Skip to content
AnthropicAnthropic

Staff+ Application Security Engineer

Staff Application Security Engineer focused on M&A due diligence and secure integration of acquired codebases and systems at Anthropic. Lead security assessments, risk readouts, post-close remediation and automation using Claude, while contributing to core AppSec work. Requires 7+ years AppSec experience, rapid codebase assessment skills, and coding ability.

About the job

Key Responsibilities

  • Lead pre-close security due diligence on prospective acquisitions: coordinate external penetration testing, threat-model architecture, assess security controls, and deliver security risk readout for leadership.
  • Drive post-close security integration: implement static/dynamic analysis, track remediation of high/critical issues, integrate into bug bounty, and onboard to automated vulnerability systems.
  • Coordinate with adjacent security teams (supply chain, cloud, corporate, detection & response) on integration aspects.
  • Work with diverse stakeholders including corporate development, legal, security leadership, internal engineering teams, and external counterparts at target companies; translate and keep security workstreams legible.
  • Formalize and scale M&A security playbook (risk-scoring, runbooks, checklists) and automate with Claude-powered tooling.
  • Participate in on-run rotation for bug bounty, launch consults, and incident response (with adjustments during active deals).
  • Contribute to core AppSec projects between deals, including secure design reviews, threat modeling for agentic systems, and security automation.

Minimum Qualifications

  • Hands-on application and infrastructure security experience, including cloud and containerized environments.
  • Ability to rapidly assess unfamiliar codebases or architectures and produce clear, prioritized risk assessments for non-security audiences.
  • Production-quality coding in at least one of: Python, Go, Rust, or TypeScript.
  • Practical threat-modeling and vulnerability identification skills with experience finding and reasoning about real bugs.
  • Comfort with high autonomy, ambiguity, and confidential contexts.
  • Clear written and verbal communication across executives, legal, corporate development, and engineering audiences.

Preferred Qualifications

  • 7+ years in application security, security consulting, or security architecture.
  • Prior M&A security due diligence, third-party assessment, or technical due diligence experience.
  • Experience standing up/scaling SAST/DAST, bug bounty, or vulnerability management across codebases.
  • Track record building security automation/tooling.
  • Familiarity using LLMs as core part of security workflow.
  • Experience securing agentic, code-execution, or LLM-integrated systems.

Minimum Education

Bachelor’s degree or equivalent combination of education, training, and/or experience in a relevant field.

Skills

Application Security, Threat Modeling, Python, Go, Rust, TypeScript, Cloud Security, Container Security, SAST, DAST, Bug Bounty, Vulnerability Management, LLMs, Security Automation

Gusto

Gusto

San Francisco, CA

Senior Staff IT Controls, Enterprise Applications
$245k+/yrHybrid10+ YOESecurity Engineering

Own and scale IT general controls, access governance, segregation of duties, and audit readiness across enterprise applications. The role combines SOX expertise with AI-enabled continuous controls monitoring and requires 10+ years of controls, audit, or enterprise governance experience.

Anthropic

Anthropic

San Francisco, CA
Staff+ Software Engineer, GRC Platform
$405k+/yrHybrid8+ YOESecurity Engineering

Build the GRC platform at Anthropic by designing data pipelines, integrations, and agentic LLM workflows that automate compliance evidence collection, policy-as-code, and real-time risk reporting across cloud, identity, HR, and CI/CD systems.

Harvey

Harvey

San Francisco, CA

Staff Security Software Engineer, IAM
$231k+/yrHybrid10+ YOESecurity Engineering

Staff Security Software Engineer leading identity and access strategy, architecture, and hands-on platform development across customer, employee, contractor, and agentic identities. Requires 10+ years of production software experience and deep expertise in identity and authorization systems.

Reddit

Reddit

United States

Staff Software Engineer - Site Defense
$217k+/yrRemote7+ YOESecurity Engineering

Design and operate distributed, low-latency infrastructure that protects Reddit from DDoS attacks, bots, scraping, and other network threats. The role requires 7+ years of distributed-systems experience plus expertise in security, networking, and production operations.

Upside

Upside

Washington, DC
Staff Application Security Engineer
$210k+/yrRemote6+ YOESecurity Engineering

Staff-level AppSec engineer building secure coding practices and vulnerability management for a commerce platform. Requires 6+ years in application security with deep AWS and Python experience.