Skip to main content
Anthropic
Anthropic

Staff+ Application Security Engineer

RemoteUnited States only
Published
Role
Security
Experience
Staff
Employment
Full-time
Company size
Startup
$320k–$485k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Anthropic is seeking a Staff+ Application Security Engineer to secure its AI systems, including Claude. This role involves designing and building LLM-powered security systems, leading threat modeling for novel AI systems, evolving a bug bounty program, and partnering with product and infrastructure teams. The ideal candidate has hands-on application and infrastructure security experience, production-quality coding skills in Python, Go, Rust, or TypeScript, and practical threat-modeling abilities. Experience with LLMs and securing agentic or LLM-integrated systems is preferred.

Core skills

LLMapplication security

Required skills

PythonGoRustTypeScript

Optional skills

LLMsagentic systemscode-execution systemsLLM-integrated systemsbug bounty programvulnerability disclosure programvulnerability-management infrastructuresecurity automation

What you'll do

  • Design, build, and operate Claude-powered security systems — LLM-driven code analysis, automated vulnerability remediation, AI-assisted threat modeling — and own one or more of them end-to-end, including the cross-functional relationships that come with it
  • Lead secure design reviews and threat modeling for novel AI systems, identifying risks that don't map to existing frameworks
  • Evolve a public bug bounty program where automation handles routine triage and root-cause work, and engineers handle escalations and corner cases
  • Partner with Product, Infrastructure, and Research teams as an embedded security owner — consulting on launches, shaping architecture, and influencing decisions where security is the constraint
  • Share an operational on-run rotation with the rest of the team — bounty escalations, incident response, and launch consults on systems serving Claude in production

What they require

  • Hands-on application and infrastructure security experience, including cloud and containerized environments
  • Production-quality coding ability in at least one of Python, Go, Rust, or TypeScript, with a track record of building durable systems rather than one-off scripts
  • Practical threat-modeling and vulnerability-identification skills — you've found and reasoned about real bugs in real systems, even if breaking isn't your primary mode
  • Demonstrated ability to operate with high autonomy and ambiguity — comfortable being handed a problem and a lot of latitude rather than a spec
  • Clear technical communication with both engineers and leadership
  • Minimum education: Bachelor’s degree or an equivalent combination of education, training, and/or experience
  • Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience
  • Minimum years of experience: Years of experience required will correlate with the internal job level requirements for the position
  • Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices.
  • We encourage you to apply even if you do not believe you meet every single qualification.
  • Not all strong candidates will meet every single qualification as listed.
  • Research shows that people who identify as being from underrepresented groups are more prone to experiencing imposter syndrome and doubting the strength of their candidacy, so we urge you not to exclude yourself prematurely and to submit an application if you're interested in this work.
  • We think AI systems like the ones we're building have enormous social and ethical implications. We think this makes representation even more important, and we strive to include a range of diverse perspectives on our team.
  • Preferred qualifications: 7+ years in application security, security engineering, or security-focused software engineering
  • Preferred qualifications: Already use LLMs as a core part of how you work, with opinions about where they help and where they don't
  • Preferred qualifications: Experience securing agentic, code-execution, or LLM-integrated systems specifically
  • Preferred qualifications: Prior ownership of a bug bounty program, vulnerability disclosure program, or vulnerability-management infrastructure at scale
  • Preferred qualifications: Background building security automation or developer-facing security tooling
  • Preferred qualifications: Offensive security or penetration testing experience

Benefits

  • Competitive compensation and benefits
  • Optional equity donation matching
  • Generous vacation and parental leave
  • Flexible working hours
  • A lovely office space in which to collaborate with colleagues

American artificial intelligence corporation

🇺🇸 United StatesArtificial IntelligenceStartupanthropic.com/

Details

Visa sponsorshipYes
$320k–$485k/yr