Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
Anthropic is seeking an experienced Application Security Engineer to embed security into the software development lifecycle. You will partner with engineers and researchers to proactively identify risks through threat modeling and secure design reviews, and build tooling to enable secure shipping of code.
In this hands-on role, you will manage vulnerability programs, guide remediations, and develop security policies and playbooks to uplift the entire engineering organization.
Bring experience with modern application stacks, infrastructure, and security tools to implement pragmatic defensesAre practiced at collaborating cross-functionally and effectively balancing security requirements with business objectivesHave 7+ years of hands-on experience in application and infrastructure security, including securing cloud-based and containerized environmentsEmbody a proactive mindset to thread security throughout the product lifecycle through activities like threat modeling, secure code review, and educationLead with empathy, a collaborative spirit, and a learning mindset to work cross-functionally with engineers of all levels to build security into the software development life cycleAre keen to distill complex security concepts into clear actions and drive consensus without direct authorityPossess broad security knowledge to connect the dots across domains and identify holistic ways to decrease the overall threat surfaceAdvocate for security fundamentals like least privilege, defense-in-depth, and eliminating complexity that could sub-linearly scale security through smart designHave a strong grasp of offensive security to anticipate risks from an adversary’s perspective, not just check compliance boxesStrong proficiency in at least one programming language (e.g., Python, Rust, Go, Java)Leverage creative and strategic thinking to reduce risk through secure design and simplicity, not just controlsMinimum education: Bachelor’s degree or an equivalent combination of education, training, and/or experienceMinimum years of experience: Years of experience required will correlate with the internal job level requirements for the positionRequired field of study: A field relevant to the role as demonstrated through coursework, training, or professional experienceWe encourage you to apply even if you do not believe you meet every single qualification. Not all strong candidates will meet every single qualification as listed. Research shows that people who identify as being from underrepresented groups are more prone to experiencing imposter syndrome and doubting the strength of their candidacy, so we urge you not to exclude yourself prematurely and to submit an application if you’re interested in this workHands-on technical expertise securing complex cloud environments and microservices architectures leveraging technologies like Kubernetes, Docker, and AWS / GCPExposure to offensive security techniques like vulnerability testing, bug bounty, pen testing, and red team exercisesFamiliarity with AI/ML security risks such as prompt injection, data poisoning, model extraction, etc. and mitigationsSolid foundational knowledge of both software and security engineering principles and are keen to continue learningExperience building security tools, applications, and automated toolsExcellent communication skills, able to distill complex security topics for broad audiencesWorked and thrived in fast-paced environments, and comfortable navigating ambiguity