🏢
Anthropic
Head of Vulnerability Disclosure & Security Community
Job Description
ABOUT THE ROLE
Anthropic is building reliable, interpretable, and steerable AI systems that benefit users and society. As Head of Vulnerability Disclosure & Security Community you will lead the organization’s coordinated vulnerability disclosure program, oversee the CVE Numbering Authority, and shape how model‑level vulnerabilities are identified, reported, and remediated. Your work will directly influence model release decisions and policy, ensuring that Anthropic’s AI systems remain safe, trustworthy, and aligned with industry best practices. You will serve as the public face of Anthropic’s security community, representing the company at conferences, in research forums, and to government and industry partners.
WHAT YOU'LL DO
- Own and operate Anthropic’s public coordinated‑disclosure jailbreak program from intake through resolution.
- Lead the CVE Numbering Authority function, authoring CVEs and maintaining compliance with NIST and other standards.
- Build and nurture partnerships with external security researchers, open‑source maintainers, and threat‑intelligence organizations.
- Represent Anthropic at security conferences, workshops, and in media engagements, articulating our disclosure policy and security posture.
- Collaborate with the Senior Cyber Policy Lead to embed disclosure findings into risk assessments, model‑release criteria, and policy frameworks.
- Design and scale the program’s tooling, including AI‑assisted triage, severity assessment, and workflow automation.
- Recruit, mentor, and grow a high‑performance analyst team that can sustain a growing disclosure pipeline.
WHAT YOU'LL NEED
- Proven experience operating or participating in a coordinated vulnerability disclosure program, including multi‑party coordination with researchers, vendors, and open‑source projects.
- Demonstrated ability to manage a disclosure queue with clear triage and response timelines, handling TLP‑marked and embargoed information.
- Strong background in PSIRT operations, CVE authoring, and public vulnerability reporting.
- Familiarity with government disclosure requirements and experience engaging with regulatory bodies.
- Excellent communication skills, able to translate technical findings into policy recommendations and public messaging.
- Strategic mindset, capable of shaping disclosure policy, setting timelines, and aligning the program with industry norms.
- Experience integrating AI or automation into vulnerability triage, severity scoring, or report handling is highly desirable.
WHY REMOTE
Anthropic values a distributed, asynchronous culture that empowers teams to work from anywhere while maintaining high levels of collaboration. Remote work allows you to balance a flexible schedule with the need for focused, deep work on complex security challenges. We provide the tools and support to keep you connected—virtual collaboration platforms, secure VPN access, and regular virtual town halls—so you can engage with colleagues, researchers, and partners across the globe without geographic constraints. Whether you are in a quiet home office or a bustling city, you will have the autonomy to manage your time and deliver results at the pace that suits your workflow.
BENEFITS
Compensation: $330,000–$395,000 USD annually, commensurate with experience.
Comprehensive health, dental, and vision coverage for you and your dependents.
Generous paid time off