- Company Name
- Anthropic
- Job Title
- Security Engineer, Detection & Response
- Job Description
-
**Job Title**
Security Engineer, Detection & Response
**Role Summary**
Design, build, and operate the detection and incident response capabilities for a cutting‑edge AI platform. Lead incident investigations, develop automated tooling (including LLM‑based solutions), and continuously improve detection and response playbooks across the entire technology stack.
**Expectations**
- 5+ years in detection engineering, threat hunting, or incident response;
- 3+ years of software engineering experience, preferably with security focus;
- Expertise in cloud‑native environments and SaaS operations;
- Ability to work independently, lead projects, and participate in an on‑call rotation;
- Strong written and verbal communication, and collaboration across security and engineering teams.
**Key Responsibilities**
1. Lead end‑to‑end incident response across external attacks, insider threats, and all layers of the platform.
2. Design, prototype, and deploy novel detection tooling, leveraging large‑language models where appropriate.
3. Author, maintain, and refine detection rules, playbooks, and automated workflows to accelerate triage and containment.
4. Monitor incident response metrics, identify gaps, and implement process improvements.
5. Collaborate with cloud, DevOps, and engineering teams to embed security controls and observability into the continuous delivery pipeline.
**Required Skills**
- Software development (Python preferred), query languages (SQL), and scripting;
- Deep knowledge of EDR, SIEM, SOAR, and related security tooling;
- Experience with Kubernetes security and large‑scale cloud environments;
- Established track record in threat hunting, forensic analysis, or related investigative work;
- Ability to prototype high‑quality detections and conduct attack‑behavior analysis;
- Excellent teamwork, communication, and self‑driven project ownership.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Cybersecurity, or a related field (or equivalent professional experience).
- Professional security certifications (e.g., CISSP, CEH, GCIH, CSX‑DE) are highly desirable.