI safety and the role security engineering plays in building trustworthy AI systems
Preferred qualifications
- Built security frameworks or libraries adopted across an engineering organization, and done the work to drive that adoption
- Built or operated a zero-trust / BeyondCorp-style access gateway or identity-aware proxy
- Migrated a fleet to mTLS at scale, including certificate issuance and staged enforcement
- Maintained or contributed to open-source cryptographic libraries
- Designed authorization systems using policy languages or relationship-based models
- Familiarity with ML infrastructure (training, inference serving)
The annual compensation range for this role is listed below.
Annual Salary:
$32,000—$485,000 USD
Logistics
Standard company text repeated across Anthropic's postings is omitted here.