SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 320,000 - 0 / annual
Anthropic is seeking a Platform Security Engineer to own Dynamic Root of Trust for Measurement (DRTM) across the infrastructure that trains and serves frontier AI models. This role sits at the lowest layers of the stack—firmware, bootloaders, kernel, and silicon features—and involves bringing DRTM up on both x86 and ARM platforms, building attestation and isolation properties, and hardening platform security components.
Key responsibilities include:
**DRTM Adoption & Integration:** Own adoption and integration of DRTM hardware security features across Anthropic's infrastructure on x86 and ARM. Implement attestation services and security/privacy capabilities enabled by DRTM. Design bootloader-agnostic solutions for initiating and relaunching DRTM sessions. Investigate further hardening of existing DRTM solutions, including PPAM for SMM isolation on x86, VMM features for UEFI runtime service isolation, and ACPI handling in DRTM environments.
**Vendor & Upstream Engagement:** Interface with vendor and OEM partners on DRTM solutions, refining requirements jointly. Publish relevant DRTM work upstream and help carry Linux Secure Launch maintainership as tboot is retired. Act as technical lead in architecture and design, disseminating work through technical papers, conference talks, and community engagement. Assist other Anthropic teams with open source efforts and upstream interactions.
**Broader Platform Security:** Build and harden other platform security features, including confidential computing solutions like TDX and SEV. Support custom OS artifacts, implement device drivers for custom hardware, and conduct firmware diagnosis and enhancement work. Debug and diagnose kernel and system-level issues on production hardware. Take on investigative work in new and unsolved technical areas (e.g., dTPM vs. fTPM security distinctions).
Minimum qualifications include deep hands-on experience with measured boot and roots of trust (DRTM, SRTM, TPM); strong C and assembly with deep Linux kernel and early-boot fundamentals; a record of landing non-trivial work upstream in Linux, TianoCore, GRUB, or comparable communities; comfort at the hardware/firmware boundary with debugging expertise (JTAG, serial, platform bring-up, silicon errata); strong technical cross-functional leadership with external vendors and OEMs; clear written communication for specifications and design docs; and working knowledge of NIST firmware security guidance (SP 800-193, 800-147/155).
Preferred qualifications: 8+ years in systems security with at least 5 years focused on firmware, bootloader, and OS-level security; existing maintainership or subsystem ownership in Linux or standing in TCG, UEFI Forum, or OCP communities; confidential computing implementation experience (TDX, SEV-SNP, ARM CCA); hardware roots of trust and attestation beyond TPM (Caliptra, OCP S.A.F.E., SPDM); memory-safe systems code in Rust; firmware vulnerability research, reverse engineering, or fuzzing; previous work with AI/ML infrastructure security.