Platform Hardware Security Engineer – Secure Boot & Attestation
Anthropic · San Francisco
Job description
About the role
Anthropic is looking for a Platform Hardware Security Engineer to design and implement security architectures for its bare‑metal AI training infrastructure. You will work across hardware and software teams to build secure boot chains, attestation systems, and runtime integrity monitoring that protect the integrity of massive compute fleets.
Key responsibilities
- Design and implement secure boot chains from firmware through OS initialization for CPUs, BMCs, switches, peripherals, and embedded microcontrollers.
- Architect cryptographic attestation systems that provide proof of system state from the hardware root of trust to the application layer.
- Develop measured‑boot implementations and continuous runtime integrity monitoring.
- Create reference architectures and security requirements for bare‑metal deployments.
- Integrate security controls with infrastructure teams while preserving AI training performance.
- Prototype, validate, and deploy security mechanisms at scale.
- Conduct firmware vulnerability assessments, penetration testing, and build analysis pipelines for continuous monitoring.
- Document security architectures, maintain threat models, and collaborate with hardware and software vendors.
Required profile
- Hands‑on experience with secure boot, measured boot, and attestation technologies (TPM, Intel TXT, AMD SEV, ARM TrustZone).
- Strong understanding of cryptographic protocols and hardware security modules.
- Experience with UEFI/BIOS or embedded firmware security, bootloader hardening, and chain‑of‑trust implementation.
- Proficiency in low‑level programming languages such as C, Rust, and Assembly.
- Knowledge of firmware vulnerability assessment, threat modeling, and supply‑chain security.
- Track record designing security architectures for complex, distributed systems.
- Familiarity with NIST firmware security guidelines and hardware security frameworks.
Required skills
- Secure boot
- Measured boot
- Attestation technologies (TPM, Intel TXT, AMD SEV, ARM TrustZone)
- Cryptographic protocols
- Hardware security modules
- UEFI/BIOS firmware
- Embedded firmware security
- Bootloader hardening
- C programming
- Rust programming
- Assembly language
- Firmware vulnerability assessment
- Threat modeling
- Supply‑chain security
- NIST firmware security guidelines
Questions fréquentes
Why are you reporting this job?
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 3 weeks ago
Expires 1 month from now
12 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
Anthropic
San Francisco