Staff+ Application Security Engineer
Job description
About the role
Anthropic is building a dedicated function for acquisition security within its Application Security organization, and this role owns that mandate from end to end. You will lead pre-close security due diligence on prospective acquisitions, coordinating external penetration testing and threat modeling while producing a concise security risk readout for leadership. Post-close, you will drive integration by standing up static and dynamic analysis coverage, tracking remediation for high- and critical-severity findings, and folding acquired assets into Anthropic's bug bounty scope. You will formalize and scale the M&A security playbook, including the risk-scoring model, diligence runbook, and integration checklist, and turn as much of this as possible into Claude-powered tooling instead of manual effort. This is an AppSec role first, and you will be an active member of the existing team, attending the same on-run rotation and using the same tooling while securing Anthropic's own agentic product surfaces. The position is bursty and assessment-heavy, centered on confidential, time-sensitive work where you parachute into unfamiliar codebases under pressure and deliver a clear risk picture. When deal flow is quiet, you will pick up core AppSec project work; when it is active, M&A is your priority.
Key facts
What you'll do
Lead pre-close security due diligence on prospective acquisitions by coordinating external penetration testing, threat-modeling the target architecture, assessing security controls, and delivering a security risk readout for leadership ahead of close and integration planning.
Drive post-close security integration by standing up static and dynamic analysis coverage on acquired codebases, tracking high- and critical-severity remediation to closure, folding acquired assets into bug bounty scope, and onboarding repositories to Anthropic's automated vulnerability remediation and reporting systems.
Coordinate adjacent security engineering teams including supply chain, cloud, corporate security, detection and response on their portions of each integration.
Work across a wide set of stakeholders on every deal, including corporate development, legal, security leadership, and engineering teams inheriting acquired systems internally, as well as engineering and security counterparts at the target company externally, translating between them and keeping the security workstream legible to all of them.
Formalize and scale Anthropic's M&A security playbook by defining the risk-scoring model, diligence runbook, and integration checklist, and turn as much of it as possible into Claude-powered tooling rather than manual process.
Share the team's operational on-run rotation, handling bug bounty escalations and launch consults, and swapping out during periods of active deal work.
Contribute to core AppSec projects between deals, including secure design reviews, threat modeling for agentic systems, and the team's security automation roadmap.
Establish security due diligence as a repeatable, standardized function within Anthropic's M&A lifecycle.
Maintain clear documentation of findings, decisions, and remediation plans so that leadership and acquired teams can act on them without ambiguity.
Support the security integration during active deal windows, prioritizing high-impact fixes and ensuring that acquired systems meet Anthropic's bar before deeper integration.
Own the communication of security tradeoffs and risk acceptance decisions to both technical and executive audiences.
Continuously look for ways to automate repetitive security tasks during integrations, leveraging Claude and existing tooling to reduce manual effort for each acquisition.
Requirements
Hands-on application and infrastructure security experience, including cloud and containerized environments.
Demonstrated ability to rapidly assess an unfamiliar codebase or architecture and produce a clear, prioritized risk assessment for a non-security audience.
Production-quality coding ability in at least one of Python, Go, Rust, or TypeScript.
Practical threat-modeling and vulnerability-identification skills, evidenced by having found and reasoned about real bugs in real systems.
Comfort operating with high autonomy, ambiguity, and tightly-held confidential context.
Clear written and verbal communication across varied audiences, including executives, legal and corporate development partners, and engineering counterparts at an acquired company.
Nice to have
Only items explicitly indicated as preferred in the source are included, and no additional preferences are added.
Practical notes
The role operates under the constraints listed in the source, including location flexibility with travel requirements, engagement details as specified, and compensation as noted. No additional benefits, hours, or policies are introduced beyond what is stated in the source material.