Staff+ Application Security EngineerActive$320K

The opportunity

Anthropic's Application Security team secures the systems that build, serve, and increasingly are Claude. The attack surface is unlike most AppSec work: multi-agent orchestration, sandboxed code execution, agents holding delegated credentials, untrusted tool output crossing…

What you'll do

  • Design, build, and operate Claude-powered security systems: LLM-driven code analysis, automated vulnerability remediation, AI-assisted threat modeling — and own one or more of them end-to-end, including the cross-functional relationships that come with it

  • Lead secure design reviews and threat modeling for novel AI systems,: identifying risks that don't map to existing frameworks

  • Evolve a public bug bounty program where automation handles routine triage: and root-cause work, and engineers handle escalations and corner cases

  • Partner with Product, Infrastructure, and Research teams as an embedded: security owner — consulting on launches, shaping architecture, and influencing decisions where security is the constraint

  • Share an operational on-run rotation with the rest of the team: bounty escalations, incident response, and launch consults on systems serving Claude in production

  • Hands-on application and infrastructure security experience, including cloud and containerized environments

What they're looking for

  • Production-quality coding ability in at least one of Python, Go, Rust, or: TypeScript, with a track record of building durable systems rather than one-off scripts
  • Practical threat-modeling and vulnerability-identification skills: you've found and reasoned about real bugs in real systems, even if breaking isn't your primary mode
  • Demonstrated ability to operate with high autonomy and ambiguity: comfortable being handed a problem and a lot of latitude rather than a spec
  • Clear technical communication with both engineers and leadership