Staff+ Application Security Engineer
Remote • Remote-Friendly (Travel-Required) | San Francisco, CA | Seattle, WA | New York City, NY
Posted 16d ago
About the job
Anthropic is building reliable, interpretable, and steerable AI systems to be safe and beneficial for users and society. The Application Security team plays a crucial role in integrating security throughout the software development lifecycle. In this hands-on technical role, you will collaborate with software engineers and researchers to embed security from design to implementation. You will lead threat modeling and secure design reviews, proactively identify and mitigate risks, and build tools to support secure coding practices. Your work will influence our tooling, detection capabilities, and defenses against emerging AI/ML threats, while also developing standards, processes, and educational resources to empower all engineers as security champions. This role requires a security practitioner with an attacker's mindset, a developer's perspective, and strong relationship-building skills.
Responsibilities
- Help secure AI products and internal tools facing novel security risks.
- Lead "shift left" security efforts to integrate security into the software development lifecycle.
- Conduct secure design reviews and threat modeling to identify and prioritize risks, attack surfaces, and vulnerabilities.
- Develop tooling to scale security code reviews and advise developers on vulnerability remediation and secure coding practices.
- Manage the vulnerability management program, including data ingestion, prioritization logic, and developing automated remediation systems.
- Oversee the bug bounty program, including scope setting, submission validation, root cause analysis, remediation coordination, and bounty awards.
- Collaborate with product engineers and researchers to instill security best practices and advocate for secure architecture, design, and development.
- Develop and document security policies, standards, and playbooks, and conduct security awareness training for engineers.
Requirements
- 7+ years of hands-on experience in application and infrastructure security, including securing cloud-based and containerized environments.
- Strong proficiency in at least one programming language (e.g., Python, Rust, Go, Java).
- Ability to lead with empathy, a collaborative spirit, and a learning mindset to work cross-functionally with engineers.
- Creative and strategic thinking to reduce risk through secure design and simplicity.
- Broad security knowledge to identify holistic ways to decrease the overall threat surface.
- Ability to distill complex security concepts into clear actions and drive consensus.
- Proactive mindset to integrate security throughout the product lifecycle via threat modeling, secure code review, and education.
- Strong grasp of offensive security to anticipate risks from an adversary's perspective.
- Experience with modern application stacks, infrastructure, and security tools.
- Practiced at collaborating cross-functionally and balancing security requirements with business objectives.
- Advocate for security fundamentals like least privilege, defense-in-depth, and eliminating complexity.