Security Engineer - Threat Intel
Remote • New York City, NY; Remote-Friendly (Travel-Required) | San Francisco, CA | Washington, DC; San Francisco, CA | New York City, NY
Posted 12d ago
Job Location
New York City, NY; Remote-Friendly (Travel-Required) | San Francisco, CA | Washington, DC; San Francisco, CA | New York City, NY
Tech Stack
Remote Work Policy
Fully remote
Categories
Applied AI Engineer
About the job
Anthropic is at the forefront of AI development, making it a prime target for sophisticated adversaries. The Threat Intelligence function within the Detection & Response team is crucial for anticipating and mitigating these threats. As a Threat Intelligence Engineer, you will be a hands-on practitioner responsible for generating actionable intelligence that guides our detection strategies, threat hunts, and defensive priorities. You will track adversaries targeting frontier AI labs, develop tools and pipelines to transform raw indicators into operational defenses, and collaborate closely with detection engineers and incident responders to ensure intelligence effectively influences security outcomes. This is a high-impact, builder-oriented role within a small team, offering significant autonomy to shape the collection, analysis, and operationalization of threat intelligence at Anthropic.
Responsibilities
- Research, track, and report on threat actors and campaigns targeting AI labs, cloud infrastructure, and the technology sector, producing timely, actionable intelligence for Security Engineering stakeholders.
- Build and maintain tooling and automated pipelines for collecting, enriching, correlating, and operationalizing indicators of compromise into the detection and alerting stack.
- Develop and execute intelligence-driven threat hunts across endpoint, cloud, identity, and SaaS telemetry, and translate findings into durable detections.
- Perform technical analysis of malware, phishing infrastructure, and attacker tooling to extract indicators, TTPs, and attribution signals.
- Partner with Detection Engineering and Incident Response to translate intelligence into detection rules, hunting hypotheses, and incident context in near-real-time.
- Curate and triage inbound intelligence from commercial feeds, open source, government, and peer relationships, prioritizing based on Anthropic's threat model.
- Contribute to threat models and risk assessments to inform security architecture and defensive investments.
- Build and maintain external intelligence-sharing relationships with peer companies, ISACs, and government partners.
Requirements
- 5+ years of hands-on experience in cyber threat intelligence, threat hunting, or intrusion analysis at an organization facing sophisticated adversaries.
- Deep, demonstrable knowledge of specific nation-state or advanced criminal threat actors, including their tooling, infrastructure patterns, tradecraft, and targeting.
- Strong engineering skills, including production-quality Python (or similar), experience building automation and data pipelines.
- Comfort performing malware analysis, infrastructure analysis (passive DNS, certificate pivoting, netflow), and log analysis to develop and validate findings.
- Experience authoring detection logic (YARA, Sigma, Snort/Suricata, or SIEM-native queries) and understanding of detection durability.
- Ability to write clearly and concisely, producing intelligence products that are acted upon.
- Existing network in the threat intelligence community and a track record of productive bidirectional sharing.