Staff+ Application Security Engineer
Job Description
A senior Staff+ Application Security Engineer role focused on Claude powered security systems and end-to-end security for production AI systems.
Responsibilities
- Design, build, and operate Claude powered security systems including LLM driven code analysis, automated vulnerability remediation, and AI assisted threat modeling; own one or more end-to-end, including cross functional relationships
- Lead secure design reviews and threat modeling for novel AI systems, identifying risks that fall outside existing frameworks
- Evolve a public bug bounty program where automation handles routine triage and root cause work, while engineers manage escalations and corner cases
- Partner with Product, Infrastructure, and Research as an embedded security owner — advise on launches, shape architecture, and influence decisions where security is a constraint
- Share an on run rotation with the team to handle bounty escalations, incident response, and launch consultations for systems serving Claude in production
Requirements
- Hands on application and infrastructure security experience, including cloud and containerized environments
- Production quality coding ability in Python, Go, Rust, or TypeScript with a track record of building durable systems
- Practical threat modeling and vulnerability identification skills, with experience finding and reasoning about real bugs in real systems
- Ability to operate with high autonomy and ambiguity, comfortable with un scripted problem ownership
- Clear technical communication with both engineers and leadership
Technologies
- Claude
- Python
- Go
- Rust
- TypeScript
Benefits
- Competitive compensation and benefits
- Optional equity donation matching
- Generous vacation and parental leave
- Flexible working hours
- A lovely office space to collaborate
ABOUT ANTHROPIC
Anthropic is dedicated to creating reliable, interpretable, and steerable AI systems that are safe and beneficial for users and society. The team comprises researchers, engineers, policy experts, and business leaders collaborating to build beneficial AI systems.
ABOUT THE ROLE
- Anthropic's Application Security team protects the systems that build, serve, and increasingly run Claude. The attack surface includes multi agent orchestration, sandboxed code execution, agents with delegated credentials, and untrusted tool output crossing trust boundaries
- The team uses Claude as the primary tool across the job: it drives static analysis, drafts and fixes vulnerabilities as pull requests, handles first line bug bounty triage, and assists threat modeling for design reviews. Humans provide the judgment layer for system level reasoning
- This is a builder's role on a senior team. Engineers ship production systems, pass a hands on threat modeling bar, and own a system end to end, shaping customer facing product security including Claude Code security review tooling, its security guidance plugin, sandboxing, and auto mode
REPRESENTATIVE PROJECTS
- Autonomous vulnerability pipeline where LLM driven code analysis detects issues, scores exploitability, and opens fix PRs with humans reviewing
- Bug bounty operations where Claude handles first line triage and drafting, with engineers focusing on high judgment reports
- AI assisted threat modeling that generates intake questions, drafts models, and recommends which design reviews require human involvement
- Automated dependency vulnerability remediation across Anthropic's codebase
- Company wide vulnerability dashboard and SLA enforcement for all engineering teams
- Threat models and security architecture for agentic product surfaces including code execution sandboxing, agent identity and delegated authentication, and tool use boundaries
LOGISTICS
- Salary: USD 320,000 - 485,000 per year
- Minimum education: Bachelor’s degree or equivalent
- Minimum field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience
- Location policy: Remote work; staff are expected to be in one of our offices at least 25% of the time, with some roles requiring more time in the office
- Visa sponsorship: We sponsor visas; efforts are made to assist if offered, though not guaranteed for every role
- We encourage applicants to apply even if not every qualification is met
COME WORK WITH US
- Anthropic is a public benefit corporation headquartered in San Francisco
- Competitive compensation and benefits, optional equity donation matching, generous vacation and parental leave, flexible working hours
- A lovely office space to collaborate with colleagues
- Guidance on AI usage in the application process