> Markdown version of [/jobs/ext/2723117-security-engineer-corporate-security](https://www.wearedevelopers.com/jobs/ext/2723117-security-engineer-corporate-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer, Corporate Security - **Company:** Anthropic's Mission - **Location:** New York, United States - **Experience:** Expert - **Salary:** $320,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Artificial Intelligence, Apple Mac Systems, Chrome OS, Software as a Service, Cloud Computing Security, Continuous Integration, Linux, Identity and Access Management, Python (Programming Language), OAuth, Zero Trust Network Access, Mobile Security, Systems Integration, Scripting, Large Language Models, Software Security - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/security-engineer-corporate-security-anthropic-3-9617374 ## About the Role * Hands-on endpoint security engineering on macOS, Windows, Linux, or ChromeOS, such as MDM and declarative device management profile engineering, application allowlisting or binary authorization, system extensions and endpoint security frameworks, or their platform equivalents * Proficiency in Python and scripting languages generally; you architect and build integrations, automation, and internal tooling as a normal part of the job, and can write a detection when the work calls for it * Working depth in identity and access management, SaaS security, and zero-trust access * Threat-modeling judgment that finds the problems worth solving and the ability to scope them, define "done," and drive them to completion * Care for Anthropic's mission and the part corporate security plays in it, * Experience defining the scope and choosing the tooling for a security program rather than inheriting it * Experience shipping an enforcement change to a large user population: using data to find what will break before it does, staging the rollout, building the alternative path for affected workflows, and moving people onto it ahead of enforcement * Endpoint depth across more than one of macOS, Windows, Linux, and ChromeOS, with the judgment to harden for the threats that matter rather than to a checklist * Mobile security across managed and BYOD contexts, including protecting people and devices in higher-risk settings such as international travel * Experience bringing security governance to a modern SaaS environment, including third-party integrations, delegated access, and the long tail of internally built and AI-generated apps, in a way that speeds decisions up rather than slowing them down * Configuration-as-code, infrastructure-as-code, and CI/CD applied to corporate infrastructure * LLM-assisted security tooling you built that materially changed what a team could cover, and the judgment to know which work to hand to a model, which to keep, and how to combine the two * A track record of getting security controls adopted across an organization through influence and partnership rather than authority, Minimum education: Bachelor's degree or an equivalent combination of education, training, and/or experience Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience Minimum years of experience: Years of experience required will correlate with the internal job level requirements for the position Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices. ## Description Corporate Security protects the environment Anthropic's people work in every day: their laptops and phones, their identities, the tools they collaborate in and the company data that flows through all of it. Everything that makes Claude what it is sits behind that environment. We keep company access on devices we manage, make those devices hard to compromise and right-size what any one of them can reach, while caring a great deal about the day-to-day experience of the people using them. The company is growing quickly and this team is growing with it, so we treat the work as an engineering discipline: controls as code and automation over queues, built to scale with headcount rather than strain against it., As a Security Engineer here you'll drive significant parts of that work end to end. You'll set technical direction and turn it into shipped tooling. When a control collides with someone's workflow, you'll find the path that keeps them moving without giving up the protection. You'll be handed problems rather than task lists and you'll find as many yourself: threat-modeling the environment to surface what matters, fixing it and bringing the evidence that shapes what the team prioritizes next. This is a senior, hands-on individual contributor role., * Drive endpoint hardening across macOS, Windows, Linux, and ChromeOS, including device management configuration, application allowlisting, patching, and browser policy, favoring controls that are versioned, reviewable, and repeatable over one-off configuration * Extend device-trust and zero-trust access controls so company systems are reached from managed devices bound to the right person and carrying the right level of access, treating the experience of fellow employees as a design constraint rather than an afterthought * Build the automation and integrations that let the team scale with the company: joiner/mover/leaver automation across identity and device management, exception and expiry workflows, posture-driven policy, and Claude-assisted triage of review queues * Lead SaaS and identity governance, including third-party OAuth grants, delegated admin access, chat-platform apps, browser extensions, and software security reviews, turning recurring decisions into policy and tooling * Partner across the wider Security team, IT, and Engineering on telemetry, detections, and shared standards, and help define how a company that increasingly runs on AI agents does so securely and at scale ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)