Anthropic12 дней назад

Инженер по безопасности платформы, DRTM / Secure Launch

26 667–33 750 ₽в месяц · до вычета
РЫНОК
16 167медиана по профессии
Data Scientist · 183 вакансий с указанной зарплатой
5 000половина предложений: 13 167–22 083120 000
Выше рынка · выше 90% предложений
San Francisco

Обязанности

  • 01Own adoption and integration of DRTM hardware security features across Anthropic infrastructure, on both x86 and ARM platforms
  • 02Implement attestation services and the additional security and privacy capabilities that DRTM presence enables
  • 03Design and implement a bootloader-agnostic solution for initiating and relaunching DRTM sessions
  • 04Investigate further hardening of existing DRTM solutions: PPAM to isolate SMM on x86, VMM features to isolate UEFI runtime services, ACPI handling and hardening in DRTM environments
  • 05Interface with vendor and OEM partners on their DRTM solutions: refine requirements jointly and determine which changes are desirable and feasible
  • 06Publish relevant DRTM work upstream and help carry Linux Secure Launch maintainership as tboot is retired
  • 07Act as technical lead in architecture and design, and disseminate the work through technical papers, conference talks, and community engagement
  • 08Assist other Anthropic teams with their own open source efforts and upstream interactions
  • 09Build and harden other platform security features, including confidential computing solutions such as TDX and SEV
  • 10Support custom operating system artifacts, implement device drivers for custom hardware and features, and do firmware diagnosis and enhancement work
  • 11Debug and diagnose kernel and system-level issues on production hardware
  • 12Take on investigative work in new technical areas and old unsolved ones (for example, the distinct security problems in dTPMs and fTPMs)

Требования

  • 01Deep hands-on experience with measured boot and roots of trust: DRTM (Intel TXT, AMD SKINIT, ARM equivalents), SRTM, TPM 1.2/2.0, and the measurement chains built on them
  • 02Strong C and assembly, with deep Linux kernel and early-boot fundamentals (bootloaders, UEFI, ACPI, SMM)
  • 03A record of landing non-trivial work upstream in Linux, TianoCore, GRUB, or a comparable community
  • 04Comfort at the hardware/firmware boundary and with the debugging that comes with it: JTAG, serial, platform-level bring-up, silicon errata
  • 05Strong technical cross-functional leadership and direction setting, including with external vendors and OEMs
  • 06Clear written communication: this role produces specifications, design docs, and public technical writing
  • 07Working knowledge of NIST firmware security guidance, particularly SP 800-193 and 800-147/155
  • 08Minimum education: Bachelor’s degree or an equivalent combination of education, training, and/or experience
  • 09Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience
  • 10Minimum years of experience: Years of experience required will correlate with the internal job level requirements for the position

Условия

  • 01Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time
  • 02Visa sponsorship: We do sponsor visas! However, we aren't able to successfully sponsor visas for every role and every candidate