Staff+ Application Security Engineer
Staff Application Security Engineer focused on M&A due diligence and secure integration of acquired codebases and systems at Anthropic. Lead security assessments, risk readouts, post-close remediation and automation using Claude, while contributing to core AppSec work. Requires 7+ years AppSec experience, rapid codebase assessment skills, and coding ability.
About the job
Key Responsibilities
- Lead pre-close security due diligence on prospective acquisitions: coordinate external penetration testing, threat-model architecture, assess security controls, and deliver security risk readout for leadership.
- Drive post-close security integration: implement static/dynamic analysis, track remediation of high/critical issues, integrate into bug bounty, and onboard to automated vulnerability systems.
- Coordinate with adjacent security teams (supply chain, cloud, corporate, detection & response) on integration aspects.
- Work with diverse stakeholders including corporate development, legal, security leadership, internal engineering teams, and external counterparts at target companies; translate and keep security workstreams legible.
- Formalize and scale M&A security playbook (risk-scoring, runbooks, checklists) and automate with Claude-powered tooling.
- Participate in on-run rotation for bug bounty, launch consults, and incident response (with adjustments during active deals).
- Contribute to core AppSec projects between deals, including secure design reviews, threat modeling for agentic systems, and security automation.
Minimum Qualifications
- Hands-on application and infrastructure security experience, including cloud and containerized environments.
- Ability to rapidly assess unfamiliar codebases or architectures and produce clear, prioritized risk assessments for non-security audiences.
- Production-quality coding in at least one of: Python, Go, Rust, or TypeScript.
- Practical threat-modeling and vulnerability identification skills with experience finding and reasoning about real bugs.
- Comfort with high autonomy, ambiguity, and confidential contexts.
- Clear written and verbal communication across executives, legal, corporate development, and engineering audiences.
Preferred Qualifications
- 7+ years in application security, security consulting, or security architecture.
- Prior M&A security due diligence, third-party assessment, or technical due diligence experience.
- Experience standing up/scaling SAST/DAST, bug bounty, or vulnerability management across codebases.
- Track record building security automation/tooling.
- Familiarity using LLMs as core part of security workflow.
- Experience securing agentic, code-execution, or LLM-integrated systems.
Minimum Education
Bachelor’s degree or equivalent combination of education, training, and/or experience in a relevant field.
Skills
Application Security, Threat Modeling, Python, Go, Rust, TypeScript, Cloud Security, Container Security, SAST, DAST, Bug Bounty, Vulnerability Management, LLMs, Security Automation
Similar jobs
Security Engineering jobsOwn and scale IT general controls, access governance, segregation of duties, and audit readiness across enterprise applications. The role combines SOX expertise with AI-enabled continuous controls monitoring and requires 10+ years of controls, audit, or enterprise governance experience.
Build the GRC platform at Anthropic by designing data pipelines, integrations, and agentic LLM workflows that automate compliance evidence collection, policy-as-code, and real-time risk reporting across cloud, identity, HR, and CI/CD systems.
Staff Security Software Engineer leading identity and access strategy, architecture, and hands-on platform development across customer, employee, contractor, and agentic identities. Requires 10+ years of production software experience and deep expertise in identity and authorization systems.
Design and operate distributed, low-latency infrastructure that protects Reddit from DDoS attacks, bots, scraping, and other network threats. The role requires 7+ years of distributed-systems experience plus expertise in security, networking, and production operations.
Staff-level AppSec engineer building secure coding practices and vulnerability management for a commerce platform. Requires 6+ years in application security with deep AWS and Python experience.