Staff+ Application Security Engineer

Menlo Ventures

New York (NY)

Hybrid

USD 405,000 - 485,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Equity donation matching
Generous vacation and parental leave
Flexible working hours

Job summary

Menlo Ventures is looking for an Application Security professional to join Anthropic in New York City. This role focuses on integrating security into the software development lifecycle, ensuring security is a core aspect from initial design through implementation.

You will lead threat modeling and secure design reviews, handle vulnerability management, and develop educational resources to empower engineers. Ideal candidates will have 7+ years of experience in application security and proficiency in programming languages such as Python or Go.

Qualifications

  • 7+ years of hands-on experience in application and infrastructure security.
  • Strong proficiency in at least one programming language.
  • Ability to lead cross-functional teams to integrate security into development.

Responsibilities

  • Lead security efforts in the software development lifecycle.
  • Conduct secure design reviews and threat modeling.
  • Develop tools for scaling security code reviews.

Skills

Application and infrastructure security
Programming languages (Python, Rust, Go, Java)
Cloud-based environments
Security best practices

Education

Bachelor's degree or equivalent

Tools

Kubernetes
Docker
AWS
GCP

Job description

Anthropic’s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole.

About The Role

The Application Security team is at the forefront of building security into every phase of the software development lifecycle at Anthropic. In this hands‑on technical role, you will partner closely with our software engineers and researchers to ensure that security is a core consideration from initial design through implementation. You will lead threat modeling and secure design reviews to proactively identify and mitigate risks early, and help with continuous risk assessment. You will build tools and systems to support developers shipping code securely, adhering to secure coding best practices. Your insights will shape our tooling, detection capabilities, and defenses against emerging threats to AI/ML. You’ll develop the standards, processes, and educational resources that enable all Anthropic engineers to be security champions. This high‑impact role demands a security practitioner who can think like an attacker, has a developer mindset, and can build strong relationships.

Responsibilities
  • Help secure AI products and internal tools that are introducing industry‑novel security risks and pushing established security boundaries
  • Lead “shift left” security efforts to build security into the software development lifecycle
  • Conduct secure design reviews and threat modeling; identify and prioritize risks, attack surfaces, and vulnerabilities
  • Develop tooling to scale security code reviews and respond to developer questions, including advising developers on remediating vulnerabilities and following secure coding practices
  • Manage Anthropic’s vulnerability management program, including integrating data ingestion pipelines, coding logic to prioritize vulnerability fixes, supporting teams remediating vulnerabilities and developing automated systems at scale
  • Oversee Anthropic’s bug bounty program. Set scope, validate submissions, perform root cause analysis, coordinate remediation with engineering teams, and award bounties. Cultivate relationships with the ethical hacker community
  • Collaborate closely with product engineers and researchers to instill security best practices and advocate for secure architecture, design, and development
  • Develop and document security policies, standards, and playbooks; conduct security awareness training for engineers
You May Be a Good Fit If You
  • Have 7+ years of hands‑on experience in application and infrastructure security, including securing cloud‑based and containerized environments
  • Strong proficiency in at least one programming language (Python, Rust, Go, Java)
  • Lead with empathy, a collaborative spirit, and a learning mindset to work cross‑functionally with engineers of all levels to build security into the software development life cycle
  • Leverage creative and strategic thinking to reduce risk through secure design and simplicity, not just controls
  • Possess broad security knowledge to connect the dots across domains and identify holistic ways to decrease the overall threat surface
  • Are keen to distill complex security concepts into clear actions and drive consensus without direct authority
  • Embody a proactive mindset to thread security throughout the product lifecycle through activities like threat modeling, secure code review, and education
  • Have a strong grasp of offensive security to anticipate risks from an adversary’s perspective, not just check compliance boxes
  • Bring experience with modern application stacks, infrastructure, and security tools to implement pragmatic defenses
  • Are practiced at collaborating cross‑functionally and effectively balancing security requirements with business objectives
  • Advocate for security fundamentals such as least privilege, defense‑in‑depth, and eliminating complexity that could sub‑linearly scale security through smart design
Strong Candidates May Also
  • Hands‑on technical expertise securing complex cloud environments and microservices architectures leveraging technologies such as Kubernetes, Docker, AWS, GCP
  • Exposure to offensive security techniques such as vulnerability testing, bug bounty, pen testing, and red team exercises
  • Familiarity with AI/ML security risks such as prompt injection, data poisoning, model extraction, and mitigations
  • Experience building security tools, applications, and automated tools
  • Solid foundational knowledge of both software and security engineering principles and a willingness to continue learning
  • Excellent communication skills, able to distill complex security topics for broad audiences
  • Worked and thrived in fast‑paced environments, and comfortable navigating ambiguity
Annual Salary

$405,000—$485,000 USD

Logistics
  • Minimum education: Bachelor’s degree or an equivalent combination of education, training, and/or experience
  • Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience
  • Minimum years of experience: Years of experience required will correlate with the internal job level requirements for the position
  • Location‑based hybrid policy: Staff are expected to be in one of our offices at least 25% of the time, with some roles requiring more office presence
  • Visa sponsorship: We sponsor visas and will make reasonable efforts to obtain one if we make an offer
  • Benefits: Competitive compensation, optional equity donation matching, generous vacation and parental leave, flexible working hours, and a collaborative office environment

Anthropic is a public benefit corporation headquartered in San Francisco. We offer competitive compensation and benefits, optional equity donation matching, generous vacation and parental leave, flexible working hours, and a lovely office space in which to collaborate with colleagues.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff+ Software Security Engineer
Staff+ Software Security Engineer

Anthropic • New York (NY)

Hybrid
USD 405,000 - 485,000
Senior Software Security Engineer
Senior Software Security Engineer

Anthropic • New York (NY)

Hybrid
USD 320,000 - 405,000
Equity donation matching
Generous vacation and parental leave
Flexible working hours
+1
Staff+ Security Engineer, Risk Engineering San Francisco, CA | New York City, NY | Seattle, WA
Staff+ Security Engineer, Risk Engineering San Francisco, CA | New York City, NY | Seattle, WA

Anthropic • New York (NY)

On-site
USD 405,000
Generous vacation and parental leave
Flexible working hours
Office space
Staff Software Security Engineer
Staff Software Security Engineer

Anthropic • San Francisco (CA)

On-site
USD 405,000 - 485,000
Senior Software Security Engineer Anthropic San Francisco, CA | New York City, NY | Seattle, WA
Senior Software Security Engineer Anthropic San Francisco, CA | New York City, NY | Seattle, WA

Neura Market • San Francisco (CA), Northern (KY)

Hybrid
USD 320,000 - 405,000
Competitive compensation
Equity donation matching
Generous vacation
+3
Staff+ Application Security Engineer
Staff+ Application Security Engineer

SignalAI • New York (NY)

Hybrid
USD 320,000 - 485,000
Senior Software Security Engineer
Senior Software Security Engineer

Anthropic • San Francisco (CA)

On-site
USD 300,000 - 320,000
Competitive compensation and benefits
Optional equity donation matching
Generous vacation and parental leave
+2
Technical Program Manager, Security
Technical Program Manager, Security

Anthropic • San Francisco (CA)

On-site
USD 290,000 - 365,000
Competitive compensation and benefits
Flexible working hours
Generous vacation and parental leave
Staff+ Security Engineer (Risk Engineering)
Staff+ Security Engineer (Risk Engineering)

Anthropic • San Francisco (CA)

Hybrid
USD 405,000
Flexible working hours
Generous vacation leave
Collaborative office environment
+1
Senior Software Security Engineer
Senior Software Security Engineer

SignalAI • New York (NY)

Hybrid
USD 320,000 - 405,000
Competitive compensation
Equity donation matching
Generous vacation and parental leave
+2