CF CloudFrame Job Scanner Open Dashboard →
Verified Active Opening

Staff Security Engineer, Detection & Response

Anthropic • Zürich, CH

Job Description

<div class="content-intro"><h2><strong>About Anthropic</strong></h2> <p>Anthropic’s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems.</p></div><h2>About the role</h2> <p>As Anthropic's models grow more capable, so does the interest of people who want to attack or misuse them. The Detection and Response (D&R) team spots those threats and responds to incidents across every layer of Anthropic's technology stack.</p> <p>The team is early-stage, so you'll help build our detection and response capabilities from the ground up and work closely with our security and research teams.</p> <h2>Key responsibilities</h2> <ul> <li>Lead incident response across a range of domains, from external attacks to insider threats, spanning all layers of Anthropic's technology stack</li> <li>Build and deploy tooling, including tools that use large language models, to improve how we detect and respond to threats</li> <li>Create and tune detections, playbooks, and workflows to catch and respond to incidents quickly</li> <li>Review incident response metrics and procedures, and drive improvements</li> <li>Work across security and engineering teams</li> <li>Take part in an on-call rotation</li> </ul> <h2>Minimum qualifications</h2> <ul> <li>Experience handling security incidents and investigating anomalies as part of a team</li> <li>Working knowledge of EDR, SIEM, SOAR, or similar security tooling</li> <li>A solid understanding of cloud environments and operations</li> <li>Experience working with engineering teams in a SaaS environment</li> <li>Proficiency with a scripting language such as Python and query languages such as SQL</li> <li>Strong communication and collaboration skills</li> <li>Able to lead projects with little guidance</li> <li>Able to pick up new languages and technologies quickly</li> </ul> <h2>Preferred qualifications</h2> <ul> <li>7+ years of software engineering experience, or 7+ years of detection engineering, incident response, or threat hunting experience</li> <li>Security operations or investigations involving large-scale Kubernetes environments</li> <li>Experience analyzing attack behavior and prototyping high-quality detections</li> <li>Experience with threat intelligence, malware analysis, infrastructure as code, or forensics</li> <li>Experience contributing to a high-growth startup environment</li> </ul><div class="content-conclusion"><h2><strong>Logistics</strong></h2> <p><strong>Minimum education: </strong>Bachelor’s degree or an equivalent combination of education, training, and/or experience</p> <p><strong>Required field of study: </strong>A field relevant to the role as demonstrated through coursework, training, or professional experience</p> <p><strong>Minimum years of experience: </strong>Years of experience required will correlate with the internal job level requirements for the position</p> <p><strong>Location-based hybrid policy:</strong> Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices.</p> <p><strong data-stringify-type="bold">Visa sponsorship:</strong> We do sponsor visas! However, we aren't able to successfully sponsor visas for every role

Job Reference ID: CF-153436 • Posted on CloudFrame Job Scanner