Head of Vulnerability Disclosure & Security Community
Leads Anthropic’s coordinated vulnerability disclosure and CNA programs, including jailbreak disclosures, external researcher partnerships, public communication, and AI-assisted triage. The role requires disclosure coordination, vulnerability-response operations, and security-community engagement experience.
About the job
Responsibilities
- Own and operate Anthropic’s public coordinated-disclosure jailbreak program end to end.
- Lead Anthropic’s CVE Numbering Authority (CNA) function, including disclosures involving open-source contexts.
- Build and maintain partnerships with external security researchers and threat-intelligence organizations.
- Represent Anthropic at security conferences and in the broader vulnerability-research community.
- Maintain familiarity with vulnerability-database ecosystems and industry norms.
- Lead external technical engagement on cyber safety topics, including public and community-facing communication.
- Collaborate with the Senior Cyber Policy Lead so disclosure findings inform evaluations and policy.
- Build the function by hiring and mentoring an analyst and implementing tooling and AI-assisted triage.
Requirements
- Experience operating or participating in a coordinated vulnerability disclosure program.
- Experience coordinating multi-party disclosures involving researchers, vendors, and open-source maintainers.
- Experience managing a disclosure queue with defined triage and response timelines.
- Experience handling sensitive or embargoed vulnerability information, including TLP-marked material.
- Bachelor’s degree or equivalent combination of education, training, and experience in a relevant field.
Nice-to-haves
- Experience running or working inside a PSIRT.
- Experience coordinating disclosures involving government parties.
- Track record of authoring CVEs or vulnerability disclosures.
- Experience presenting original research at security conferences.
- Experience operating or supporting a CNA.
- Experience incorporating AI into vulnerability disclosure or CNA processes, such as automated triage, severity assessment, or report handling.
- Experience operating or scaling a bug bounty program through a commercial platform.
- Established relationships across the disclosure coordination community and its programs.
Compensation
- Annual salary: $330,000–$395,000 USD.
- Benefits include competitive compensation, optional equity donation matching, generous vacation and parental leave, flexible working hours, and office collaboration space.
Skills
Coordinated Vulnerability Disclosure, Cve, Cna, Psirt, Vulnerability Triage, Vulnerability Databases, Threat Intelligence, Bug Bounty Programs, Security Research, Cyber Safety, Artificial Intelligence, Tlp
Similar jobs
Security Engineering jobsLeads Exa’s company-wide security strategy, architecture, engineering, governance, incident response, and team development across AI infrastructure, cloud, products, and corporate systems. Requires executive-level security accountability and deep technical credibility in a rapidly scaling technology company.
Leads ID.me’s Product Security program and security engineering team, partnering with Product and Engineering to reduce risk through practical, developer-aligned controls. Requires strong technical depth across application and cloud security, outcome-based leadership, and experience building security programs in fast-moving cloud-native environments.
Leads GameChanger’s Information Security and Technology strategy, teams, roadmap, and risk decisions, with primary focus on product and application security. Requires 10+ years of security experience, broad security-program leadership, and experience managing technical leaders and partnering with Engineering and executives.
Leads Chronograph’s information security and IT strategy, combining executive leadership with hands-on oversight of cloud, application, AI, corporate, and compliance security. Requires at least seven years of security experience, broad technical depth, assurance-program leadership, and strong executive communication.
Leads LogicGate’s internal security organization, compliance posture, risk management, and customer trust program while serving as Deputy CISO. Requires 7–10 years of information security experience, substantial people leadership, SaaS compliance expertise, and strong technical knowledge of modern security architectures.