Staff+ Application Security Engineer - M&a

Anthropic Anthropic · AI Frontier · United States · Remote · Security

This role focuses on Application Security within the context of Mergers & Acquisitions (M&A) for an AI company. The primary responsibility is to conduct security due diligence on target companies before acquisition and ensure secure integration of acquired systems post-close. While the role is AppSec-focused, it heavily leverages AI tools (like Claude) for automation and analysis, and contributes to core AppSec projects, including securing agentic systems. The role involves formalizing M&A security processes and building related tooling.

What you'd actually do

  1. Lead pre-close security due diligence on prospective acquisitions — coordinate external penetration testing, threat-model the target's architecture, assess security controls, and deliver the security risk readout for leadership ahead of close and integration planning
  2. Drive post-close security integration — stand up static and dynamic analysis coverage on acquired codebases, track high- and critical-severity remediation to closure, fold acquired assets into bug bounty scope, and onboard repositories to Anthropic's automated vulnerability remediation and reporting systems
  3. Formalize and scale Anthropic's M&A security playbook — risk-scoring model, diligence runbook, integration checklist — and turn as much of it as possible into Claude-powered tooling rather than manual process
  4. Contribute to core AppSec projects between deals — secure design reviews, threat modeling for agentic systems, and the team's security automation roadmap

Skills

Required

  • Application and infrastructure security experience
  • Cloud and containerized environments
  • Rapidly assess an unfamiliar codebase or architecture
  • Produce a clear, prioritized risk assessment for a non-security audience
  • Python, Go, Rust, or TypeScript coding ability
  • Threat modeling
  • Vulnerability identification
  • High autonomy
  • Ambiguity
  • Confidential context handling
  • Written and verbal communication

Nice to have

  • 7+ years in application security, security consulting, or security architecture
  • Prior M&A security due diligence, third-party security assessment, or technical due diligence experience
  • Standing up or scaling SAST/DAST, bug bounty, or vulnerability management coverage
  • Building security automation or tooling
  • Using LLMs as a core part of your security workflow
  • Securing agentic, code-execution, or LLM-integrated systems

What the JD emphasized

  • AppSec role first
  • M&A rather than core product security
  • burstier, more assessment-heavy
  • parachuting into an unfamiliar codebase under time pressure
  • Production-quality coding ability in at least one of Python, Go, Rust, or TypeScript
  • Practical threat-modeling and vulnerability-identification skills
  • Comfort operating with high autonomy, ambiguity, and tightly-held confidential context
  • Familiarity with using LLMs as a core part of your security workflow
  • Experience securing agentic, code-execution, or LLM-integrated systems