Staff+ Application Security Engineer - M&A
Remote • Remote-Friendly (Travel-Required) | San Francisco, CA | Seattle, WA | New York City, NY
Posted 16d ago
About the job
Anthropic's Application Security team is responsible for securing the systems that build, serve, and operate Claude. This role will establish and lead the security due diligence and integration function for Anthropic's acquisitions. You will assess target companies' security postures pre-close, provide security risk assessments to leadership, and ensure acquired systems meet Anthropic's security standards post-close. This is a dedicated role to formalize the M&A security playbook, risk model, and tooling, making the process repeatable and scalable. While the primary focus is M&A security, you will also be an active member of the Application Security team, participating in team rituals, on-call rotations, and contributing to core AppSec projects when deal flow is quiet. The role requires comfort with ambiguity, time-sensitive work, and the ability to quickly assess unfamiliar systems under pressure.
Responsibilities
- Lead pre-close security due diligence for prospective acquisitions, including coordinating penetration testing, threat modeling, and assessing security controls.
- Deliver security risk readouts to leadership for acquisition targets.
- Drive post-close security integration, including implementing SAST/DAST, managing remediation, and onboarding assets to bug bounty programs.
- Coordinate with various security engineering teams (supply chain, cloud, etc.) on integration efforts.
- Collaborate with diverse stakeholders, including corporate development, legal, and engineering teams, to ensure clear communication and progress on security workstreams.
- Formalize and scale Anthropic's M&A security playbook, including risk scoring, diligence processes, and integration checklists.
- Develop Claude-powered tooling to automate M&A security processes.
- Participate in the Application Security team's on-call rotation and core AppSec projects, such as secure design reviews and threat modeling.
- Contribute to the team's security automation roadmap.
Requirements
- Hands-on experience in application and infrastructure security, including cloud and containerized environments.
- Ability to rapidly assess unfamiliar codebases or architectures and produce clear, prioritized risk assessments.
- Proficiency in at least one of Python, Go, Rust, or TypeScript for production-quality coding.
- Practical threat modeling and vulnerability identification skills.
- Comfort operating with high autonomy, ambiguity, and confidential information.
- Strong written and verbal communication skills for diverse audiences.
- Experience building security automation or tooling.