Staff Application Security Engineer

Anthropic

York and North Yorkshire

On-site

GBP 90,000 - 140,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Health insurance
Dental insurance
Vision insurance
Parental leave (22 weeks)

Job summary

Anthropic is seeking an experienced Application Security Engineer to embed security into the software development lifecycle. You will partner with engineers and researchers to proactively identify risks through threat modeling and secure design reviews, and build tooling to enable secure shipping of code.

In this hands-on role, you will manage vulnerability programs, guide remediations, and develop security policies and playbooks to uplift the entire engineering organization.

Qualifications

  • 7+ years of hands-on experience in application and infrastructure security.
  • Experience securing cloud-based and containerized environments.

Responsibilities

  • Lead threat modeling and secure design reviews to identify and mitigate risks.
  • Develop tooling to support secure coding and code reviews at scale.
  • Oversee vulnerability management and coordinate remediation with engineering teams.
  • Develop and document security policies, standards, and playbooks.

Skills

Threat modeling
Secure design reviews
Cloud security
Kubernetes
Docker
AWS
GCP
Python

Education

Bachelor's degree

Tools

Kubernetes
Docker
AWS
GCP

Job description

  • The Application Security team is at the forefront of building security into every phase of the software development lifecycle at Anthropic
  • In this hands-on technical role, you will partner closely with our software engineers and researchers to ensure that security is a core consideration from initial design through implementation
  • You will lead threat modeling and secure design reviews to proactively identify and mitigate risks early, and help with continuous risk assessment
  • You will build tools and systems to support developers shipping code securely, adhering to secure coding best practices
  • Your insights will shape our tooling, detection capabilities, and defenses against emerging threats to AI/ML
  • You’ll develop the standards, processes, and educational resources that enable all Anthropic engineers to be security champions
  • This high-impact role demands a security practitioner who can think like an attacker, has a developer mindset, and can build strong relationships
  • Help secure AI products and internal tools that are introducing industry-novel security risks and pushing established security boundaries
  • Lead “shift left” security efforts to build security into the software development lifecycle
  • Conduct secure design reviews and threat modeling. Identify and prioritize risks, attack surfaces, and vulnerabilities
  • Develop tooling to scale security code reviews and respond to developer questions, including advising developers on remediating vulnerabilities and following secure coding practices
  • Manage Anthropic’s vulnerability management program, including integrating data ingestion pipelines, coding logic to prioritize vulnerability fixes, supporting teams remediating vulnerabilities and developing automated systems at scale
  • Oversee Anthropic’s bug bounty program. Set scope, validate submissions, perform root cause analysis, coordinate remediation with engineering teams, and award bounties. Cultivate relationships with the ethical hacker community
  • Collaborate closely with product engineers and researchers to instill security best practices. Advocate for secure architecture, design, and development
  • Develop and document security policies, standards, and playbooks. Conduct security awareness training for engineers
Benefits
  • Comprehensive health, dental, and vision insurance for you and your dependents
  • Inclusive fertility benefits via Carrot Fertility
  • 22 weeks of paid parental leave
  • Flexible paid time off and absence policies
  • Mental health support for you and your dependents
  • Competitive salary and equity packages
  • Optional equity donation matching at a 1:1 ratio, up to 25% of your equity grant
  • Retirement plans with competitive matching
  • Life and income protection plans
  • $500/month flexible wellness and time saver stipend
  • Commuter benefits
  • Annual education stipend
  • Home office stipends
  • Relocation support for those moving for Anthropic
  • Daily meals and snacks in the office

Bring experience with modern application stacks, infrastructure, and security tools to implement pragmatic defensesAre practiced at collaborating cross-functionally and effectively balancing security requirements with business objectivesHave 7+ years of hands-on experience in application and infrastructure security, including securing cloud-based and containerized environmentsEmbody a proactive mindset to thread security throughout the product lifecycle through activities like threat modeling, secure code review, and educationLead with empathy, a collaborative spirit, and a learning mindset to work cross-functionally with engineers of all levels to build security into the software development life cycleAre keen to distill complex security concepts into clear actions and drive consensus without direct authorityPossess broad security knowledge to connect the dots across domains and identify holistic ways to decrease the overall threat surfaceAdvocate for security fundamentals like least privilege, defense-in-depth, and eliminating complexity that could sub-linearly scale security through smart designHave a strong grasp of offensive security to anticipate risks from an adversary’s perspective, not just check compliance boxesStrong proficiency in at least one programming language (e.g., Python, Rust, Go, Java)Leverage creative and strategic thinking to reduce risk through secure design and simplicity, not just controlsMinimum education: Bachelor’s degree or an equivalent combination of education, training, and/or experienceMinimum years of experience: Years of experience required will correlate with the internal job level requirements for the positionRequired field of study: A field relevant to the role as demonstrated through coursework, training, or professional experienceWe encourage you to apply even if you do not believe you meet every single qualification. Not all strong candidates will meet every single qualification as listed. Research shows that people who identify as being from underrepresented groups are more prone to experiencing imposter syndrome and doubting the strength of their candidacy, so we urge you not to exclude yourself prematurely and to submit an application if you’re interested in this workHands-on technical expertise securing complex cloud environments and microservices architectures leveraging technologies like Kubernetes, Docker, and AWS / GCPExposure to offensive security techniques like vulnerability testing, bug bounty, pen testing, and red team exercisesFamiliarity with AI/ML security risks such as prompt injection, data poisoning, model extraction, etc. and mitigationsSolid foundational knowledge of both software and security engineering principles and are keen to continue learningExperience building security tools, applications, and automated toolsExcellent communication skills, able to distill complex security topics for broad audiencesWorked and thrived in fast-paced environments, and comfortable navigating ambiguity

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff+ Software Security Engineer
Staff+ Software Security Engineer

Anthropic • York and North Yorkshire

On-site
GBP 120,000 - 180,000
Comprehensive health insurance
Relocation support
Education stipend
+2
Security Engineer (Corporate Security)
Security Engineer (Corporate Security)

Anthropic • York and North Yorkshire

On-site
GBP 120,000 - 180,000
Comprehensive health insurance
Dental and vision coverage
15–22 weeks parental leave
Staff Software Security Engineer
Staff Software Security Engineer

Anthropic Limited • Greater London

Hybrid
GBP 120,000 - 180,000
Security Engineer (Threat Intel)
Security Engineer (Threat Intel)

Anthropic • York and North Yorkshire

On-site
GBP 85,000 - 130,000
Health insurance
Fertility benefits
Parental leave (22 weeks)
+8
Staff+ Software Engineer (Product Sandboxing)
Staff+ Software Engineer (Product Sandboxing)

Anthropic • York and North Yorkshire

On-site
GBP 90,000 - 150,000
Health insurance
Fertility benefits
Parental leave
+12
Staff+ Software Engineer (Authentication & Identity)
Staff+ Software Engineer (Authentication & Identity)

Anthropic • York and North Yorkshire

On-site
GBP 120,000 - 150,000
Health and wellness benefits
Equity packages
Relocation support
+2
Senior Software Security Engineer
Senior Software Security Engineer

Menlo Ventures • Greater London

On-site
GBP 240,000 - 325,000
Competitive salary
Equity options
Flexible working hours
Staff Software Security Engineer
Staff Software Security Engineer

Anthropic • City Of London

Hybrid
GBP 270,000 - 325,000
Staff+ Software Engineer (Account Abuse)
Staff+ Software Engineer (Account Abuse)

Anthropic • York and North Yorkshire

On-site
GBP 90,000 - 150,000
Health and dental insurance
Parental leave 22 weeks
Equity packages
+4
Applied AI Security Architect
Applied AI Security Architect

job-boards.greenhouse.io- JobBoard • Greater London

On-site
GBP 80,000 - 100,000
Visa sponsorship
Diverse team representation
Hybrid work policy