Staff+ Application Security Engineer - M&A
Ai Security
Application Security
Application Security Engineering
Bug Bounty
Cybersecurity Tools
Dynamic Application Security Testing
Engineer
Information Security
InfoSec
M&A Integration
Rust
Security Assessment
Security Automation
Security Testing
Software Security
Static Application Security Testing
Job Description
The Staff+ Application Security Engineer will support Anthropic’s M&A program by running application security due diligence before close and leading secure integration activities after acquisition. The role emphasizes automation, secure tooling, and clear risk communication across deal stakeholders.
Application Security for Pre-Close Due Diligence
- Lead security due diligence for prospective acquisitions, including coordinating external penetration testing and conducting threat modeling of target architectures.
- Assess security controls and produce a security risk readout for leadership ahead of close and integration planning.
Post-Close Security Integration and Remediation
- Drive post-close security integration by standing up static and dynamic analysis coverage for acquired codebases.
- Track high- and critical-severity remediation through to closure.
- Fold acquired assets into bug bounty scope and onboard repositories to Anthropic’s automated vulnerability remediation and reporting systems.
Cross-Team Deal Coordination
- Coordinate with adjacent security engineering teams including supply chain, cloud, corporate security, and detection & response for their respective integration areas.
- Partner with stakeholders across each deal, including corporate development, legal, security leadership, and engineering teams inheriting acquired systems internally, as well as engineering and security counterparts at the target company externally.
- Translate technical security workstreams so they remain clear to a range of audiences throughout the integration lifecycle.
M&A AppSec Playbook Automation
- Formalize and scale Anthropic’s M&A security playbook, including a risk-scoring model, diligence runbook, and integration checklist.
- Convert manual steps into Claude-powered tooling wherever possible.
Operational Rotation and AppSec Contributions
- Share the team’s on-run rotation for activities such as bug bounty escalations, launch consults, and incident response, with rotation coverage swapped during periods of active deal work.
- Contribute between deals to core AppSec efforts, including secure design reviews and threat modeling for agentic systems, as well as the team’s security automation roadmap.
Required Qualifications
- Hands-on application and infrastructure security experience, including cloud and containerized environments.
- Ability to rapidly assess unfamiliar codebases or architectures and produce prioritized risk assessments for non-security audiences.
- Production-quality coding experience in at least one of Python, Go, Rust, or TypeScript.
- Practical threat-modeling and vulnerability identification skills, including finding and reasoning about real bugs in real systems.
- Comfort working with high autonomy, ambiguity, and tightly held confidential context.
- Clear written and verbal communication across executive, legal, corporate development, and engineering stakeholders, including counterparts at acquired companies.
Relevant Technologies
Python, Go, Rust, TypeScript, SAST, DAST, bug bounty, Claude, static and dynamic analysis, LLMs
Education and Logistics
- Minimum education: Bachelor’s degree or an equivalent combination of education, training, and/or experience.
- Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience.
- Minimum years of experience: Years of experience required will correlate with internal job level requirements.
- Location: Remote (remote).
Location-based hybrid policy: Currently, Anthropic expects staff to be in one of its offices at least 25% of the time, though some roles may require more time in offices.
- Visa sponsorship: Anthropic does sponsor visas and will make reasonable efforts if an offer is made; an immigration lawyer is retained to support the process.
- Application guidance: Encouraged to apply even if not all qualifications are met.
- Recruiter safety: Anthropic recruiters only contact candidates from @anthropic.com addresses; legitimate recruiters will never request money, fees, or banking information before the first day.
Compensation
USD 320,000 - 485,000 per yearly
Benefits
- Optional equity donation matching.
- Generous vacation and parental leave.
- Flexible working hours.
- Lovely office space for collaboration with colleagues.
- Competitive compensation and benefits.
- Guidance on Candidates’ AI Usage, including a policy for using AI in the application process.
Representative Projects
- Applied internal LLM-driven code analysis and AI-assisted scanning at an acquired repository and produced a prioritized remediation plan within days.
- Designed the risk-scoring framework used to compare security posture across acquisitions of different profiles.
- Built automation to onboard an acquired codebase to Anthropic’s vulnerability dashboard, dependency auto-patching, and bounty scope without manual checklist work.
- Wrote security risk memos for live deals and presented them to corporate development and security leadership.