Anthropic

Platform Security Engineering - OpenBMC

Anthropic
Apply
3 months ago
Seattle, WA, USA +2 moreStaff+
H1B sponsor

Base Salary

$405k - $405k/yr

Responsibilities

  • Design, build, and ship OpenBMC firmware and manageability features for x86 and Arm platforms, including GPU platforms, using Yocto/OpenEmbedded.
  • Build management capabilities using MCTP, PLDM, SPDM, Redfish, RDE, IPMI, and KCS, including sensors, telemetry, inventory, logging, and RAS.
  • Implement BMC-to-BIOS/host communications and thermal, fan, and power management using eSPI/LPC and PMBus.
  • Work across I2C/I3C, SPI, PCIe, SMBus, device trees, U-Boot, and Linux at the hardware/firmware boundary.
  • Own the BMC security posture, including secure and measured boot, root of trust, SPDM attestation, PLDM firmware updates, rollback protection, and attack-surface reduction.
  • Lead threat modeling, secure design reviews, and coordinated vulnerability disclosure with vendors and the upstream community.
  • Build verification tooling for static analysis, fuzzing, firmware extraction, and CI gating.
  • Provide technical leadership and direction for the founding OpenBMC platform security engineering team.

Requirements

  • 8+ years of systems security experience, including at least 5 years focused on firmware and hardware security.
  • Hands-on OpenBMC/BMC firmware experience on x86 and/or Arm platforms from bring-up through production, including D-Bus/sdbusplus.
  • Strong C/C++ and Python skills, deep Linux user-space and kernel fundamentals, and proficiency with Yocto/OpenEmbedded.
  • Experience with firmware security, bootloaders, OS-level security, secure boot, signing, attestation, authenticated updates, and rollback protection.
  • Upstream contributions to OpenBMC, U-Boot, DMTF, or OCP.
  • Working knowledge of out-of-band and in-band management, relevant DMTF specifications, and the device interfaces they use.
  • Knowledge of NIST firmware security guidelines and hardware security frameworks, specifically SP 800-193 and SP 800-147/155.
  • Strong debugging skills and a track record of shipping reliable, well-tested code.
  • Strong technical cross-functional leadership, direction-setting, communication, and collaboration across hardware and software teams and external vendors.
  • Preferred experience with Caliptra, OCP S.A.F.E., TPM/HRoT, SPDM, Rust, Zig, firmware vulnerability research, reverse engineering, fuzzing, or AI/ML infrastructure security.
  • Bachelor’s degree or an equivalent combination of education, training, and/or experience in a relevant field demonstrated through coursework, training, or professional experience.

Benefits

  • Competitive compensation and benefits
  • Optional equity donation matching
  • Generous vacation and parental leave
  • Flexible working hours
  • Office space for collaboration
  • Hybrid policy requiring staff to be in an office at least 25% of the time
  • Visa sponsorship may be available
  • Rolling applications with no stated deadline
Anthropic

About Anthropic

5,001-10,000 employees

Anthropic builds large language models and the Claude AI assistant for developers and enterprises, offered via API access and enterprise plans. Founded in 2021 and headquartered in San Francisco, it distributes Claude through its own platform and via partners such as Amazon Bedrock and Google Cloud’s Vertex AI. Its work emphasizes model reliability, interpretability, and practical tooling for tasks like coding assistance, analysis, and customer support automation.

Contact me