Platform Security Engineer, OpenBMCActive$320K

The opportunity

Anthropic is standing up a founding team to own the server management firmware running across its server fleet. You would be one of the first engineers on it.

What you'll do

  • Design, build, and ship OpenBMC firmware and manageability features for x86: and Arm (including GPU) platforms, from bring-up through production, using Yocto/OpenEmbedded

  • Build the management stack on DMTF/OCP standards (MCTP, PLDM, SPDM, Redfish,: RDE) and IPMI/KCS: sensors, telemetry, inventory, logging, RAS

  • Implement BMC-to-BIOS/host communications, eSPI/LPC, thermal/fan/power management (PMBus)

  • Work the hardware/firmware boundary: I2C/I3C, SPI, PCIe, SMBus, device trees, U-Boot, Linux

  • Own the BMC security posture: secure and measured boot, root of trust, attestation (SPDM), authenticated update (PLDM FW Update), rollback protection, attack-surface reduction

  • Lead threat modeling and secure design reviews; run coordinated vulnerability: disclosure with vendors and the upstream community

What they're looking for

  • + years of experience in systems security, with at least 5 years focused on: firmware and hardware security (firmware, bootloaders, and OS-level security)
  • Hardware roots of trust and attestation: Caliptra, OCP S.A.F.E., TPM/HRoT, SPDM
  • Memory-safe systems code in Rust or Zig
  • Firmware vulnerability research, reverse-engineering, or fuzzing
  • Previous work with AI/ML infrastructure security