Staff+ Application Security Engineer
Anthropic · Remote-Friendly (Travel-Required) | San Francisco, CA | Seattle, WA | New York City, NY · Security · listed January 22, 2025
The shape of it
Seniority
Staff
Where
Hybrid
Stated pay
$320,000 – $485,000 USD
Requirements listed
5
Length
1,225 words
In the posting’s own words
The way the team works is also different. We use Claude as our primary tool across every part of the job: it drives our static analysis, drafts and fixes vulnerabilities as pull requests, performs first-line bug bounty triage, and assists threat modeling for design reviews. The human work is the judgment layer — system-level reasoning, deciding what matters, and building the next thing the model can't do yet.
What it asks for · 5
- Hands-on application and infrastructure security experience, including cloud and containerized environments
- Production-quality coding ability in at least one of Python, Go, Rust, or TypeScript, with a track record of building durable systems rather than one-off scripts
- Practical threat-modeling and vulnerability-identification skills — you've found and reasoned about real bugs in real systems, even if breaking isn't your primary mode
- Demonstrated ability to operate with high autonomy and ambiguity — comfortable being handed a problem and a lot of latitude rather than a spec
- Clear technical communication with both engineers and leadership
Also a plus
- 7+ years in application security, security engineering, or security-focused software engineering
- Already use LLMs as a core part of how you work, with opinions about where they help and where they don't
- Experience securing agentic, code-execution, or LLM-integrated systems specifically
- Prior ownership of a bug bounty program, vulnerability disclosure program, or vulnerability-management infrastructure at scale
- Background building security automation or developer-facing security tooling
- Offensive security or penetration testing experience
What the job covers
- Design, build, and operate Claude-powered security systems — LLM-driven code analysis, automated vulnerability remediation, AI-assisted threat modeling — and own one or more of them end-to-end, including the cross-functional relationships that come with it
- Lead secure design reviews and threat modeling for novel AI systems, identifying risks that don't map to existing frameworks
- Evolve a public bug bounty program where automation handles routine triage and root-cause work, and engineers handle escalations and corner cases
- Partner with Product, Infrastructure, and Research teams as an embedded security owner — consulting on launches, shaping architecture, and influencing decisions where security is the constraint
- Share an operational on-run rotation with the rest of the team — bounty escalations, incident response, and launch consults on systems serving Claude in production
Tools and skills named
Security & compliance
- Security15×
- Threat modeling4×
- Penetration testing
Languages
- Go
- Python
- Rust
- TypeScript
Models & research
- LLM4×
Ways of working
- Cross-functional
- Testing
Frameworks
- REST
Words the posting leans on
- security14×
- systems10×
- vulnerability6×
- claude5×
- code5×
- engineers5×
- bug bounty4×
- rather4×
- threat modeling4×
- build3×
- building3×
- design reviews3×
- engineering3×
- every3×
- experience3×
- finds3×
Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.
The posting, your resume, and the gaps between them. One click loads all three.
More open at Anthropic
- Account Executive, AI NativeNew York City, NY; San Francisco, CA | New York City, NY
- Account Executive - DNBSingapore
- Account Executive, Public SectorSydney, Australia
- Account Executive - Public Sector (ASEAN)Singapore
- Account Executive, StartupsSan Francisco, CA | New York City, NY
- Accounting, Revenue Internal ControlsSan Francisco, CA | Seattle, WA