Staff+ Application Security Engineer - M&A

Anthropic

New York (NY)

Hybrid

USD 320,000 - 485,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Visa sponsorship

Job summary

Anthropic is seeking a seasoned Application Security leader to own due diligence for acquisitions and scale security integration of acquired systems. You will build playbooks, risk models, and Claude-powered tooling while coordinating across governance, legal, and engineering teams.

The role emphasizes M&A security with opportunities to contribute to AppSec projects and security automation, leveraging deep coding and threat modeling skills in a fast-paced environment.

Qualifications

  • Hands-on application and infrastructure security across cloud and containerized environments.
  • Ability to rapidly assess unfamiliar codebases and present risk to non-security audiences.
  • Production-quality coding ability in Python, Go, Rust, or TypeScript.
  • Threat-modeling and vulnerability-identification skills with real-world bug experience.
  • Comfort operating with high autonomy and confidential context.
  • Clear written and verbal communication with executives, legal, and engineering partners.

Responsibilities

  • Lead pre-close security due diligence on prospective acquisitions — coordinate external testing, threat-model the target, assess controls, deliver leadership risk readout.
  • Drive post-close security integration — static/dynamic analysis on acquired codebases, track remediation, onboard repositories to remediation/reporting systems.
  • Coordinate with security engineering teams across supply chain, cloud, and corporate security on integration workstreams.
  • Translate security work across governance, legal, and engineering teams, keeping workstream legible for all stakeholders.
  • Formalize and scale Anthropic's M&A security playbook — risk-scoring model, diligence runbook, integration checklist, tooling automation.
  • Share operational on-run rotation for bug bounty escalations, launches, and incident response.
  • Contribute to core AppSec projects — secure design reviews, threat modeling for agentic systems, security automation roadmap.

Skills

Security assessment
Threat modeling
Coding in Python/Go/Rust/TypeScript
Clear communication
Autonomy

Education

Bachelor's degree

Tools

SAST/DAST tooling
Bug bounty tooling
LLMs in security workflows

Job description

About Anthropic

Anthropic’s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems.

About the role

Anthropic's Application Security team secures the systems that build, serve, and increasingly are Claude — and as Anthropic's footprint grows, that mandate now extends to companies and codebases we bring in from outside. This role establishes that function.

You’ll own security due diligence and secure integration for Anthropic's acquisitions — assessing a target's security posture pre-close, writing the security risk readout for leadership, and after close, bringing acquired systems up to Anthropic's bar. Security has been part of every deal to date, but this is the first dedicated role for it: you’ll formalize the playbook, the risk model, and the tooling, and make them repeatable.

This is an AppSec role first. You’ll be an active member of the Application Security team — same rituals, same on-run rotation, same tooling, working alongside engineers securing Anthropic's own agentic product surfaces. The expectation is the same too: we use Claude as our primary tool, and you're expected to automate the repeatable parts of diligence and integration as you go, so each acquisition is easier than the last. When deal flow is quiet, you'll pick up core AppSec project work; when it's active, M&A is your priority.

We're upfront that the center of gravity here is M&A rather than core product security. It's burstier, more assessment-heavy, and operates on confidential, time-sensitive work. If you like parachuting into an unfamiliar codebase under time pressure and turning it into a clear risk picture for leadership, this is that job.

Key responsibilities
  • Lead pre-close security due diligence on prospective acquisitions — coordinate external penetration testing, threat-model the target's architecture, assess security controls, and deliver the security risk readout for leadership ahead of close and integration planning
  • Drive post-close security integration — stand up static and dynamic analysis coverage on acquired codebases, track high- and critical-severity remediation to closure, fold acquired assets into bug bounty scope, and onboard repositories to Anthropic's automated vulnerability remediation and reporting systems
  • Coordinate adjacent security engineering teams (supply chain, cloud, corporate security, detection & response) on their portions of each integration
  • Work across a wide set of stakeholders on every deal — corporate development, legal, security leadership, and the engineering teams inheriting acquired systems internally; engineering and security counterparts at the target company externally — translating between them and keeping the security workstream legible to all of them
  • Formalize and scale Anthropic's M&A security playbook — risk-scoring model, diligence runbook, integration checklist — and turn as much of it as possible into Claude-powered tooling rather than manual process
  • Share the team's operational on-run rotation (bug bounty escalations, launch consults, incident response), swapping out during periods of active deal work
  • Contribute to core AppSec projects between deals — secure design reviews, threat modeling for agentic systems, and the team's security automation roadmap
Minimum qualifications
  • Hands-on application and infrastructure security experience, including cloud and containerized environments
  • Demonstrated ability to rapidly assess an unfamiliar codebase or architecture and produce a clear, prioritized risk assessment for a non-security audience
  • Production-quality coding ability in at least one of Python, Go, Rust, or TypeScript
  • Practical threat-modeling and vulnerability-identification skills — you've found and reasoned about real bugs in real systems
  • Comfort operating with high autonomy, ambiguity, and tightly-held confidential context
  • Clear written and verbal communication across varied audiences — executives, legal and corporate development partners, and engineering counterparts at an acquired company
Preferred qualifications
  • 7+ years in application security, security consulting, or security architecture
  • Prior M&A security due diligence, third-party security assessment, or technical due diligence experience
  • Experience standing up or scaling SAST/DAST, bug bounty, or vulnerability management coverage across multiple codebases
  • Track record of building security automation or tooling rather than relying solely on manual review
  • Familiarity with using LLMs as a core part of your security workflow
  • Experience securing agentic, code-execution, or LLM-integrated systems
Representative projects
  • Point Anthropic's internal LLM-driven code analysis and AI-assisted scanning at an acquired repository nobody here has seen, and turn the output into a prioritized remediation plan in days rather than weeks
  • Design the risk-scoring framework Anthropic uses to compare security posture across acquisitions of different shapes and sizes
  • Build the automation that onboards an acquired codebase to Anthropic's vulnerability dashboard, dependency auto-patching, and bounty scope without a human running a checklist
  • Write the security risk memo for a live deal and present it to corporate development and security leadership
Annual Salary

$320,000 — $485,000 USD

Logistics

Minimum education: Bachelor’s degree or an equivalent combination of education, training, and/or experience

Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience

Minimum years of experience: Years of experience required will correlate with the internal job level requirements for the position

Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices.

Visa sponsorship: We do sponsor visas! However, we aren't able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this.

We encourage you to apply even if you do not believe you meet every single qualification. Not all strong candidates will meet every single qualification as listed. Research shows that people who identify as being from underrepresented groups are more prone to experiencing imposter syndrome and doubting the strength of their candidacy, so we urge you not to exclude yourself prematurely and to submit an application if you're interested in this work. We think AI systems like the ones we're building have enormous social and ethical implications. We think this makes representation even more important, and we strive to include a range of diverse perspectives on our team.

Your safety matters to us. To protect yourself from potential scams, remember that Anthropic recruiters only contact you from @anthropic.com email addresses. In some cases, we may partner with vetted recruiting agencies who will identify themselves as working on behalf of Anthropic. Be cautious of emails from other domains. Legitimate Anthropic recruiters will never ask for money, fees, or banking information before your first day. If you're ever unsure about a communication, don't click any links—visit anthropic.com/careers directly for confirmed position openings.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff+ Application Security Engineer - M&A
Staff+ Application Security Engineer - M&A

Visa Hunt • Seattle (WA), San Francisco (CA)

Hybrid
USD 320,000 - 485,000
Health insurance
Staff+ Application Security Engineer - M&A
Staff+ Application Security Engineer - M&A

Anthropic • San Francisco (CA)

Hybrid
USD 320,000 - 485,000
Staff+ Application Security Engineer - M&A Anthropic Remote-Friendly (Travel-Required) | San Fr[...]
Staff+ Application Security Engineer - M&A Anthropic Remote-Friendly (Travel-Required) | San Fr[...]

Neura Market • San Francisco (CA), Northern (KY)

Hybrid
USD 320,000 - 485,000
Staff Software Security Engineer
Staff Software Security Engineer

Anthropic • San Francisco (CA)

On-site
USD 405,000 - 485,000
Staff+ Application Security Engineer
Staff+ Application Security Engineer

SignalAI • New York (NY)

Hybrid
USD 320,000 - 485,000
Security Engineer, Corporate Security
Security Engineer, Corporate Security

Anthropic • San Francisco (CA)

Hybrid
USD 320,000 - 405,000
Staff+ Application Security Engineer
Staff+ Application Security Engineer

Menlo Ventures • New York (NY)

Hybrid
USD 405,000 - 485,000
Equity donation matching
Generous vacation and parental leave
Flexible working hours
Security Engineer, Corporate Security
Security Engineer, Corporate Security

Anthropic • Washington

Hybrid
USD 320,000 - 405,000
Visa sponsorship available
Equity donation matching
Generous vacation and parental leave
+2
Strategic Account Executive, Cybersecurity
Strategic Account Executive, Cybersecurity

WinsAbove • San Francisco (CA)

Hybrid
USD 380,000 - 450,000
Security Engineer, Corporate Security
Security Engineer, Corporate Security

Alex Loftus • New York (NY)

Hybrid
USD 320,000 - 405,000