# Head of Vulnerability Disclosure & Security Community

**Company:** [Anthropic](https://hotfix.jobs/companies/anthropic)
**Location:** New York, NY, San Francisco, CA, Washington, DC
**Role:** Security Engineering
**Salary:** $330k – $395k/yr
**Experience:** 8+ years
**Skills:** Coordinated Vulnerability Disclosure, Cve, Cna, Psirt, Vulnerability Triage, Vulnerability Databases, Threat Intelligence, Bug Bounty Programs, Security Research, Cyber Safety, Artificial Intelligence, Tlp
**Posted:** 2026-08-21

> Leads Anthropic’s coordinated vulnerability disclosure and CNA programs, including jailbreak disclosures, external researcher partnerships, public communication, and AI-assisted triage. The role requires disclosure coordination, vulnerability-response operations, and security-community engagement experience.

## Job Description

## Responsibilities
- Own and operate Anthropic’s public coordinated-disclosure jailbreak program end to end.
- Lead Anthropic’s CVE Numbering Authority (CNA) function, including disclosures involving open-source contexts.
- Build and maintain partnerships with external security researchers and threat-intelligence organizations.
- Represent Anthropic at security conferences and in the broader vulnerability-research community.
- Maintain familiarity with vulnerability-database ecosystems and industry norms.
- Lead external technical engagement on cyber safety topics, including public and community-facing communication.
- Collaborate with the Senior Cyber Policy Lead so disclosure findings inform evaluations and policy.
- Build the function by hiring and mentoring an analyst and implementing tooling and AI-assisted triage.

## Requirements
- Experience operating or participating in a coordinated vulnerability disclosure program.
- Experience coordinating multi-party disclosures involving researchers, vendors, and open-source maintainers.
- Experience managing a disclosure queue with defined triage and response timelines.
- Experience handling sensitive or embargoed vulnerability information, including TLP-marked material.
- Bachelor’s degree or equivalent combination of education, training, and experience in a relevant field.

## Nice-to-haves
- Experience running or working inside a PSIRT.
- Experience coordinating disclosures involving government parties.
- Track record of authoring CVEs or vulnerability disclosures.
- Experience presenting original research at security conferences.
- Experience operating or supporting a CNA.
- Experience incorporating AI into vulnerability disclosure or CNA processes, such as automated triage, severity assessment, or report handling.
- Experience operating or scaling a bug bounty program through a commercial platform.
- Established relationships across the disclosure coordination community and its programs.

## Compensation
- Annual salary: **$330,000–$395,000 USD**.
- Benefits include competitive compensation, optional equity donation matching, generous vacation and parental leave, flexible working hours, and office collaboration space.

## Similar jobs

- [Head of Security](https://hotfix.jobs/jobs/45cddafa-6b3c-44a3-9c56-db1964a9e710) - Exa - San Francisco, CA - $250k – $350k/yr
- [Director of Product Security](https://hotfix.jobs/jobs/123c400d-2a94-464c-922f-220de7c89131) - Idme - Mountain View, CA - $244k – $272k/yr
- [Director, Information Security & Technology](https://hotfix.jobs/jobs/206a3607-4d09-42a8-8ff7-ff8d9b3096f3) - GameChanger - Remote - $220k – $240k/yr
- [Head of Information Security & IT](https://hotfix.jobs/jobs/98a87854-ad33-42f1-9397-7da08267b0d2) - Chronograph - Brooklyn, NY - $215k – $250k/yr
- [Director, Cybersecurity](https://hotfix.jobs/jobs/845df48d-ee3b-40c5-822e-d5f01842dbc3) - LogicGate - Chicago, IL - $190k – $240k/yr

**Apply:** https://hotfix.jobs/jobs/785e032d-5f93-4f31-b52b-5c2ee76ef1d7
**Canonical:** https://hotfix.jobs/jobs/785e032d-5f93-4f31-b52b-5c2ee76ef1d7