An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Anthropic in the United Kingdom is seeking a Threat Intelligence Engineer to produce actionable intelligence for detections, hunts, and defensive priorities. You will track adversaries targeting frontier AI labs and build tooling to turn indicators into defenses.
You will work with Detection Engineering and Incident Response to translate intelligence into detections and durable defenses, shaping threat models and risk assessments across the enterprise.
Have experience authoring detection logic (YARA, Sigma, Snort/Suricata, or SIEM‑native queries) and understand what makes a detection durable vs. brittleHave 5+ years of hands‑on experience in cyber threat intelligence, threat hunting, or intrusion analysis at an organization facing sophisticated adversariesHave an existing network in the threat intelligence community and a track record of productive bidirectional sharingCan write clearly and concisively — your intelligence products are read and acted on, not filed awayAre a strong engineer: you write production‑quality Python (or similar), have built automation and data pipelines, and don’t need to hand requirements to someone else to get tooling builtAre comfortable performing malware analysis, infrastructure analysis (passive DNS, certificate pivoting, netflow), and log analysis to develop and validate your own findingsHave deep, demonstrable knowledge of specific nation‑state or advanced criminal threat actors — their tooling, infrastructure patterns, tradecraft, and targetingExperience defending cloud‑native and research‑heavy environments (AWS/GCP, Kubernetes, ML infrastructure, developer tooling and supply chain)Prior work operating in a threat intelligence role tracking sophisticated or state‑sponsored adversaries, where your analysis directly informed detection, threat hunting, and incident responseExperience applying LLMs or other AI tooling to accelerate intelligence collection, enrichment, and analysisPublic research, conference talks, or open‑source tooling contributions in the CTI spaceMinimum education: Bachelor’s degree or an equivalent combination of education, training, and/or experienceRequired field of study: A field relevant to the role as demonstrated through coursework, training, or professional experienceWe encourage you to apply even if you do not believe you meet every single qualification. Not all strong candidates will meet every single qualification as listedWe urge you not to exclude yourself prematurely and to submit an application if you’re interested in this work