资深+应用安全工程师 - 并购
Staff+ Application Security Engineer - M&A
关于 Anthropic
Anthropic 的使命是创建可靠、可解释且可引导的 AI 系统。我们希望 AI 对我们的用户以及整个社会都是安全且有益的。我们的团队是一支快速发展的由致力于研究、工程、政策专家和商业领袖组成的团队,共同构建有益的 AI 系统。
关于该职位
Anthropic 的应用安全团队负责保护构建、提供并日益成为 Claude 的系统——随着 Anthropic 的影响力扩大,该职责现在也扩展到我们从外部引入的公司和代码库。该职位将建立这一职能。
你将负责 Anthropic 收购的安全部署和安全整合——在交易完成前评估目标的安全态势,为管理层撰写安全风险报告,并在交易完成后将收购的系统提升至 Anthropic 的标准。安全一直是每笔交易的一部分,但这是首个专门为此设立的职位:你将制定标准化流程、风险模型和工具,并使其可重复执行。
这是一个应用安全(AppSec)职位。你将成为应用安全团队的活跃成员——遵循相同的流程、值班轮换和工具,与工程师一起保护 Anthropic 自己的代理产品界面。同样也有相同的要求:我们使用 Claude 作为主要工具,你需在尽职调查和整合过程中自动化可重复的部分,使每次收购都比上一次更容易。当交易不活跃时,你将参与核心应用安全项目工作;当交易活跃时,并购(M&A)将是你的首要任务。
我们坦诚地说明,这里的重心是并购而非核心产品安全。它更波动、更依赖评估,并且涉及保密、时间敏感的工作。如果你喜欢在时间压力下进入一个不熟悉的代码库,并将其转化为清晰的风险图景供管理层参考,这就是这份工作。
关键职责
- 领导潜在收购的交易前安全尽职调查——协调外部渗透测试,对目标架构进行威胁建模,评估安全控制措施,并在交易完成和整合规划前向管理层提交安全风险报告
- 推动交易后安全整合——在收购的代码库上建立静态和动态分析覆盖,跟踪高危和严重修复直至关闭,将收购资产纳入漏洞赏金范围,并将仓库接入 Anthropic 的自动化漏洞修复和报告系统
查看英文原文
About Anthropic
Anthropic’s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems.
About the role
Anthropic's Application Security team secures the systems that build, serve, and increasingly are Claude — and as Anthropic's footprint grows, that mandate now extends to companies and codebases we bring in from outside. This role establishes that function.
You'll own security due diligence and secure integration for Anthropic's acquisitions — assessing a target's security posture pre-close, writing the security risk readout for leadership, and after close, bringing acquired systems up to Anthropic's bar. Security has been part of every deal to date, but this is the first dedicated role for it: you'll formalize the playbook, the risk model, and the tooling, and make them repeatable.
This is an AppSec role first. You'll be an active member of the Application Security team — same rituals, same on-run rotation, same tooling, working alongside engineers securing Anthropic's own agentic product surfaces. The expectation is the same too: we use Claude as our primary tool, and you're expected to automate the repeatable parts of diligence and integration as you go, so each acquisition is easier than the last. When deal flow is quiet, you'll pick up core AppSec project work; when it's active, M&A is your priority.
We're upfront that the center of gravity here is M&A rather than core product security. It's burstier, more assessment-heavy, and operates on confidential, time-sensitive work. If you like parachuting into an unfamiliar codebase under time pressure and turning it into a clear risk picture for leadership, this is that job.
Key responsibilities
- Lead pre-close security due diligence on prospective acquisitions — coordinate external penetration testing, threat-model the target's architecture, assess security controls, and deliver the security risk readout for leadership ahead of close and integration planning
- Drive post-close security integration — stand up static and dynamic analysis coverage on acquired codebases, track high- and critical-severity remediation to closure, fold acquired assets into bug bounty scope, and onboard repositories to Anthropic's automated vulnerability remediation and reporting systems
- Coordinate adjacent security engineering teams (supply chain, cloud, corporate security, detection & response) on their portions of each integration
- Work across a wide set of stakeholders on every deal — corporate development, legal, security leadership, and the engineering teams inheriting acquired systems internally; engineering and security counterparts at the target company externally — translating between them and keeping the security workstream legible to all of them
- Formalize and scale Anthropic's M&A security playbook — risk-scoring model, diligence runbook, integration checklist — and turn as much of it as possible into Claude-powered tooling rather than manual process
- Share the team's operational on-run rotation (bug bounty escalations, launch consults, incident response), swapping out during periods of active deal work
- Contribute to core AppSec projects between deals — secure design reviews, threat modeling for agentic systems, and the team's security automation roadmap
Minimum qualifications
- Hands-on application and infrastructure security experience, including cloud and containerized environments
- Demonstrated ability to rapidly assess an unfamiliar codebase or architecture and produce a clear, prioritized risk assessment for a non-security audience
- Production-quality coding ability in at least one of Python, Go, Rust, or TypeScript
- Practical threat-modeling and vulnerability-identification skills — you've found and reasoned about real bugs in real systems
- Comfort operating with high autonomy, ambiguity, and tightly-held confidential context
- Clear written and verbal communication across varied audiences — executives, legal and corporate development partners, and engineering counterparts at an acquired company
Preferred qualifications
- 7+ years in application security, security consulting, or security architecture
- Prior M&A security due diligence, third-party security assessment, or technical due diligence experience
- Experience standing up or scaling SAST/DAST, bug bounty, or vulnerability management coverage across multiple codebases
- Track record of building security automation or tooling rather than relying solely on manual review
- Familiarity with using LLMs as a core part of your security workflow
- Experience securing agentic, code-execution, or LLM-integrated systems
Representative projects
- Point Anthropic's internal LLM-driven code analysis and AI-assisted scanning at an acquired repository nobody here has seen, and turn the output into a prioritized remediation plan in days rather than weeks
- Design the risk-scoring framework Anthropic uses to compare security posture across acquisitions of different shapes and sizes
- Build the automation that onboards an acquired codebase to Anthropic's vulnerability dashboard, dependency auto-patching, and bounty scope without a human running a checklist
- Write the security risk memo for a live deal and present it to corporate development and security leadership
The annual compensation range for this role is listed below.
For sales roles, the range provided is the role’s On Target Earnings ("OTE") range, meaning that the range includes both the sales commissions/sales bonuses target and annual base salary for the role.
Annual Salary:
$320,000—$485,000 USD
Logistics
Minimum education: Bachelor’s degree or an equivalent combination of education, training, and/or experience
Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience
Minimum years of experience: Years of experience required will correlate with the internal job level requirements for the position
Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices.
Visa sponsorship: We do sponsor visas! However, we aren't able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this.
We encourage you to apply even if you do not believe you meet every single qualification. Not all strong candidates will meet every single qualification as listed. Research shows that people who identify as being from underrepresented groups are more prone to experiencing imposter syndrome and doubting the strength of their candidacy, so we urge you not to exclude yourself prematurely and to submit an application if you're interested in this work. We think AI systems like the ones we're building have enormous social and ethical implications. We think this makes representation even more important, and we strive to include a range of diverse perspectives on our team.
Your safety matters to us. To protect yourself from potential scams, remember that Anthropic recruiters only contact you from @anthropic.com email addresses. In some cases, we may partner with vetted recruiting agencies who will identify themselves as working on behalf of Anthropic. Be cautious of emails from other domains. Legitimate Anthropic recruiters will never ask for money, fees, or banking information before your first day. If you're ever unsure about a communication, don't click any links—visit anthropic.com/careers directly for confirmed position openings.
How we're different
We believe that the highest-impact AI research will be big science. At Anthropic we work as a single cohesive team on just a few large-scale research efforts. And we value impact — advancing our long-term goals of steerable, trustworthy AI — rather than work on smaller and more specific puzzles. We view AI research as an empirical science, which has as much in common with physics and biology as with traditional efforts in computer science. We're an extremely collaborative group, and we host frequent research discussions to ensure that we are pursuing the highest-impact work at any given time. As such, we greatly value communication skills.
The easiest way to understand our research directions is to read our recent research. This research continues many of the directions our team worked on prior to Anthropic, including: GPT-3, Circuit-Based Interpretability, Multimodal Neurons, Scaling Laws, AI & Compute, Concrete Problems in AI Safety, and Learning from Human Preferences.
Come work with us!
Anthropic is a public benefit corporation headquartered in San Francisco. We offer competitive compensation and benefits, optional equity donation matching, generous vacation and parental leave, flexible working hours, and a lovely office space in which to collaborate with colleagues. Guidance on Candidates' AI Usage: Learn about our policy for using AI in our application process.