Staff+ Application Security Engineer - M&A

Anthropic
San Francisco, Seattle, New York
Workplace: RemoteFull timeUSD 320,000 - 485,000 annuallyFunction: CybersecurityEducation: bachelorsSkills: ["Communication","Stakeholder management","Risk assessment","Autonomy","Problem-solving"]

Own application security due diligence and post-close integration for acquisitions. Lead pre-close security assessments—coordinating penetration testing, threat modeling, and security control evaluation—then drive remediation through static/dynamic analysis, bug bounty integration, and automated vulnerability reporting. Partner across legal, corporate development, and engineering teams to formalize an M&A AppSec playbook and scale Claude-powered tooling, while supporting core AppSec projects between deals.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Anthropic
Anthropic
1 month ago

Staff+ Application Security Engineer - M&A

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 7 hours agoStatus: Live

Job Summary

Own application security due diligence and post-close integration for acquisitions. Lead pre-close security assessments—coordinating penetration testing, threat modeling, and security control evaluation—then drive remediation through static/dynamic analysis, bug bounty integration, and automated vulnerability reporting. Partner across legal, corporate development, and engineering teams to formalize an M&A AppSec playbook and scale Claude-powered tooling, while supporting core AppSec projects between deals.
Location: San Francisco, Seattle, New York
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Sr. Manager level

Key Responsibilities

  • •Lead pre-close security due diligence for acquisitions, including coordinating penetration testing, threat modeling, and security control assessment, and delivering leadership readouts ahead of close.
  • •Drive post-close security integration by standing up static/dynamic analysis, tracking high- and critical-severity remediation to closure, and onboarding acquired repositories to automated vulnerability remediation and reporting systems.
  • •Coordinate with adjacent security engineering teams (supply chain, cloud, corporate security, detection & response) on integration workstreams.
  • •Translate and coordinate across internal and external stakeholders on each deal to keep the security workstream legible to all parties.
  • •Formalize and scale an M&A security playbook (risk model, diligence runbook, integration checklist) and automate it with Claude-powered tooling.
Travel: Medium travel

Pay and Benefits

Salary: USD 320,000 - 485,000 annually
Perks:Paid LeaveParental Leave

Key Requirements

  • •Hands-on application and infrastructure security experience, including cloud and containerized environments.
  • •Rapidly assess unfamiliar codebases or architectures and produce clear, prioritized risk assessments for non-security audiences.
  • •Production-quality coding ability in at least one of Python, Go, Rust, or TypeScript.
  • •Practical threat modeling and vulnerability identification experience, finding and reasoning about real bugs.
  • •High autonomy and ability to operate with ambiguity and tightly held confidential context.
Education:Bachelor's
Skills:CommunicationStakeholder managementRisk assessmentAutonomyProblem-solving
Languages:English
Tech Stack:PythonGoRustTypeScriptClaudeLLMsSASTDASTBug bountyVulnerability managementPenetration testingStatic analysisDynamic analysis

Company Brief

Anthropic
Develops large-scale AI systems and safety research to create reliable, steerable, and interpretable AI assistants and models for commercial and research applications.
Industry: AI & Machine Learning
Company Size: Enterprise (1,001+ employees)
Growth: Scaleup
Valuation: Unicorn (USD 1B+)
Funding: Series C
Headquarters: San Francisco, United States
Founded: 2021
WebsiteLinkedIn