At a Glance
- Tasks: Lead the design and architecture for account security systems to protect users from compromise.
- Company: Join a mission-driven AI company focused on safety and societal benefit.
- Benefits: Competitive salary, flexible hours, generous leave, and equity donation matching.
- Other info: Collaborative environment with opportunities for professional growth and mentorship.
- Why this job: Make a real impact in AI safety while tackling complex security challenges.
- Qualifications: 10+ years in security systems with strong coding skills in Python and SQL.
About the company
The company’s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems.
About the role
The company's Safeguards organization builds the systems that keep Claude safe to use at scale. The Account Compromise team owns one specific slice of that work: protecting the people and organizations who use Claude from losing control of their accounts, and preventing compromised accounts and credentials from being used to abuse our platform. Account takeover, credential stuffing, phishing-driven session theft, leaked API keys, and resold access all cause real harm — to the customers whose accounts are hijacked, and to the wider ecosystem when stolen access is used to route abusive traffic through legitimate accounts.
We are looking for a staff+ engineer to set the technical direction for this work. You will own the architecture of how we detect, contain, and remediate account compromise across Claude and the Claude Developer Platform, making the design decisions that other engineers and teams build on top of. You will move between deep technical work and adversarial problem-solving: threat modelling how attackers will adapt, scoping multi-month projects from ambiguous starting points, and leading complex live investigations when they escalate.
This is a hard problem space. Attackers iterate quickly, the signals separating a compromised account from an unusual but legitimate one are subtle, and every defence carries a cost to real users if it fires incorrectly. You will be building the playbook, and the judgement calls about where to draw those lines will largely be yours to make and defend.
You will operate with high autonomy — owning detection coverage and incident leadership, driving alignment with Security, Product, and Policy teams, and shaping how the company approaches this problem globally rather than executing against someone else's roadmap.
Key responsibilities
- Set the technical direction and own the architecture for account compromise detection, response, and remediation across Claude and the Claude Developer Platform.
- Independently scope and lead complex, multi-month engineering projects from an ambiguous starting point through to production systems that operate reliably under adversarial pressure.
- Build and evolve detection systems that identify account takeover, credential abuse, and compromised API keys in near real time.
- Design automated response flows that cut off attacker access while minimising disruption to legitimate users.
- Lead investigations into significant compromise incidents end to end, then convert what you learn into durable, automated defences.
- Threat model how attackers are likely to adapt, and prioritise the team's work against that view rather than only against incidents already observed.
- Drive cross-organisational alignment on account security direction with Security, Product, Support, Policy and other partners.
- Define how the team measures success and hold the work to those measures.
- Set technical standards for the domain and raise the bar for other engineers through code review, design review, and mentorship.
- Surface patterns from compromise cases to research and product teams so that protections improve upstream.
Minimum qualifications
- 10+ years experience designing, building, and operating detection, anti-fraud, anti-abuse, or security systems in production.
- A track record of independently scoping and delivering complex, ambiguous, multi-month technical projects.
- Experience making architectural decisions in an adversarial domain that other engineers and teams then build on.
- Proficiency in Python and SQL, with strong software engineering fundamentals and hands-on coding ability.
- Experience leading investigations into account-based abuse or security incidents, and translating findings into automated detection.
- Ability to reason rigorously about large behavioural or telemetry datasets, and to distinguish attacker behaviour from unusual but legitimate use.
- Strong written communication and a track record of driving alignment across multiple teams and stakeholders.
- Sound judgement about the tradeoff between stopping bad actors and disrupting legitimate users, and the ability to explain and defend where you have drawn that line.
Preferred qualifications
- Significant engineering experience in trust and safety, platform integrity, fraud, or detection and response, including time as a technical lead or mentor.
- Deep familiarity with account attack techniques.
- Experience with authentication and identity systems, including OAuth, single sign-on, multi-factor authentication, device binding, and risk-based authentication.
- Experience applying machine learning to fraud or abuse detection, alongside a clear sense of when simpler rules-based approaches are the better choice.
- Experience with cloud data tooling such as BigQuery, Spark, dbt, Airflow or similar.
- Experience building tooling for operational or investigative teams, and partnering closely with the people who use it.
- Interest in AI safety, and in the specific ways account compromise intersects with model misuse.
Representative projects
- Design the architecture for real-time login risk scoring, and get agreement across Security, Product, and Safeguards on where step-up authentication should and should not fire.
- Design detection for compromised API keys, together with security controls to limit exposure.
- Rebuild product features to regain access quickly when customers get compromised.
- Write the threat model that sets the team's roadmap for the next year, and bring the rest of the organisation along with it.
- Instrument a false positive review loop that measures how often the team’s defences affect legitimate users, and drive that number down.
The annual compensation range for this role is listed below. For sales roles, the range provided is the role’s On Target Earnings ("OTE") range, meaning that the range includes both the sales commissions/sales bonuses target and annual base salary for the role.
Annual Salary: £325,000 - £390,000 GBP
Logistics
- Minimum education: Bachelor’s degree or an equivalent combination of education, training, and/or experience.
- Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience.
- Minimum years of experience: Years of experience required will correlate with the internal job level requirements for the position.
- Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices.
- Visa sponsorship: We do sponsor visas! However, we aren’t able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this.
We encourage you to apply even if you do not believe you meet every single qualification. Not all strong candidates will meet every single qualification as listed. Research shows that people who identify as being from underrepresented groups are more prone to experiencing imposter syndrome and doubting the strength of their candidacy, so we urge you not to exclude yourself prematurely and to submit an application if you’re interested in this work. We think AI systems like the ones we’re building have enormous social and ethical implications. We think this makes representation even more important, and we strive to include a range of diverse perspectives on our team.
Your safety matters to us. To protect yourself from potential scams, remember that the company recruiters only contact you from @the company.com email addresses. In some cases, we may partner with vetted recruiting agencies who will identify themselves as working on behalf of the company. Be cautious of emails from other domains. Legitimate the company recruiters will never ask for money, fees, or banking information before your first day. If you’re ever unsure about a communication, don’t click any links—visit the company.com/careers directly for confirmed position openings.
How we’re different
We believe that the highest-impact AI research will be big science. At the company we work as a single cohesive team on just a few large-scale research efforts. And we value impact — advancing our long-term goals of steerable, trustworthy AI — rather than work on smaller and more specific puzzles. We view AI research as an empirical science, which has as much in common with physics and biology as with traditional efforts in computer science. We’re an extremely collaborative group, and we host frequent research discussions to ensure that we are pursuing the highest-impact work at any given time. As such, we greatly value communication skills.
The easiest way to understand our research directions is to read our recent research. This research continues many of the directions our team worked on prior to the company, including: GPT-3, Circuit-Based Interpretability, Multimodal Neurons, Scaling Laws, AI & Compute, Concrete Problems in AI Safety, and Learning from Human Preferences.
Come work with us! The company is a public benefit corporation headquartered in San Francisco. We offer competitive compensation and benefits, optional equity donation matching, generous vacation and parental leave, flexible working hours, and a lovely office space in which to collaborate with colleagues.
Staff+ Software Engineer, Account Compromise employer: United States Digital Space LLC
United States Digital Space LLC is an exceptional employer, offering a dynamic work culture that prioritises innovation and collaboration in the heart of Greater London. With a strong focus on employee well-being and flexible work options, we provide ample opportunities for professional growth and development, making it an ideal environment for those looking to make a meaningful impact in the field of AI-enabled SaaS engineering.
Contact Details:
United States Digital Space LLC Recruitment Team
StudySmarter Expert Advice🤫
We think this is how you could land Staff+ Software Engineer, Account Compromise
✨Join Local Tech Meetups
Get out there and mingle with fellow developers by joining local tech meetups. It’s a fantastic way to meet people who might be working at United States Digital Space LLC or know someone who does. Plus, you can pick up some trendy tech skills and trends while you're at it!
✨Contribute to Open Source Projects
Show off your coding chops by jumping into open-source projects. Not only does this give you practical experience, but it also gets you noticed in the dev community. You'll create a killer portfolio that speaks volumes about your skills to United States Digital Space LLC.
✨Tap into Online Developer Communities
Don’t underestimate the power of online developer communities like GitHub, Stack Overflow, and even Reddit. Participate in discussions, share your projects, and build your visibility. We can often find opportunities through these channels that can lead to a full-time gig at companies like United States Digital Space LLC.
✨Explore Job Boards Specifically for Tech Roles
Keep your eyes peeled on job boards that focus on tech roles. Sites like TechCareers or Stack Overflow Jobs can often have listings for companies like United States Digital Space LLC that might not show up on broader job sites. Make it a habit to check these regularly, and don’t hesitate to apply directly through our website!
We think you need these skills to ace Staff+ Software Engineer, Account Compromise
Some tips for your application 🫡
Show off your coding skills:When applying for a software engineering role, it's super important to showcase your coding skills. Make sure your CV includes your tech stack, any relevant programming languages you’re comfortable with, and examples of projects you've worked on. If you have a GitHub profile, link it up! We love to see code in action.
Tailor your portfolio:For a full-time role, we’d expect to see some solid examples of your work in your portfolio. Make sure to include at least two or three projects that highlight your problem-solving skills and your ability to work with different technologies. Focus on the projects that are most relevant to the position at United States Digital Space LLC.
Craft a killer cover letter:Your cover letter is your chance to stand out—make it personal! Explain why you want to work at United States Digital Space LLC and how your skills align with the role. Show us your passion for software development. We dig enthusiastic candidates who understand the value of collaboration and continuous learning!
Be clear and concise:When it comes to writing your CV and cover letter, clarity is key. Avoid jargon that could confuse us and stick to simple, direct language. Highlight your achievements with quantifiable results where possible, and keep everything easy to read. A well-organised application goes a long way!
How to prepare for a job interview at United States Digital Space LLC
✨Brush Up on Your Coding Skills
For a full-time software engineering role, it's crucial that we stay sharp with our coding abilities. Expect technical questions that might involve solving problems on the spot or discussing algorithms. Practise on platforms like LeetCode or HackerRank to get comfortable with the types of questions that often come up.
✨Know Your Tools and Frameworks
Make sure we’re well-acquainted with the tools and technologies listed in the job description. Familiarise ourselves with any specific frameworks or programming languages mentioned. If United States Digital Space LLC uses React or Node.js, for instance, be ready to discuss how we’ve used them in previous projects or coursework.
✨Showcase Your Projects
Bring along a portfolio that highlights our best work. This could be code samples, GitHub repositories, or any side projects we’ve built. Make sure we can talk through our thought process for each project, especially the challenges we faced and how we solved them—this shows our problem-solving skills in action.
✨Prepare for Behavioural Questions
While technical skills are key, full-time positions also require cultural fit. Be ready to discuss our previous experiences and how we handle teamwork, conflict, and deadlines. Brush up on the STAR method—Situation, Task, Action, Result—to clearly articulate our past experiences when discussing how we've contributed to a team.