Staff Security Engineer, Detection & Response
About the role
As Anthropic's models grow more capable, so does the interest of people who want to attack or misuse them. The Detection and Response (D&R) team spots those threats and responds to incidents across every layer of Anthropic's technology stack.
The team is early-stage, so you'll help build our detection and response capabilities from the ground up and work closely with our security and research teams.
Key responsibilities
Lead incident response across a range of domains, from external attacks to insider threats, spanning all layers of Anthropic's technology stack
Build and deploy tooling, including tools that use large language models, to improve how we detect and respond to threats
Create and tune detections, playbooks, and workflows to catch and respond to incidents quickly
Review incident response metrics and procedures, and drive improvements
Work across security and engineering teams
Take part in an on-call rotation
Minimum qualifications
Experience handling security incidents and investigating anomalies as part of a team
Working knowledge of EDR, SIEM, SOAR, or similar security tooling
A solid understanding of cloud environments and operations
Experience working with engineering teams in a SaaS environment
Proficiency with a scripting language such as Python and query languages such as SQL
Strong communication and collaboration skills
Able to lead projects with little guidance
Able to pick up new languages and technologies quickly
Preferred qualifications
7+ years of software engineering experience, or 7+ years of detection engineering, incident response, or threat hunting experience
Security operations or investigations involving large-scale Kubernetes environments
Experience analyzing attack behavior and prototyping high-quality detections
Experience with threat intelligence, malware analysis, infrastructure as code, or forensics
Experience contributing to a high-growth startup environment