Staff+ Application Security Engineer - M&A

USD 320,000-485,000 per year
SENIOR
✅ Remote ✅ Hybrid
✅ Visa Sponsorship

Tech Stack

AI Agentic Systems @ 4 Communication @ 6 Due Diligence @ 4 Go @ 6 LLM @ 4 Python @ 6 Rust @ 6 Security @ 4 TypeScript @ 6

Details

Anthropic's Application Security team secures the systems that build, serve, and increasingly are Claude. This role establishes the security function for companies and codebases acquired by Anthropic.

The role owns security due diligence and secure integration for acquisitions, including assessing a target's security posture before closing, preparing security risk readouts for leadership, and bringing acquired systems up to Anthropic's security standards after closing. It is an Application Security role first, with participation in the team's rituals, on-call rotation, tooling, and core AppSec projects. The role uses Claude as a primary tool and is expected to automate repeatable diligence and integration processes.

Responsibilities

  • Lead pre-close security due diligence for prospective acquisitions, including coordinating external penetration testing, threat modeling target architectures, assessing security controls, and delivering security risk readouts for leadership.
  • Drive post-close security integration by establishing static and dynamic analysis coverage, tracking high- and critical-severity remediation, incorporating acquired assets into bug bounty scope, and onboarding repositories to automated vulnerability remediation and reporting systems.
  • Coordinate supply chain, cloud, corporate security, and detection and response teams during integrations.
  • Work with corporate development, legal, security leadership, engineering teams, and external engineering and security counterparts at acquired companies.
  • Formalize and scale the M&A security playbook, including the risk-scoring model, diligence runbook, and integration checklist.
  • Build Claude-powered tooling to replace manual processes where possible.
  • Participate in the operational on-call rotation, including bug bounty escalations, launch consultations, and incident response.
  • Contribute to core AppSec projects between deals, including secure design reviews, threat modeling for agentic systems, and security automation.

Requirements

  • Hands-on application and infrastructure security experience, including cloud and containerized environments.
  • Ability to rapidly assess unfamiliar codebases or architectures and produce clear, prioritized risk assessments for non-security audiences.
  • Production-quality coding ability in at least one of Python, Go, Rust, or TypeScript.
  • Practical threat-modeling and vulnerability-identification skills, including experience finding and analyzing real bugs in real systems.
  • Ability to operate with high autonomy, ambiguity, and confidential information.
  • Clear written and verbal communication skills across executives, legal and corporate development partners, engineering teams, and acquired-company counterparts.
  • Bachelor's degree or equivalent combination of education, training, and experience. The field of study must be relevant to the role through coursework, training, or professional experience.

Preferred Qualifications

  • 7+ years of experience in application security, security consulting, or security architecture.
  • M&A security due diligence, third-party security assessment, or technical due diligence experience.
  • Experience establishing or scaling SAST, DAST, bug bounty, or vulnerability management coverage across multiple codebases.
  • Experience building security automation or tooling rather than relying solely on manual review.
  • Familiarity with using LLMs as a core part of a security workflow.
  • Experience securing agentic, code-execution, or LLM-integrated systems.

Representative Projects

  • Direct Anthropic's internal LLM-driven code analysis and AI-assisted scanning at an unfamiliar acquired repository and produce a prioritized remediation plan.
  • Design the risk-scoring framework used to compare security posture across acquisitions.
  • Automate onboarding acquired codebases to Anthropic's vulnerability dashboard, dependency auto-patching, and bug bounty scope.
  • Write and present security risk memos to corporate development and security leadership.

Benefits

Anthropic offers competitive compensation and benefits, optional equity donation matching, generous vacation and parental leave, flexible working hours, and office space for collaboration. Anthropic sponsors visas and makes reasonable efforts to obtain visas with assistance from an immigration lawyer.

The role is remote-friendly but travel is required. Staff are currently expected to work from one of Anthropic's offices at least 25% of the time.

More jobs at Anthropic

Similar jobs