Staff+ Application Security Engineer - M&A
Anthropic · Remote-Friendly (Travel-Required) | San Francisco, CA | Seattle, WA | New York City, NY · Security · listed July 10, 2026
The shape of it
Seniority
Staff
Where
Remote
Stated pay
$320,000 – $485,000 USD
Requirements listed
6
Length
1,353 words
In the posting’s own words
You'll own security due diligence and secure integration for Anthropic's acquisitions — assessing a target's security posture pre-close, writing the security risk readout for leadership, and after close, bringing acquired systems up to Anthropic's bar. Security has been part of every deal to date, but this is the first dedicated role for it: you'll formalize the playbook, the risk model, and the tooling, and make them repeatable.
What it asks for · 6
- Hands-on application and infrastructure security experience, including cloud and containerized environments
- Demonstrated ability to rapidly assess an unfamiliar codebase or architecture and produce a clear, prioritized risk assessment for a non-security audience
- Production-quality coding ability in at least one of Python, Go, Rust, or TypeScript
- Practical threat-modeling and vulnerability-identification skills — you've found and reasoned about real bugs in real systems
- Comfort operating with high autonomy, ambiguity, and tightly-held confidential context
- Clear written and verbal communication across varied audiences — executives, legal and corporate development partners, and engineering counterparts at an acquired company
Also a plus
- 7+ years in application security, security consulting, or security architecture
- Prior M&A security due diligence, third-party security assessment, or technical due diligence experience
- Experience standing up or scaling SAST/DAST, bug bounty, or vulnerability management coverage across multiple codebases
- Track record of building security automation or tooling rather than relying solely on manual review
- Familiarity with using LLMs as a core part of your security workflow
- Experience securing agentic, code-execution, or LLM-integrated systems
What the job covers
- Lead pre-close security due diligence on prospective acquisitions — coordinate external penetration testing, threat-model the target's architecture, assess security controls, and deliver the security risk readout for leadership ahead of close and integration planning
- Drive post-close security integration — stand up static and dynamic analysis coverage on acquired codebases, track high- and critical-severity remediation to closure, fold acquired assets into bug bounty scope, and onboard repositories to Anthropic's automated vulnerability remediation and reporting systems
- Coordinate adjacent security engineering teams (supply chain, cloud, corporate security, detection & response) on their portions of each integration
- Work across a wide set of stakeholders on every deal — corporate development, legal, security leadership, and the engineering teams inheriting acquired systems internally; engineering and security counterparts at the target company externally — translating between them and keeping the security workstream legible to all of them
- Formalize and scale Anthropic's M&A security playbook — risk-scoring model, diligence runbook, integration checklist — and turn as much of it as possible into Claude-powered tooling rather than manual process
- Share the team's operational on-run rotation (bug bounty escalations, launch consults, incident response), swapping out during periods of active deal work
- Contribute to core AppSec projects between deals — secure design reviews, threat modeling for agentic systems, and the team's security automation roadmap
Tools and skills named
Security & compliance
- Security30×
- Penetration testing
- Threat modeling
Languages
- Go
- Python
- Rust
- TypeScript
Models & research
- LLM3×
Operations & finance
- Supply chain
Product & design
- Roadmap
Ways of working
- Testing
Words the posting leans on
- security29×
- acquired7×
- systems7×
- codebase6×
- deal6×
- integration6×
- risk6×
- leadership5×
- acquisitions4×
- core4×
- due diligence4×
- engineering4×
- experience4×
- rather4×
- tooling4×
- active3×
Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.
The posting, your resume, and the gaps between them. One click loads all three.
More open at Anthropic
- Account Executive, AI NativeNew York City, NY; San Francisco, CA | New York City, NY
- Account Executive - DNBSingapore
- Account Executive, Public SectorSydney, Australia
- Account Executive - Public Sector (ASEAN)Singapore
- Accounting, Revenue Internal ControlsSan Francisco, CA | Seattle, WA
- AI Fluency Education LeadSan Francisco, CA | New York City, NY