Platform Security Engineer, OpenBMC
Anthropic · San Francisco, CA | New York City, NY | Seattle, WA · 2026-07-03
About this role
<div class="content-intro"><h2><strong>About Anthropic</strong></h2> <p>Anthropic’s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems.</p></div><h2><strong>About the role</strong></h2> <p>Anthropic is standing up a founding team to own the OpenBMC-based management firmware running across its server fleet. You would be one of the first engineers on it. That means production firmware and manageability features (board bring-up through production) on one side, and hardening that firmware against sophisticated adversaries on the other.</p> <p>Security is a first-class constraint in everything you ship: you'll write firmware to a high security bar and partner closely with our firmware security and hardware engineers on secure boot, signing, and attestation.</p> <h2><strong>Key responsibilities</strong></h2> <p>Production and manageability:</p> <ul> <li>Design, build, and ship OpenBMC firmware and manageability features for x86 and Arm (including GPU) platforms, from bring-up through production, using Yocto/OpenEmbedded</li> <li>Build the management stack on DMTF/OCP standards (MCTP, PLDM, SPDM, Redfish, RDE) and IPMI/KCS: sensors, telemetry, inventory, logging, RAS</li> <li>Implement BMC-to-BIOS/host communications, eSPI/LPC, thermal/fan/power management (PMBus)</li> <li>Work the hardware/firmware boundary: I2C/I3C, SPI, PCIe, SMBus, device trees, U-Boot, Linux</li> </ul> <p>Security and hardening:</p> <ul> <li>Own the BMC security posture: secure and measured boot, root of trust, attestation (SPDM), authenticated update (PLDM FW Update), rollback protection, attack-surface reduction</li> <li>Lead threat modeling and secure design reviews; run coordinated vulnerability disclosure with vendors and the upstream community</li> <li>Build verification tooling: static analysis, fuzzing, firmware extraction, CI gating</li> </ul> <h2><strong>Minimum qualifications&nbsp;</strong></h2> <ul> <li>Strong technical cross-functional leadership skills, direction setting</li> <li>Hands-on OpenBMC/BMC firmware experience on x86 and/or Arm, from bring-up through production with hands-on D-Bus/sdbusplus</li> <li>Strong C/C++ and Python, deep Linux user-space/kernel fundamentals, and Yocto/OpenEmbedded proficiency</li> <li>A security mindset applied to firmware, not bolted on afterward</li> <li>Upstream contributions to OpenBMC, U-Boot, DMTF, or OCP</li> <li>Working knowledge of out-of-band and in-band management, the relevant DMTF specs, and the device interfaces they run over</li> <li>Strong debugging and a track record of shipping reliable, well-tested code.</li> <li>Clear communication across internal teams and external vendors</li> <li>Ability to work effectively across hardware and software boundaries</li> <li>Knowledge of NIST firmware security guidelines and hardware security frameworks, specifically SP 800-193 and 800-147/155</li> </ul> <h2><strong>Preferred qualifications</strong></h2> <ul> <li>8+ years of experience in systems security, with at least 5 years focused on firmware and hardware security (firmware, bootloaders, and OS-level security)</li> <li>Hardware roots of trust and attestation: Caliptra, OCP S.A.F.E., TPM/HRoT, SPDM</li> <li>Memory-safe systems code in Rust or Zig</li> <li>Firmware vulnerability research, reverse-engineering, or fuzzing</li> <li>Previous work with AI/ML infrastructure security</li> </ul><div class="content-pay-transparency"><div class="pay-input"><div class="description"><p>The annual compensation range for this role is listed below.&nbsp;</p> <p>For sales roles, the range provided is the role’s On Target Earnings ("OTE") range, meaning that the range includes both the sales commissions/sales bonuses target and annual base salary for the role.</p></div><div class="title">Annual Salary:</div><div class="pay-range"><span>$405,000</span><span class="divider">&mdash;</span><span>$405,000 USD</span></div></div></div><div class="content-conclusion"><h2><strong>Logistics</strong></h2> <p><strong>Minimum education: </strong>Bachelor’s degree or an equivalent combination of education, training, and/or experience</p> <p><strong>Required field of study:&nbsp;</strong>A field relevant to the role as demonstrated through coursework, training, or professional experience</p> <p><strong>Minimum years of experience: </strong>Years of experience required will correlate with the internal job level requirements for the position</p> <p><strong>Location-based hybrid policy:</strong> Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices.</p> <p><strong data-stringify-type="bold">Visa sponsorship:</strong>&nbsp;We do sponsor visas! However, we aren't able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every…
Skills asked for
- linux
- c++
- python
- rust
Similar jobs
- Software Engineer, Platform SecurityDecagon · San Francisco
- Senior Software Engineer, Platform SecurityDecagon · San Francisco
- Offensive Hardware Security Engineer, Platform SecurityAnthropic · San Francisco
- Platform Security Engineering, AuditorAnthropic · San Francisco
- Platform Security Engineering, Operating SystemsAnthropic · San Francisco
- Senior Platform Security EngineerMonaco · San Francisco
- Software Engineer – Platform SecurityFriendliai · San Francisco
- Senior Platform Engineer, SecurityDecagon · San Francisco
Your next role is already in here.
Search live openings from thousands of employers, save the ones worth a second look, and let JobBob keep watch for the rest.