Engineering Manager, Hardware Platform Security

Anthropic · San Francisco, CA | Seattle, WA · Engineering

Posted 2026-08-28

Apply for this role →

About the role

Platform Security Engineering (PSE) sits within Data Center Security Engineering (DCSE). As Anthropic expands beyond traditional cloud providers into owned facilities, colocation, and partner sites, we take on the security responsibilities that cloud providers used to abstract away: firmware integrity, boot chain verification, platform trust, and host hardening. PSE exists so that Anthropic can deploy training and inference workloads to any qualified environment with a demonstrable security posture, including the technical controls behind our AI Safety Level commitments.

We are hiring an engineering manager to lead a group of platform security engineers covering firmware research, OS and kernel hardening, platform trust integration, and server manageability firmware. You will own the roadmap for this group, grow the team, and be accountable for the security posture of the compute platforms Anthropic runs on: hardware roots of trust, secure and measured boot, attestation, firmware supply chain, and the integrity of the hosts that hold model weights on bare-metal infrastructure.

This is a hands-on management role. You will not write most of the code, but you will review designs, make the final call on hard trade-offs, and be able to reason with your engineers from a silicon root of trust through firmware, bootloader, kernel, and host software. You will partner with infrastructure, fleet, and compute teams inside Anthropic, and with silicon vendors, OEMs, and compute providers outside it.

You will report to the Data Center Security Engineering manager.

Key responsibilities

Lead and grow the platform security engineering group: hiring, onboarding, development, performance, and prioritization for full-time engineers, and coordination of contractor and vendor engineers working alongside them

Own the platform security roadmap and its delivery: hardware root of trust and attestation, secure and measured boot across CPU, BMC, accelerator, and peripheral firmware, OS and kernel hardening, and the host-side pipeline that turns attestation evidence into production gates

Own the firmware supply chain posture for the fleet: SBOM and reference integrity manifests, authenticated update, rollback protection, and the vendor relationships needed to get fixes shipped

Drive platform risk assessments for new compute platforms and providers, and make evidence-based go/no-go recommendations with bounded risk rather than perfect-or-nothing gates

Partner with infrastructure, fleet, compute, and detection and response teams so that platform controls land in production without degrading training or inference performance

Manage relationships with silicon vendors, OEMs, and compute providers: security requirements, vulnerability management, disclosure and remediation timelines, and upstream and standards-body engagement (TCG, OCP, IETF)

Run the team's operating rhythm: design reviews, threat models, incident participation for platform-layer issues, and clear written status to security and infrastructure leadership

Minimum qualifications

Have 10+ years in systems security, with at least 5 years focused on firmware, hardware, or OS-level security

Have 5+ years as a people manager of security or systems engineers, including hiring and developing senior and staff-level engineers

Can go from architecture to implementation detail with your engineers: secure boot, measured boot, TPM and other roots of trust, attestation protocols (SPDM, DICE, remote attestation), UEFI and BMC firmware, and Linux kernel  and OS hardening

Have owned a technical roadmap end to end, including the prioritization calls when security, performance, and delivery timelines conflict

Have worked directly with silicon vendors, OEMs, or cloud and bare-metal providers on security requirements and remediation, and can push a partner to a fix without burning the relationship

Write clearly: design reviews, risk assessments, and status for executives are part of the job

Are comfortable building a team and its processes from an early stage, with a scope that is broader than the headcount

Preferred qualifications

Experience managing a mixed team of full-time engineers, contractors, and vendor engineers while keeping design authority in-house

Hands-on background in OpenBMC or other server management firmware, DRTM or secure launch, or confidential computing primitives (TDX, SEV-SNP, ARM CCA)

A record of upstream contributions or maintainership in Linux, OpenBMC, or a comparable community, or standing in TCG, UEFI Forum, or OCP

Experience securing large-scale HPC or AI training infrastructure

Firmware vulnerability research, reverse engineering, or fuzzing background

Experience running coordinated vulnerability disclosure with hardware or firmware vendors

The annual compensation range for this role is listed below.

For sales roles, the range provided is the role’s On Target Earnings ("OTE") range, meaning that the range includes both the sales commissions/sales bonuses target and annual base salary for the role.

Annual Salary:

$485,000—$625,000 USD

Apply for this role →

← Back to all jobs