
Compensation
$485,000-$625,000/yrDescription
About the role
Platform Security Engineering (PSE) sits within Data Center Security Engineering (DCSE). As Anthropic expands beyond traditional cloud providers into owned facilities, colocation, and partner sites, we take on the security responsibilities that cloud providers used to abstract away: firmware integrity, boot chain verification, platform trust, and host hardening. PSE exists so that Anthropic can deploy training and inference workloads to any qualified environment with a demonstrable security posture, including the technical controls behind our AI Safety Level commitments.
We are hiring an engineering manager to lead a group of platform security engineers covering firmware research, OS and kernel hardening, platform trust integration, and server manageability firmware. You will own the roadmap for this group, grow the team, and be accountable for the security posture of the compute platforms Anthropic runs on: hardware roots of trust, secure and measured boot, attestation, firmware supply chain, and the integrity of the hosts that hold model weights on bare-metal infrastructure.
This is a hands-on management role. You will not write most of the code, but you will review designs, make the final call on hard trade-offs, and be able to reason with your engineers from a silicon root of trust through firmware, bootloader, kernel, and host software. You will partner with infrastructure, fleet, and compute teams inside Anthropic, and with silicon vendors, OEMs, and compute providers outside it.
You will report to the Data Center Security Engineering manager.
Key responsibilities
-
Lead and grow the platform security engineering group: hiring, onboarding, development, performance, and prioritization for full-time engineers, and coordination of contractor and vendor engineers working alongside them
-
Own the platform security roadmap and its delivery: hardware root of trust and attestation, secure and measured boot across CPU, BMC, accelerator, and peripheral firmware, OS and kernel hardening, and the host-side pipeline that turns attestation evidence into production gates
-
Own the firmware supply chain posture for the fleet: SBOM and reference integrity manifests, authenticated update, rollback protection, and the vendor relationships needed to get fixes shipped
-
Drive platform risk assessments for new compute platforms and providers, and make evidence-based go/no-go recommendations with bounded risk rather than perfect-or-nothing gates
-
Partner with infrastructure, fleet, compute, and detection and response teams so that platform controls land in production without degrading training or inference performance
-
Manage relationships with silicon vendors, OEMs, and compute providers: security requirements, vulnerability management, disclosure and remediation timelines, and upstream and standards-body engagement (TCG, OCP, IETF)
-
Run the team's operating rhythm: design reviews, threat models, incident participation for platform-layer issues, and clear written status to security and infrastructure leadership
Minimum qualifications
-
Have 10+ years in systems security, with at least 5 years focused on firmware, hardware, or OS-level security
-
Have 5+ years as a people manager of security or systems engineers, including hiring and developing senior and staff-level engineers
-
Can go from architecture to implementation detail with your engineers: secure boot, measured boot, TPM and other roots of trust, attestation protocols (SPDM, DICE, remote attestation), UEFI and BMC firmware, and Linux kernel and OS hardening
-
Have owned a technical roadmap end to end, including the prioritization calls when security, performance, and delivery timelines conflict
-
Have worked directly with silicon vendors, OEMs, or cloud and bare-metal providers on security requirements and remediation, and can push a partner to a fix without burning the relationship
-
Write clearly: design reviews, risk assessments, and status for executives are part of the job
-
Are comfortable building a team and its processes from an early stage, with a scope that is broader than the headcount
Preferred qualifications
-
Experience managing a mixed team of full-time engineers, contractors, and vendor engineers while keeping design authority in-house
-
Hands-on background in OpenBMC or other server management firmware, DRTM or secure launch, or confidential computing primitives (TDX, SEV-SNP, ARM CCA)
-
A record of upstream contributions or maintainership in Linux, OpenBMC, or a comparable community, or standing in TCG, UEFI Forum, or OCP
-
Experience securing large-scale HPC or AI training infrastructure
-
Firmware vulnerability research, reverse engineering, or fuzzing background
-
Experience running coordinated vulnerability disclosure with hardware or firmware vendors
- Posted
- Aug 27, 2026
- Last seen
- Aug 28, 2026
- First seen
- Aug 28, 2026




