<?xml version="1.0" encoding="UTF-8"?>
<source>
  <jobs>
    <job>
      <externalid>b7d5aa44-517</externalid>
      <Title>Member of Product, Security</Title>
      <Description><![CDATA[<p>At Anchorage Digital, we are building the world&#39;s most advanced digital asset platform for institutions to participate in crypto. As our first Security Product Manager, you will own the product strategy and execution that strengthens our defense-in-depth architecture and operational controls across custody, wallets, authorization, policy, and risk systems.</p>
<p>You&#39;ll partner with Security, Platform, Core Experience, Protocols, and Compliance to ship secure-by-default capabilities that meet bank-grade and auditor expectations while preserving developer velocity and client experience. You will define and own the roadmap for security platform capabilities across cloud defense, secrets management, HSM-bound workflows, and secure-by-default developer tooling.</p>
<p>You&#39;ll translate regulatory, audit, and risk requirements into usable product surfaces and guardrails for internal teams and client-facing flows. You will also establish crisp product requirements, success metrics, and post-ship control evidence so Security, Risk, and Audit can verify effectiveness without slowing teams.</p>
<p>We have created the Factors of Growth &amp; Impact to help Villagers better measure impact and articulate coaching, feedback, and the rich and rewarding learning that happens while exploring, developing, and mastering the capabilities and contributions within and outside of the Security Product Manager role:</p>
<p><strong>Technical Skills:</strong></p>
<ul>
<li>Work closely with the security engineering team on the detail prioritization of the security product roadmap, balancing new capability development with technical debt retirement to ensure long-term platform health.</li>
<li>Demonstrate deep strategic thinking in shaping the roadmap, considering threat landscape, regulatory requirements, competitive positioning, and customer needs to drive long-term security product success.</li>
<li>Deliver complex, cross-functional security projects with multiple dependencies (Security Engineering, Platform, Core Experience, Compliance), demonstrating strong product management skills and ability to drive swift execution while maintaining quality.</li>
<li>Drive comprehensive go-to-market strategy for security capabilities, including defining success metrics, tracking KPIs, and iterating based on data-driven insights.</li>
</ul>
<p><strong>Complexity and Impact of Work:</strong></p>
<ul>
<li>Contribute strategic insights that significantly impact company direction, control coverage, and the security roadmap.</li>
<li>Demonstrate product leadership that elevates team performance and effectiveness across security and platform domains.</li>
</ul>
<p><strong>Organizational Knowledge:</strong></p>
<ul>
<li>Develop deep understanding of Anchorage&#39;s business model, organizational structure, regulatory posture, and strategic priorities.</li>
<li>Build and maintain strong relationships with stakeholders across Security, Engineering, Compliance, Risk, and Ops to ensure effective collaboration.</li>
<li>Navigate and improve organizational processes to enhance efficiency, safety, and auditability across teams.</li>
<li>Contribute to organizational strategy through security product expertise, control design insights, and market intelligence.</li>
<li>Drive company objectives through strategic security product decisions and initiatives.</li>
</ul>
<p><strong>Communication and Influence:</strong></p>
<ul>
<li>Effectively influence and motivate others through respectful engagement, aligning teams with broader organizational security and product goals.</li>
<li>Enable cross-functional collaboration through clear, consistent communication and strategic influence on decision-making at every level of the organization.</li>
<li>Communicate clearly with executives, auditors, and prospective customers on control intent, coverage, evidence, and roadmap tradeoffs.</li>
<li>Act as a thoughtful knowledge partner to senior leadership, helping improve organizational security dynamics through empathetic understanding.</li>
</ul>
<p><strong>You may be a fit for this role if you have:</strong></p>
<ul>
<li>6+ years in product management with 3+ focused on platform or security products in regulated or high-assurance environments.</li>
<li>Strong technical fluency in one or more: cryptographic primitives, authN/Z, HSMs and key management, secrets management, secure software delivery, runtime isolation, threat modeling.</li>
<li>Proven record shipping platform controls that are both developer-friendly and audit-ready.</li>
<li>Experience converting regulatory or control frameworks (e.g., SOC 2, FFIEC, OCC expectations, ISO 27001) into practical product requirements.</li>
<li>Comfortable operating across deeply technical teams and non-technical stakeholders (Security, Compliance, Risk, Ops, Client Success).</li>
<li>Excellent written and verbal communication skills, adept at conveying complex security concepts clearly to diverse audiences.</li>
<li>Experience in driving and managing complex projects across multiple teams, demonstrating exceptional leadership and problem-solving skills.</li>
<li>Your empathy and adaptability not only complement others&#39; working styles but also embody our culture of curiosity, creativity, and shared understanding.</li>
<li>You self describe as some combination of the following: creative, humble, ambitious, detail oriented, hard working, trustworthy, eager to learn, methodical, action oriented, and tenacious.</li>
</ul>
<p><strong>Although not a requirement, bonus points if:</strong></p>
<ul>
<li>Experience in digital assets or financial infrastructure.</li>
<li>Hands-on experience with hardware signing flows, policy engines, or secure enclave/HSM integrations.</li>
<li>Built systems for straight-through-processing with pre-authorization risk decisions.</li>
<li>Familiarity with incident response and detection engineering product needs.</li>
<li>You have written your own smart contract or dApp.</li>
<li>You have built 0 to 1 products for financial institutions either as a PM or a developer.</li>
</ul>
<p><strong>Additional Information About Anchorage Digital:</strong></p>
<p>Who we are The Anchorage Village, what we call our team, brings together the brightest minds from platform security, financial services, and distributed ledger technology.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>remote</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>cryptographic primitives, authN/Z, HSMs and key management, secrets management, secure software delivery, runtime isolation, threat modeling</Skills>
      <Category>Engineering</Category>
      <Industry>Finance</Industry>
      <Employername>Anchorage Digital</Employername>
      <Employerlogo>https://logos.yubhub.co/anchorage.com.png</Employerlogo>
      <Employerdescription>Anchorage Digital is a crypto platform that enables institutions to participate in digital assets through custody, staking, trading, governance, settlement, and the industry&apos;s leading security infrastructure.</Employerdescription>
      <Employerwebsite>https://anchorage.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://jobs.lever.co/anchorage/43703182-aa1f-4db4-a13a-1e890ae2fae9</Applyto>
      <Location>United States</Location>
      <Country></Country>
      <Postedate>2026-04-17</Postedate>
    </job>
    <job>
      <externalid>a560bd4c-a1a</externalid>
      <Title>Cloud Security Engineer</Title>
      <Description><![CDATA[<p>We&#39;re looking for a Cloud Security Engineer to join our team. As a Cloud Security Engineer at Starling, you&#39;ll be building and supporting tooling and infrastructure that spans across AWS and GCP supporting our internal operations and interfacing with other teams to deliver the services that support our business.</p>
<p>Key Responsibilities:</p>
<ul>
<li>Engineer Secure Foundations: You will lead the design and implementation of critical security services, with a heavy focus on building robust Identity and Access Management (IAM) systems and automated, API-driven certificate management workflows.</li>
<li>Security-as-Code &amp; Scalability: Leveraging a software-first philosophy, you will develop and maintain high-quality, scalable security tooling and middleware within ECS and Kubernetes environments, ensuring security logic is integrated directly into the deployment pipeline.</li>
<li>Collaborative Code Ownership: You will serve as a technical authority in cross-functional code reviews, acting as an engineering peer who helps teams bake security into their services from the first line of code to the final pull request.</li>
<li>Proactive System Hardening: You will stay ahead of the evolving threat landscape by treating security as a continuous engineering challenge,proactively identifying vulnerabilities and architecting technical solutions to fortify our global ecosystem.</li>
</ul>
<p>Professional Requirements:</p>
<ul>
<li>Demonstrated ability to architect secure, distributed systems with a focus on programmatic IAM and automated, API-driven PKI management.</li>
<li>Extensive experience with Infrastructure as Code (IaC) in Terraform and a deep commitment to writing clean, maintainable, and production-grade code,ideally in Golang.</li>
<li>A test-first mentality toward security, with experience building unit and integration tests into CI/CD pipelines to ensure that security guardrails are as reliable as the features they protect.</li>
<li>A strong conceptual grasp of cryptographic primitives and hands-on experience securing containerized workloads and service meshes within ECS and Kubernetes.</li>
<li>A track record of taking end-to-end ownership of complex technical projects, from initial design docs and RFCs through to deployment and observability.</li>
<li>A belief that if it isn&#39;t tested, it&#39;s broken, and a drive to proactively identify and fix vulnerabilities by treating security as a continuous engineering challenge.</li>
</ul>
<p>Our Team Philosophy:
The Security Engineering team is a diverse and dynamic group passionate about building secure and resilient systems. We&#39;re enthusiastic about security, but we&#39;re not about rigid, one-size-fits-all controls. We believe in striking a balance between protecting our systems and empowering our developers to build and innovate.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>Cloud Security, AWS, GCP, Identity and Access Management, API-driven Certificate Management, Infrastructure as Code, Terraform, Golang, Cryptographic Primitives, Containerized Workloads, Service Meshes</Skills>
      <Category>Engineering</Category>
      <Industry>Finance</Industry>
      <Employername>Starling</Employername>
      <Employerlogo>https://logos.yubhub.co/starlingbank.com.png</Employerlogo>
      <Employerdescription>Starling is a fully licensed UK bank with over 3,000 employees across four offices.</Employerdescription>
      <Employerwebsite>https://www.starlingbank.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://apply.workable.com/j/3B7E26FC24</Applyto>
      <Location>London</Location>
      <Country></Country>
      <Postedate>2026-03-20</Postedate>
    </job>
    <job>
      <externalid>41528416-21c</externalid>
      <Title>Staff+ Software Security Engineer</Title>
      <Description><![CDATA[<p><strong>About Anthropic</strong></p>
<p>Anthropic&#39;s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems.</p>
<p><strong>About the Team</strong></p>
<p>The Security Engineering team protects Anthropic&#39;s AI systems and maintains the trust of our users and society. We define the authentication architecture for our training infrastructure, design the cryptographic foundations that protect model weights and training data, and drive the developer security program that shapes how engineers build and ship software.</p>
<p><strong>About the role:</strong></p>
<ul>
<li>Scope, design, and build complex security systems end to end, maintaining them through production and driving through ambiguous technical challenges with minimal oversight</li>
<li>Identify systematic risks through threat modeling and risk assessment, then build the controls and infrastructure that address them</li>
<li>Mentor engineers across the security team and broader engineering organisation, contribute to hiring, and grow security engineering culture at Anthropic</li>
<li>Enable other teams to build their own security solutions by providing design pattern guidance and expanding security ownership beyond the security team</li>
</ul>
<p><strong>Developer security and supply chain</strong></p>
<ul>
<li>Build and advance our developer security program by embedding security practices into the software development lifecycle and developer workflows</li>
<li>Harden CI/CD pipelines against supply chain attacks through isolated build environments, signed attestations, dependency verification, and automated policy enforcement</li>
</ul>
<p><strong>Identity and secrets management</strong></p>
<ul>
<li>Architect systems that protect sensitive assets including model weights, customer data, and training datasets</li>
<li>Build and operate credential issuance, rotation, and workload authentication across our multi-cloud environments</li>
</ul>
<p><strong>Infrastructure security</strong></p>
<ul>
<li>Implement and maintain cloud security controls including IAM, network segmentation, VPC architecture, and encryption across our multi-cloud and on-prem environments</li>
<li>Contribute to cluster security controls including RBAC policies, namespace isolation, workload identity, and pod security</li>
<li>Contribute to continuous cloud security posture management using infrastructure-as-code scanning, misconfiguration detection, and automated remediation</li>
</ul>
<p><strong>Secure frameworks</strong></p>
<ul>
<li>Build critical security foundations including cryptographic frameworks, mTLS infrastructure, secure serialization, and authorization systems, designed to prevent entire classes of vulnerabilities and empower engineering teams to work securely without becoming security experts themselves</li>
<li>Partner with product, research, infrastructure, and other security teams to ensure frameworks integrate smoothly with lower-layer security controls</li>
</ul>
<p><strong>You may be a good fit if you have:</strong></p>
<ul>
<li>At least 8 years of software engineering experience with deep security expertise, including leading complex security initiatives independently</li>
<li>Bachelor&#39;s degree in Computer Science or equivalent industry experience</li>
<li>Strong programming skills in Python or at least one systems language such as Go, Rust, or C/C++</li>
<li>Deep understanding of identity systems, cryptographic primitives, and secrets management</li>
<li>Working knowledge of Kubernetes security primitives including RBAC, namespaces, network policies, and service accounts</li>
<li>Experience leading cross-functional security initiatives and navigating complex organisational dynamics</li>
<li>Outstanding communication skills, translating technical concepts effectively across all levels of the organisation</li>
<li>A track record of bringing clarity and ownership to ambiguous technical problems and driving them to resolution</li>
<li>Low ego and high empathy, with a history of growing the engineers around you and supporting diverse, inclusive teams</li>
<li>Passion for AI safety and the role security engineering plays in building trustworthy AI systems</li>
</ul>
<p><strong>Strong candidates may also have:</strong></p>
<ul>
<li>Designed or operated identity and secrets management systems for large-scale AI or cloud infrastructure</li>
<li>Built security frameworks or libraries adopted across an engineering organisation</li>
<li>Led a developer security program including supply chain security, secure build infrastructure, and SDLC integrations</li>
<li>Built or secured CI infrastructure using Nix, Bazel, or Kubernetes-based deploy systems, with depth in toolchain issues, CI/CD pipelines, and developer workflow optimisation</li>
<li>Implemented machine identity or workload authentication systems using SPIFFE/SPIRE, mTLS, or equivalent</li>
<li>Understanding of Linux systems internals including namespaces, cgroups, and seccomp, and how these underpin container and workload isolation</li>
<li>Contributed to the security architecture of multi-cloud environments including network segmentation, data protection, and access governance</li>
<li>Experience with network security controls including admission controllers, CNI-level policy, service mesh security, and east-west traffic enforcement</li>
<li>Experience building runtime security monitoring using eBPF or kernel security policies</li>
</ul>
<p><strong>Deadline to apply:</strong></p>
<p>None, applications will be received on a rolling basis.</p>
<p><strong>The annual compensation range for this role is listed below.</strong></p>
<p>For sales roles, the range provided is the role’s On Target Earnings (&quot;OTE&quot;) range, meaning the total amount of money an employee is expected to earn in a year, including bonuses and other forms of compensation.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>staff</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange>The annual compensation range for this role is listed below.

For sales roles, the range provided is the role’s On Target Earnings (&quot;OTE&quot;) range, meaning the total amount of money an employee is expected to earn in a year, including bonuses and other forms of compensation.</Salaryrange>
      <Skills>Python, Go, Rust, C/C++, Kubernetes, RBAC, namespaces, network policies, service accounts, identity systems, cryptographic primitives, secrets management, Nix, Bazel, Kubernetes-based deploy systems, SPIFFE/SPIRE, mTLS, Linux systems internals, namespaces, cgroups, seccomp, container and workload isolation, multi-cloud environments, network segmentation, data protection, access governance, admission controllers, CNI-level policy, service mesh security, east-west traffic enforcement, runtime security monitoring, eBPF, kernel security policies</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Anthropic</Employername>
      <Employerlogo>https://logos.yubhub.co/anthropic.com.png</Employerlogo>
      <Employerdescription>Anthropic is a quickly growing organisation with a mission to create reliable, interpretable, and steerable AI systems. The company is working to build beneficial AI systems that are safe and beneficial for users and society as a whole.</Employerdescription>
      <Employerwebsite>https://job-boards.greenhouse.io</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/anthropic/jobs/5120512008</Applyto>
      <Location>San Francisco, CA | New York City, NY | Seattle, WA</Location>
      <Country></Country>
      <Postedate>2026-03-08</Postedate>
    </job>
  </jobs>
</source>