Senior/Staff Security Engineer, Threat Intelligence

Zürich, CH

Posted 16d ago

Job Location

Zürich, CH

Tech Stack

Remote Work Policy

On-site

Categories

Applied AI Engineer

About the job

Anthropic is at the forefront of AI development, making it a prime target for sophisticated actors. The Threat Intelligence function within the Detection & Response team is crucial for anticipating and mitigating these threats. In this role, you will be a hands-on practitioner responsible for generating actionable intelligence that guides our detection, hunting, and defensive strategies. You will track adversaries targeting AI labs, develop tools and pipelines to transform raw indicators into operational defenses, and collaborate closely with detection engineers and incident responders to ensure intelligence effectively influences security outcomes. This is a high-impact, builder-focused role on a small team, offering significant autonomy in shaping how threat intelligence is collected, analyzed, and operationalized at Anthropic.

Responsibilities

  • Research, track, and report on threat actors and campaigns targeting AI labs, cloud infrastructure, and the technology sector, producing timely intelligence for Security Engineering stakeholders.
  • Build and maintain tooling and automated pipelines for collecting, enriching, correlating, and operationalizing indicators of compromise into the detection and alerting stack.
  • Develop and execute intelligence-driven threat hunts across endpoint, cloud, identity, and SaaS telemetry, and translate findings into durable detections.
  • Perform technical analysis of malware, phishing infrastructure, and attacker tooling to extract indicators, TTPs, and attribution signals.
  • Partner with Detection Engineering and Incident Response to translate intelligence into detection rules, hunting hypotheses, and incident context in near-real-time.
  • Curate and triage inbound intelligence from commercial feeds, open source, government, and peer relationships, prioritizing based on Anthropic's threat model.
  • Contribute to threat models and risk assessments to inform security architecture and defensive investments.
  • Build and maintain external intelligence-sharing relationships with peer companies, ISACs, and government partners.

Requirements

  • Hands-on experience in cyber threat intelligence, threat hunting, or intrusion analysis at an organization facing sophisticated adversaries.
  • Deep, demonstrable knowledge of specific nation-state or advanced criminal threat actors, including their tooling, infrastructure patterns, tradecraft, and targeting.
  • Strong engineering skills with production-quality Python (or similar), experience building automation and data pipelines, and ability to build tooling end-to-end.
  • Comfort performing malware analysis, infrastructure analysis (passive DNS, certificate pivoting, netflow), and log analysis to develop and validate findings.
  • Experience authoring detection logic (YARA, Sigma, Snort/Suricata, or SIEM-native queries) and understanding of durable vs. brittle detection principles.
  • Ability to write clearly and concisely, producing intelligence products that are acted upon.
  • Bachelor’s degree or an equivalent combination of education, training, and/or experience.

About Anthropic

Get new AI jobs in your inbox

A weekly digest of the newest AI engineering roles.

© 2026 AI Job Board. All rights reserved.