Anthropic

Staff+ Application Security Engineer

$320K–$485KFull-time · Remote-Friendly (Travel-Required) +3 more
✓ Verified live on the employer's own system · added 564 days ago
Save search
Senior · 7+ yrs exp

Requirements

Experience: 7+ years

Skills & tools

SecurityHiringMachine LearningRoot Cause AnalysisOperationsProgrammingPythonRust
Apply on company site ↗ See your fit → free

Full job description

Anthropic's Application Security team secures the systems that build, serve, and increasingly are Claude. The attack surface is unlike most AppSec work: multi-agent orchestration, sandboxed code execution, agents holding delegated credentials, untrusted tool output crossing trust boundaries - problems with little prior art and no off-the-shelf playbook.

The way the team works is also different. We use Claude as our primary tool across every part of the job: it drives our static analysis, drafts and fixes vulnerabilities as pull requests, performs first-line bug bounty triage, and assists threat modeling for design reviews. The human work is the judgment layer - system-level reasoning, deciding what matters, and building the next thing the model can't do yet.

This is a builder's role on a senior team. We hire engineers who ship production systems and clear a hands-on threat-modeling bar - people who can find the vulnerability but would rather build the system that finds them all. Every engineer owns a system end-to-end, and the team's work has shaped customer-facing product security - including Claude Code's security review tooling, its security guidance plugin, sandboxing, and auto mode.

- Design, build, and operate Claude-powered security systems - LLM-driven code analysis, automated vulnerability remediation, AI-assisted threat modeling - and own one or more of them end-to-end, including the cross-functional relationships that come with it

- Lead secure design reviews and threat modeling for novel AI systems, identifying risks that don't map to existing frameworks

- Evolve a public bug bounty program where automation handles routine triage and root-cause work, and engineers handle escalations and corner cases

- Partner with Product, Infrastructure, and Research teams as an embedded security owner - consulting on launches, shaping architecture, and influencing decisions where security is the constraint

- Share an operational on-run rotation with the rest of the team - bounty escalations, incident response, and launch consults on systems serving Claude in production

- Hands-on application and infrastructure security experience, including cloud and containerized environments

- Production-quality coding ability in at least one of Python, Go, Rust, or TypeScript, with a track record of building durable systems rather than one-off scripts

- Practical threat-modeling and vulnerability-identification skills - you've found and reasoned about real bugs in real systems, even if breaking isn't your primary mode

- Demonstrated ability to operate with high autonomy and ambiguity - comfortable being handed a problem and a lot of latitude rather than a spec

- Clear technical communication with both engineers and leadership

- 7+ years in application security, security engineering, or security-focused software engineering

- Already use LLMs as a core part of how you work, with opinions about where they help and where they don't

- Experience securing agentic, code-execution, or LLM-integrated systems specifically

- Prior ownership of a bug bounty program, vulnerability disclosure program, or vulnerability-management infrastructure at scale

- Background building security automation or developer-facing security tooling

- An increasingly autonomous vulnerability pipeline - LLM-driven code analysis finds the issue, scores it for real exploitability, and opens the fix PR, with humans as the review step rather than the author

- Bug bounty operations where Claude handles first-line triage and drafting, and engineers focus on the reports that actually need judgment

- AI-assisted threat modeling that generates intake questions, drafts the model, and recommends which design reviews need a human in the room

- Automated dependency vulnerability remediation across Anthropic's codebase

- The company-wide vulnerability dashboard and SLA enforcement layer every engineering team works against

- Threat models and security architecture for agentic product surfaces - code execution sandboxing, agent identity and delegated auth, tool-use boundaries

More jobs at Anthropic

Similar jobs near Remote-Friendly (Travel-Required) +3 more

Tell me when more Staff Application Security Engineer jobs post near San Francisco (Remote) We re-check every listing against the employer’s own board — no résumé needed.

Search Staff+ Application Security Engineer jobs near Remote-Friendly (Travel-Required) +3 more → Browse all live jobs

This posting was published by Anthropic on their own careers system and is shown here with a direct link to apply there. Employers: for corrections or removal, contact jobs@veritahire.com.