The opportunity
Anthropic is standing up a founding team to own the server management firmware running across its server fleet. You would be one of the first engineers on it.
What you'll do
Design, build, and ship OpenBMC firmware and manageability features for x86: and Arm (including GPU) platforms, from bring-up through production, using Yocto/OpenEmbedded
Build the management stack on DMTF/OCP standards (MCTP, PLDM, SPDM, Redfish,: RDE) and IPMI/KCS: sensors, telemetry, inventory, logging, RAS
Implement BMC-to-BIOS/host communications, eSPI/LPC, thermal/fan/power management (PMBus)
Work the hardware/firmware boundary: I2C/I3C, SPI, PCIe, SMBus, device trees, U-Boot, Linux
Own the BMC security posture: secure and measured boot, root of trust, attestation (SPDM), authenticated update (PLDM FW Update), rollback protection, attack-surface reduction
Lead threat modeling and secure design reviews; run coordinated vulnerability: disclosure with vendors and the upstream community
What they're looking for
- + years of experience in systems security, with at least 5 years focused on: firmware and hardware security (firmware, bootloaders, and OS-level security)
- Hardware roots of trust and attestation: Caliptra, OCP S.A.F.E., TPM/HRoT, SPDM
- Memory-safe systems code in Rust or Zig
- Firmware vulnerability research, reverse-engineering, or fuzzing
- Previous work with AI/ML infrastructure security