The opportunity
Anthropic sits at the frontier of AI development, which makes us one of the most interesting targets in the world for nation-state and advanced criminal actors. The Threat Intelligence function within our Detection & Response team exists to make sure we see them coming.
What you'll do
Research, track, and report on threat actors and campaigns targeting AI labs,: cloud infrastructure, and the broader technology sector — producing timely, actionable intelligence for Security Engineering stakeholders
Build and maintain tooling and automated pipelines to collect, enrich,: correlate, and operationalize indicators of compromise into our detection and alerting stack
Develop and execute intelligence-driven threat hunts across endpoint, cloud,: identity, and SaaS telemetry, and turn findings into durable detections
Perform technical analysis of malware, phishing infrastructure, and attacker: tooling to extract indicators, TTPs, and attribution signals
Partner with Detection Engineering and Incident Response to translate: intelligence into detection rules, hunting hypotheses, and incident context in near-real-time
Curate and triage inbound intelligence from commercial feeds, open source,: government, and trusted peer relationships — prioritizing what matters for Anthropic's threat model
What they're looking for
- Contribute to threat models and risk assessments that inform security: architecture and defensive investment across the enterprise
- Build and maintain external intelligence-sharing relationships with peer: companies, ISACs, and government partners
- Have 5+ years of hands-on experience in cyber threat intelligence, threat: hunting, or intrusion analysis at an organization facing sophisticated adversaries
- Have deep, demonstrable knowledge of specific nation-state or advanced: criminal threat actors — their tooling, infrastructure patterns, tradecraft, and targeting