Staff+ Application Security Engineer - M&A

United States Digital Space LLC

United States

Hybrid

USD 320,000 - 485,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

United States Digital Space LLC is seeking an experienced AppSec leader to own security due diligence for acquisitions and drive post‑close integration across codebases and platforms.

You will formalize risk models, playbooks, and Claude‑powered tooling, coordinating with corporate development, legal, and engineering during time‑sensitive deals. This role emphasizes acquisition security over core product security, with a cadence of M&A projects.

Qualifications

  • Hands-on application and infrastructure security experience.
  • Ability to rapidly assess an unfamiliar codebase or architecture and produce a clear risk assessment for a non-security audience.
  • Production-quality coding ability in Python, Go, Rust, or TypeScript.
  • Practical threat-modeling and vulnerability-identification skills.
  • Comfort operating with high autonomy, ambiguity, and confidential context.
  • Clear written and verbal communication across varied audiences.

Responsibilities

  • Lead pre-close security due diligence on prospective acquisitions — coordinate external penetration testing, threat-model the target’s architecture, assess security controls, and deliver the security risk readout for leadership ahead of close and integration planning.
  • Drive post-close security integration — stand up static and dynamic analysis coverage on acquired codebases, track remediation to closure, fold acquired assets into bug bounty scope, and onboard repositories to automated tooling.
  • Coordinate adjacent security engineering teams on their portions of each integration.
  • Work with stakeholders across corporate development, legal, security leadership, and engineering teams of acquired companies to ensure security work is understood and prioritized.
  • Formalize and scale the company’s M&A security playbook — risk-scoring model, diligence runbook, integration checklist — and turn tools into Claude-powered automation.
  • Share the team’s operational on-run rotation (bug bounty escalations, launch consults, incident response).
  • Contribute to core AppSec projects — design reviews, threat modeling for agentic systems, and security automation roadmap.

Skills

Security risk assessment
Threat modeling
Coding in Python/Go/Rust/TS
Communication
Autonomy in ambiguity

Education

Bachelor’s degree or equivalent

Job description

About the company

the company’s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems.

About the role

the company's Application Security team secures the systems that build, serve, and increasingly *are* Claude — and as the company's footprint grows, that mandate now extends to companies and codebases we bring in from outside. This role establishes that function.

You’ll own security due diligence and secure integration for the company's acquisitions — assessing a target's security posture pre-close, writing the security risk readout for leadership, and after close, bringing acquired systems up to the company's bar. Security has been part of every deal to date, but this is the first dedicated role for it: you’ll formalize the playbook, the risk model, and the tooling, and make them repeatable.

This is an AppSec role first. You’ll be an active member of the Application Security team — same rituals, same on‑run rotation, same tooling, working alongside engineers securing the company’s own agentic product surfaces. The expectation is the same too: we use Claude as our primary tool, and you’re expected to automate the repeatable parts of diligence and integration as you go, so each acquisition is easier than the last. When deal flow is quiet, you’ll pick up core AppSec project work; when it’s active, M&A is your priority.

We’re upfront that the center of gravity here is M&A rather than core product security. It’s burstier, more assessment‑heavy, and operates on confidential, time‑sensitive work. If you like parachuting into an unfamiliar codebase under time pressure and turning it into a clear risk picture for leadership, this is that job.

Key responsibilities
  • Lead pre‑close security due diligence on prospective acquisitions — coordinate external penetration testing, threat‑model the target’s architecture, assess security controls, and deliver the security risk readout for leadership ahead of close and integration planning.
  • Drive post‑close security integration — stand up static and dynamic analysis coverage on acquired codebases, track high‑ and critical‑severity remediation to closure, fold acquired assets into bug bounty scope, and onboard repositories to the company’s automated vulnerability remediation and reporting systems.
  • Coordinate adjacent security engineering teams (supply chain, cloud, corporate security, detection & response) on their portions of each integration.
  • Work across a wide set of stakeholders on every deal — corporate development, legal, security leadership, and the engineering teams inheriting acquired systems internally; engineering and security counterparts at the target company externally — translating between them and keeping the security workstream legible to all of them.
  • Formalize and scale the company’s M&A security playbook — risk‑scoring model, diligence runbook, integration checklist — and turn as much of it as possible into Claude‑powered tooling rather than manual process.
  • Share the team’s operational on‑run rotation (bug bounty escalations, launch consults, incident response), swapping out during periods of active deal work.
  • Contribute to core AppSec projects between deals — secure design reviews, threat modeling for agentic systems, and the team’s security automation roadmap.
Minimum qualifications
  • Hands‑on application and infrastructure security experience, including cloud and containerized environments.
  • Demonstrated ability to rapidly assess an unfamiliar codebase or architecture and produce a clear, prioritized risk assessment for a non‑security audience.
  • Production‑quality coding ability in at least one of Python, Go, Rust, or TypeScript.
  • Practical threat‑modeling and vulnerability‑identification skills — you’ve found and reasoned about real bugs in real systems.
  • Comfort operating with high autonomy, ambiguity, and tightly‑held confidential context.
  • Clear written and verbal communication across varied audiences — executives, legal and corporate development partners, and engineering counterparts at an acquired company.
Preferred qualifications
  • 7+ years in application security, security consulting, or security architecture.
  • Prior M&A security due diligence, third‑party security assessment, or technical due diligence experience.
  • Experience standing up or scaling SAST/DAST, bug bounty, or vulnerability management coverage across multiple codebases.
  • Track record of building security automation or tooling rather than relying solely on manual review.
  • Familiarity with using LLMs as a core part of your security workflow.
  • Experience securing agentic, code‑execution, or LLM‑integrated systems.
Representative projects
  • Point the company’s internal LLM‑driven code analysis and AI‑assisted scanning at an acquired repository nobody here has seen, and turn the output into a prioritized remediation plan in days rather than weeks.
  • Design the risk‑scoring framework the company uses to compare security posture across acquisitions of different shapes and sizes.
  • Build the automation that onboards an acquired codebase to the company’s vulnerability dashboard, dependency auto‑patching, and bounty scope without a human running a checklist.
  • Write the security risk memo for a live deal and present it to corporate development and security leadership.

The annual compensation range for this role is listed below.

Annual Salary:

$320,000 - $485,000 USD

Logistics

Minimum education: Bachelor’s degree or an equivalent combination of education, training, and/or experience.

Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience.

Minimum years of experience: Years of experience required will correlate with the internal job level requirements for the position.

Location‑based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices.

Visa sponsorship: We do sponsor visas! However, we aren’t able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff+ Application Security Engineer - M&A
Staff+ Application Security Engineer - M&A

Anthropic • San Francisco (CA)

Hybrid
USD 320,000 - 485,000
Staff+ Application Security Engineer - M&A
Staff+ Application Security Engineer - M&A

Anthropic • New York (NY)

Hybrid
USD 320,000 - 485,000
Visa sponsorship
Staff+ Application Security Engineer - M&A
Staff+ Application Security Engineer - M&A

Visa Hunt • Seattle (WA), San Francisco (CA)

Hybrid
USD 320,000 - 485,000
Health insurance
Staff+ Application Security Engineer - M&A Anthropic Remote-Friendly (Travel-Required) | San Fr[...]
Staff+ Application Security Engineer - M&A Anthropic Remote-Friendly (Travel-Required) | San Fr[...]

Neura Market • San Francisco (CA), Northern (KY)

Hybrid
USD 320,000 - 485,000
Senior Engineer, Application Security
Senior Engineer, Application Security

Cvent • Tysons (VA)

Hybrid
USD 120,000 - 160,000
Bonus
Competitive benefits
Senior Engineer, Application Security
Senior Engineer, Application Security

Cvent, Inc. • Tysons (VA)

Hybrid
USD 120,000 - 160,000
Staff Application Security Engineer
Staff Application Security Engineer

United States Digital Space LLC • United States

Hybrid
USD 240,000 - 300,000
Up to four weeks of fully remote work per year
Security Engineer – Mergers and Acquisitions (M&A) – Metq Meta
Security Engineer – Mergers and Acquisitions (M&A) – Metq Meta

Isc2 Eastbay Chapter • Menlo Park (CA)

On-site
USD 184,000 - 257,000
Bonus
Equity
Benefits
Application Security Architect
Application Security Architect

Alarm.com • Tysons (VA)

On-site
USD 140,000 - 210,000
M&A AppSec Engineer - Due Diligence & Integration
M&A AppSec Engineer - Due Diligence & Integration

Anthropic • San Francisco (CA)

Hybrid
USD 320,000 - 485,000