🏢
Anthropic
Staff+ Application Security Engineer - M&A
Job Description
ABOUT THE ROLE
Anthropic's Application Security team is seeking a seasoned security professional to establish a dedicated function for securing acquisitions and integrating acquired systems. As the first dedicated role for security in M&A, you will formalize the security playbook, risk model, and tooling, and make them repeatable. This is an AppSec role first, with the expectation of automating repeatable parts of diligence and integration using Claude as the primary tool. When deal flow is quiet, you will pick up core AppSec project work.
WHAT YOU'LL DO
- Lead pre-close security due diligence on prospective acquisitions, coordinating external penetration testing, threat-modeling the target's architecture, assessing security controls, and delivering the security risk readout for leadership ahead of close and integration planning.
- Drive post-close security integration, standing up static and dynamic analysis coverage on acquired codebases, tracking high- and critical-severity remediation to closure, folding acquired assets into bug bounty scope, and onboarding repositories to Anthropic's automated vulnerability remediation and reporting systems.
- Coordinate adjacent security engineering teams on their portions of each integration.
- Work across a wide set of stakeholders on every deal, translating between them and keeping the security workstream legible to all.
- Formalize and scale Anthropic's M&A security playbook, risk-scoring model, diligence runbook, and integration checklist, and turn as much of it as possible into Claude-powered tooling rather than manual process.
- Share the team's operational on-run rotation, swapping out during periods of active deal work.
- Contribute to core AppSec projects between deals, including secure design reviews, threat modeling for agentic systems, and the team's security automation roadmap.
WHAT YOU'LL NEED
- Hands-on application and infrastructure security experience, including cloud and containerized environments.
- Demonstrated ability to rapidly assess an unfamiliar codebase or architecture and produce a clear, prioritized risk assessment for a non-security audience.
- Production-quality coding ability in at least one of Python, Go, Rust, or TypeScript.
- Practical threat-modeling and vulnerability-identification skills, with experience finding and reasoning about real bugs in real systems.
- Comfort operating with high autonomy, ambiguity, and tightly-held confidential context.
- Clear written and verbal communication across varied audiences, including executives, legal and corporate development partners, and engineering counterparts at an acquired company.
WHY REMOTE
This role is designed to be performed remotely, with the expectation of working independently and collaboratively with the Application Security team. You will be expected to automate repeatable parts of diligence and integration using Claude as the primary tool.
BENEFITS
The annual compensation range for this role is $180,000 - $250,000, with additional benefits to be discussed during the hiring process.