Platform Security Engineer, DRTM / Secure Launch

Anthropic$320K — $405K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of systems security experience, with emphasis on firmware and bootloader security.
  • Strong coding skills in C and assembly, with a focus on Linux kernel and early boot processes.
  • Experience contributing significant work to upstream Linux or comparable communities.
  • Proficient at debugging across hardware/firmware boundaries including JTAG and serial interfaces.
  • Technical leadership skills for guiding cross-functional teams and vendor collaboration.
  • Clear communicator able to produce specifications and technical documents in writing.
  • Familiarity with NIST firmware security standards, particularly SP 800-193, 800-147, and 800-155.

Responsibilities

  • Lead the adoption and integration of DRTM security features in both x86 and ARM environments.
  • Develop and implement attestation services leveraging DRTM capabilities.
  • Create a bootloader-agnostic method for managing DRTM sessions.
  • Explore enhancements for DRTM solutions, including isolation methods on x86 systems.
  • Collaborate with OEMs on refining DRTM requirements and identifying feasible modifications.
  • Publish and promote DRTM developments upstream, taking on maintainership duties as necessary.
  • Support low-level platform security by implementing features and diagnosing firmware issues.

Benefits

  • Visa sponsorship support available for eligible candidates.
  • Flexibility with a hybrid work environment, requiring only 25% in-office attendance.
  • Opportunities for visibility and influence in open-source communities.
  • Access to cross-functional collaboration with hardware and firmware teams.
  • Engagement in technical discussions at conferences and through publications.
Full Job Description
Anthropic is building the platform security foundation for the infrastructure that trains and serves frontier models. This role owns Dynamic Root of Trust for Measurement (DRTM) across that fleet: bringing it up on x86 and ARM, building the attestation and isolation properties it makes possible, and hardening the parts of the platform that DRTM alone does not cover. The work sits at the lowest layers of the stack: firmware, bootloaders, kernel, and the silicon features underneath them. It is also unusually public. We expect the DRTM work done here to land upstream, and the person in this role will be a visible participant in the Linux and firmware communities rather than a consumer of them. Security carries the same design weight as performance and scalability at datacenter scale. You will partner closely with our firmware security, hardware, and OS hardening engineers, and directly with vendor and OEM partners whose DRTM implementations we depend on. Key responsibilities DRTM adoption and integration: • Own adoption and integration of DRTM hardware security features across Anthropic infrastructure, on both x86 and ARM platforms • Implement attestation services and the additional security and privacy capabilities that DRTM presence enables • Design and implement a bootloader-agnostic solution for initiating and relaunching DRTM sessions • Investigate further hardening of existing DRTM solutions: PPAM to isolate SMM on x86, VMM features to isolate UEFI runtime services, ACPI handling and hardening in DRTM environments Vendors and upstream: • Interface with vendor and OEM partners on their DRTM solutions: refine requirements jointly and determine which changes are desirable and feasible • Publish relevant DRTM work upstream and help carry Linux Secure Launch maintainership as tboot is retired • Act as technical lead in architecture and design, and disseminate the work through technical papers, conference talks, and community engagement • Assist other Anthropic teams with their own open source efforts and upstream interactions Broader low-level platform work: • Build and harden other platform security features, including confidential computing solutions such as TDX and SEV • Support custom operating system artifacts, implement device drivers for custom hardware and features, and do firmware diagnosis and enhancement work • Debug and diagnose kernel and system-level issues on production hardware • Take on investigative work in new technical areas and old unsolved ones (for example, the distinct security problems in dTPMs and fTPMs) Minimum qualifications • Deep hands-on experience with measured boot and roots of trust: DRTM (Intel TXT, AMD SKINIT, ARM equivalents), SRTM, TPM 1.2/2.0, and the measurement chains built on them • Strong C and assembly, with deep Linux kernel and early-boot fundamentals (bootloaders, UEFI, ACPI, SMM) • A record of landing non-trivial work upstream in Linux, TianoCore, GRUB, or a comparable community • Comfort at the hardware/firmware boundary and with the debugging that comes with it: JTAG, serial, platform-level bring-up, silicon errata • Strong technical cross-functional leadership and direction setting, including with external vendors and OEMs • Clear written communication: this role produces specifications, design docs, and public technical writing • Working knowledge of NIST firmware security guidance, particularly SP 800-193 and 800-147/155 Preferred qualifications • 8+ years in systems security, with at least 5 years focused on firmware, bootloader, and OS-level security • Existing maintainership or subsystem ownership in Linux, or standing in the TCG, UEFI Forum, or OCP communities • Confidential computing implementation experience: TDX, SEV-SNP, ARM CCA, and their attestation flows • Hardware roots of trust and attestation beyond the TPM: Caliptra, OCP S.A.F.E., SPDM • Memory-safe systems code in Rust • Firmware vulnerability research, reverse engineering, or fuzzing • Previous work with AI/ML infrastructure security The annual compensation range for this role is listed below. For sales roles, the range provided is the role's On Target Earnings ("OTE") range, meaning that the range includes both the sales commissions/sales bonuses target and annual base salary for the role. Annual Salary: $320,000-$405,000 USD Logistics Minimum education: Bachelor's degree or an equivalent combination of education, training, and/or experience Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience Minimum years of experience: Years of experience required will correlate with the internal job level requirements for the position Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices. Visa sponsorship: We do sponsor visas! However, we aren't able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this.

About Anthropic

Anthropic is an artificial intelligence research lab that focuses on developing AI systems that are safe, reliable, and trustworthy. The company was founded in 2019 by Dr. Yoshua Bengio, a leading AI researcher and winner of the Turing Award. Anthropic's research is focused on developing AI systems that can learn from small amounts of data, reason about complex systems, and interact with humans in a natural way. The company is based in New York City and has a team of experienced AI researchers and engineers.
Learn more about Anthropic
Size
50 employees
Industry
Founded
2019

Similar Jobs

More Jobs at Anthropic

More Information Technology Jobs

Find similar Platform Security Engineer, DRTM / Secure Launch jobs: