EngineerJobs.io
← Back to all jobs

Job Description

Anthropic is hiring a Staff+ Application Security Engineer to support mergers and acquisitions with an application security focus. In this role, you will run security diligence before deals close and then drive secure integration after acquisition, using automation and security tooling while coordinating across internal security engineering teams and deal stakeholders.

Working remotely, you will be responsible for producing security risk readouts for leadership ahead of integration planning, standing up static and dynamic analysis coverage on newly acquired codebases, and scaling an M&A security playbook that can be translated into Claude-powered tooling rather than manual processes.

Responsibilities

  • Lead pre-close security due diligence by coordinating external penetration testing, threat-modeling the target architecture, assessing security controls, and delivering a security risk readout for leadership ahead of close and integration planning.
  • Drive post-close security integration by standing up static and dynamic analysis coverage on acquired codebases, tracking high- and critical-severity remediation to closure, folding acquired assets into bug bounty scope, and onboarding repositories to Anthropic’s automated vulnerability remediation and reporting systems.
  • Coordinate with adjacent security engineering teams (supply chain, cloud, corporate security, detection & response) on their portions of each integration.
  • Work across a wide set of stakeholders on every deal including corporate development, legal, security leadership, and engineering teams inheriting acquired systems internally, as well as engineering and security counterparts at the target company externally, translating between groups and keeping the security workstream legible.
  • Formalize and scale Anthropic’s M&A security playbook, including a risk-scoring model, diligence runbook, and integration checklist, and convert as much of it as possible into Claude-powered tooling instead of manual process.
  • Share the team’s operational on-run rotation covering bug bounty escalations, launch consults, and incident response, with swap coverage during active deal periods.
  • Contribute between deals to core AppSec work such as secure design reviews, threat modeling for agentic systems, and the team’s security automation roadmap.

Requirements

  • Hands-on application and infrastructure security experience, including cloud and containerized environments.
  • Demonstrated ability to rapidly assess an unfamiliar codebase or architecture and produce a clear, prioritized risk assessment for non-security audiences.
  • Production-quality coding ability in at least one of Python, Go, Rust, or TypeScript.
  • Practical threat-modeling and vulnerability-identification skills, including finding and reasoning about real bugs in real systems.
  • Comfort operating with high autonomy, ambiguity, and tightly-held confidential context.
  • Clear written and verbal communication across varied audiences including executives, legal and corporate development partners, and engineering counterparts at an acquired company.

Technologies

  • Python, Go, Rust, TypeScript
  • SAST, DAST, bug bounty
  • Claude
  • Static and dynamic analysis
  • LLMs

Benefits

  • Optional equity donation matching
  • Generous vacation and parental leave
  • Flexible working hours
  • Lovely office space in which to collaborate with colleagues
  • Competitive compensation and benefits
  • Guidance on Candidates' AI Usage (policy for using AI in the application process)

Logistics

  • Minimum education: Bachelor’s degree or an equivalent combination of education, training, and/or experience
  • Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience
  • Minimum years of experience: Years of experience required will correlate with internal job level requirements
  • Location: Remote. Location-based hybrid policy: currently expects staff to be in one of Anthropic's offices at least 25% of the time, though some roles may require more.
  • Visa sponsorship: Anthropic sponsors visas, but cannot guarantee sponsorship for every role and candidate. If an offer is made, the company will make reasonable efforts to support visa processes and retains an immigration lawyer to help.
  • Encouragement to apply even if you do not meet every single qualification.
  • Safety: Anthropic recruiters only contact candidates from @anthropic.com email addresses; legitimate recruiters will never ask for money, fees, or banking information before the first day.

Representative Projects

  • Point Anthropic’s internal LLM-driven code analysis and AI-assisted scanning at an acquired repository nobody here has seen, then turn results into a prioritized remediation plan in days rather than weeks.
  • Design the risk-scoring framework Anthropic uses to compare security posture across acquisitions of different shapes and sizes.
  • Build automation to onboard an acquired codebase to Anthropic’s vulnerability dashboard, dependency auto-patching, and bounty scope without a human running a checklist.
  • Write a security risk memo for a live deal and present it to corporate development and security leadership.

Salary: USD 320,000 - 485,000 per year.

Similar Jobs