The opportunity
Anthropic's Application Security team secures the systems that build, serve, and increasingly are Claude. The attack surface is unlike most AppSec work: multi-agent orchestration, sandboxed code execution, agents holding delegated credentials, untrusted tool output crossing…
What you'll do
Design, build, and operate Claude-powered security systems: LLM-driven code analysis, automated vulnerability remediation, AI-assisted threat modeling — and own one or more of them end-to-end, including the cross-functional relationships that come with it
Lead secure design reviews and threat modeling for novel AI systems,: identifying risks that don't map to existing frameworks
Evolve a public bug bounty program where automation handles routine triage: and root-cause work, and engineers handle escalations and corner cases
Partner with Product, Infrastructure, and Research teams as an embedded: security owner — consulting on launches, shaping architecture, and influencing decisions where security is the constraint
Share an operational on-run rotation with the rest of the team: bounty escalations, incident response, and launch consults on systems serving Claude in production
Hands-on application and infrastructure security experience, including cloud and containerized environments
What they're looking for
- Production-quality coding ability in at least one of Python, Go, Rust, or: TypeScript, with a track record of building durable systems rather than one-off scripts
- Practical threat-modeling and vulnerability-identification skills: you've found and reasoned about real bugs in real systems, even if breaking isn't your primary mode
- Demonstrated ability to operate with high autonomy and ambiguity: comfortable being handed a problem and a lot of latitude rather than a spec
- Clear technical communication with both engineers and leadership