2 months ago
Base Salary
$320k - $485k/yr
Responsibilities
- Lead pre-close security due diligence, including penetration testing coordination, architecture threat modeling, control assessment, and leadership risk readouts.
- Drive post-close security integration by establishing static and dynamic analysis, tracking critical remediation, expanding bug bounty scope, and onboarding repositories to automated vulnerability systems.
- Coordinate supply chain, cloud, corporate security, and detection and response teams during integrations.
- Manage security communication across corporate development, legal, security leadership, internal engineering teams, and acquired-company counterparts.
- Create and scale the M&A security playbook, risk-scoring model, diligence runbook, and integration checklist.
- Build Claude-powered tooling to automate diligence and integration processes.
- Participate in the operational on-run rotation for bug bounty escalations, launch consultations, and incident response.
- Contribute to core AppSec work such as secure design reviews, agentic-system threat modeling, and security automation.
Requirements
- Hands-on application and infrastructure security experience in cloud and containerized environments.
- Ability to rapidly assess unfamiliar codebases or architectures and produce prioritized risk assessments for non-security audiences.
- Production-quality coding ability in at least one of Python, Go, Rust, or TypeScript.
- Practical threat-modeling and vulnerability-identification skills based on real systems.
- Ability to operate autonomously in ambiguous, confidential, and time-sensitive contexts.
- Clear written and verbal communication with executives, legal and corporate development partners, and engineering counterparts.
- Preferred: 7+ years of experience in application security, security consulting, or security architecture.
- Preferred: M&A security due diligence, third-party security assessment, or technical due diligence experience.
- Preferred: Experience standing up or scaling SAST/DAST, bug bounty, or vulnerability management coverage across multiple codebases.
- Preferred: Experience building security automation or tooling.
- Preferred: Familiarity with using LLMs as a core part of security workflows.
- Preferred: Experience securing agentic, code-execution, or LLM-integrated systems.
- Bachelor’s degree or equivalent combination of education, training, and/or experience in a relevant field.
Benefits
- Hybrid policy requiring staff to work from an office at least 25% of the time.
- Generous vacation and parental leave.
- Flexible working hours.
- Office space for collaboration.
- Optional equity donation matching.
- Visa sponsorship may be available, with immigration lawyer support.
- Anthropic is a public benefit corporation.
Tech Stack
Categories
About Anthropic
We're an AI research company that builds reliable, interpretable, and steerable AI systems. Our first product is Claude, an AI assistant for tasks at any scale. Our research interests span multiple areas including natural language, human feedback, scaling laws, reinforcement learning, code generation, and interpretability.