Staff+ Application Security Engineer

USD 320,000-485,000 per year
SENIOR
✅ Hybrid
✅ Visa Sponsorship

Tech Stack

AI Communication @ 6 Go @ 4 LLM @ 4 Leadership @ 6 Python @ 4 Rust @ 4 Security @ 6 TypeScript @ 4

Details

Anthropic’s Application Security team secures the systems that build, serve, and increasingly are Claude. The role focuses on novel application security challenges involving multi-agent orchestration, sandboxed code execution, delegated credentials, and untrusted tool output crossing trust boundaries. The team uses Claude for static analysis, vulnerability remediation, bug bounty triage, and threat modeling, while engineers provide system-level judgment and build new security capabilities.

Responsibilities

  • Design, build, and operate Claude-powered security systems, including LLM-driven code analysis, automated vulnerability remediation, and AI-assisted threat modeling.
  • Own one or more security systems end-to-end, including related cross-functional relationships.
  • Lead secure design reviews and threat modeling for novel AI systems, identifying risks that do not map to existing frameworks.
  • Evolve a public bug bounty program where automation handles routine triage and root-cause work, while engineers handle escalations and corner cases.
  • Partner with Product, Infrastructure, and Research teams as an embedded security owner, consulting on launches, shaping architecture, and influencing security-related decisions.
  • Participate in an operational on-call rotation covering bounty escalations, incident response, and launch consultations for systems serving Claude in production.

Requirements

Minimum Qualifications

  • Hands-on application and infrastructure security experience, including cloud and containerized environments.
  • Production-quality coding ability in at least one of Python, Go, Rust, or TypeScript, with experience building durable systems rather than one-off scripts.
  • Practical threat-modeling and vulnerability-identification skills, including experience finding and reasoning about real bugs in real systems.
  • Ability to operate with high autonomy and ambiguity.
  • Clear technical communication with engineers and leadership.

Preferred Qualifications

  • 7+ years of experience in application security, security engineering, or security-focused software engineering.
  • Experience using LLMs as a core part of professional work.
  • Experience securing agentic, code-execution, or LLM-integrated systems.
  • Prior ownership of a bug bounty program, vulnerability disclosure program, or vulnerability-management infrastructure at scale.
  • Experience building security automation or developer-facing security tooling.
  • Offensive security or penetration-testing experience.

Representative Projects

  • An autonomous vulnerability pipeline in which LLM-driven code analysis identifies issues, scores real exploitability, and opens fix pull requests.
  • Bug bounty operations where Claude handles first-line triage and drafting while engineers focus on reports requiring judgment.
  • AI-assisted threat modeling that generates intake questions, drafts models, and recommends which design reviews require human participation.
  • Automated dependency vulnerability remediation across Anthropic’s codebase.
  • A company-wide vulnerability dashboard and SLA enforcement layer.
  • Threat models and security architecture for agentic product surfaces, including code-execution sandboxing, agent identity and delegated authentication, and tool-use boundaries.

A bachelor’s degree or an equivalent combination of education, training, and experience is required. The field of study should be relevant to the role through coursework, training, or professional experience. Required years of experience correlate with the internal job level requirements.

Benefits

Anthropic offers competitive compensation and benefits, optional equity donation matching, generous vacation and parental leave, flexible working hours, and office space for collaboration. Anthropic sponsors visas and makes reasonable efforts to obtain a visa for successful candidates, with support from an immigration lawyer.

The location-based hybrid policy expects staff to be in one of the company’s offices at least 25% of the time, although some roles may require more office attendance.

More jobs at Anthropic

Similar jobs