Offensive Hardware Security Engineer, Platform Security
San Francisco, CA | New York City, NY | Seattle, WA
Posted 14d ago
About the job
Anthropic is seeking a vulnerability assessment candidate for platform security. This role involves cross-functional collaboration with internal teams and external partners to assess security features across hardware, firmware, bootloaders, operating systems, and attestation systems. The primary goal is to identify and eliminate vulnerabilities from the ground up, requiring deep expertise in low-level systems security and a hands-on approach to ensure that identified issues are fully and correctly resolved in production, preventing reintroduction.
Responsibilities
- Audit secure boot chains from firmware through OS initialization for diverse hardware platforms.
- Audit attestation systems for cryptographic proof of system state.
- Audit measured boot implementations and runtime integrity monitoring.
- Integrate security controls with infrastructure teams without impacting training performance.
- Validate security mechanisms before production deployment.
- Conduct firmware vulnerability assessments and penetration testing.
- Build firmware vulnerability assessment pipelines for continuous security monitoring.
- Document security architectures and maintain threat models.
- Collaborate with vendors to ensure security capabilities meet exploit mitigation requirements.
Requirements
- Proven track record of hands-on vulnerability auditing on complex, security-critical systems.
- Hands-on experience with secure boot, measured boot, and attestation technologies (TPM, Intel TXT, AMD SEV, ARM TrustZone).
- Strong understanding of cryptographic protocols and hardware security modules.
- Experience with UEFI/BIOS or embedded firmware security, bootloader hardening, and chain of trust implementation.
- Proficiency in low-level programming languages (C, Assembly) and systems programming.
- Knowledge of firmware vulnerability assessment and threat modeling.
- Ability to work effectively across hardware and software boundaries.
- Strong communication and cross-functional collaboration skills.
- Track record of assessing security architectures for complex, distributed systems.
- Bachelor’s degree or equivalent combination of education, training, and/or experience.
Benefits
- Annual compensation range: $320,000 - $405,000 USD
- Visa sponsorship available for some roles and candidates.