The opportunity
We're looking for a Head of Vulnerability Disclosure & Security Community to own Anthropic's coordinated vulnerability disclosure program and our CVE Numbering Authority (CNA) end to end, including our public coordinated-disclosure jailbreak program. You will have the authority…
What you'll do
Own and operate Anthropic's public, coordinated-disclosure jailbreak program end-to-end
Lead Anthropic's CVE Numbering Authority (CNA) function for vulnerability: disclosure, including in open-source contexts
Build and maintain partnerships with the external security research community: and threat-intelligence organizations
Represent Anthropic at security conferences and within the broader vulnerability-research community
Maintain close familiarity with vulnerability-database ecosystems to keep our: program aligned with industry norms
Lead Anthropic's external technical engagement on cyber safety topics,: including public and community-facing communication
What they're looking for
- Experience running or working inside a PSIRT
- Experience coordinating disclosures that include government parties
- A track record of authoring CVEs or vulnerability disclosures
- Experience presenting original research at security conferences
- Experience operating or supporting a CNA (CVE Numbering Authority), either: internally or on behalf of third parties
- Experience incorporating artificial intelligence into coordinated: vulnerability disclosure or CNA processes, such as automated triage, severity assessment, or report handling
- Experience operating or scaling a bug bounty program through a commercial platform
- Established relationships across the disclosure coordination community and programs