Technical Program Manager, Security (coordinated Vulnerability Disclosure)

Anthropic Anthropic · AI Frontier · San Francisco, CA · Technical Program Management

This role manages the program for disclosing software vulnerabilities discovered by Anthropic's AI tools, ensuring responsible disclosure at scale. It involves internal triage, external coordination with vendors and maintainers, and establishing metrics for program health. The role requires managing the lifecycle of AI-generated findings, from validation to public disclosure, and collaborating across security, legal, and product teams.

What you'd actually do

  1. Own end-to-end CVD program strategy and execution: Define and drive the roadmap for coordinated vulnerability disclosure, from AI-generated finding through maintainer notification, remediation tracking, and public disclosure. Ensure alignment with Anthropic’s security posture and RSP compliance requirements.
  2. Lead internal triage and quality assurance: Establish and manage the human review process that validates all AI-generated findings before external disclosure. Set minimum confidence thresholds, deduplicate against known CVEs, and ensure every report sent to a maintainer meets Anthropic’s quality bar.
  3. Design and operate tiered disclosure timelines: Implement severity-based disclosure windows with appropriate extension policies.
  4. Build and manage pacing and submission models: Develop rate-limiting frameworks that govern how many findings are submitted to each project, scaled to maintainer capacity and project size.
  5. Lead external coordination and partner engagement: Manage relationships with open-source maintainers and closed-source vendors. Serve as the primary point of contact for vulnerability coordination, including escalation when maintainers are unresponsive. Drive the phased rollout from initial trusted partners through broader open-source engagement.

Skills

Required

  • 10+ years of experience in cybersecurity, vulnerability management, or security operations, with at least 4+ years leading vulnerability disclosure, vulnerability management, or coordinated response programs
  • Deep understanding of coordinated vulnerability disclosure processes, including experience working with CERT/CC, MITRE CVE, or similar coordination bodies
  • Technical familiarity with vulnerability discovery tooling, static analysis, fuzzing infrastructure (e.g., OSS-Fuzz, CodeQL), and the triage workflows that turn raw findings into actionable reports
  • Experience engaging directly with open-source maintainers and understanding the dynamics of open-source project governance, contributor capacity, and maintainer burnout
  • Proven experience as a Technical Program Manager or similar role in a cybersecurity or technology-focused environment, with a track record of leading complex, cross-organizational programs to successful completion
  • Executive communication skills with demonstrated ability to influence decisions at the senior leadership and C-suite level
  • Ability to manage highly ambiguous problems and navigate challenges to achieve program objectives in a fast-paced, evolving environment
  • Strong collaboration skills with proven ability to partner across diverse technical and non-technical stakeholders including Security Engineering, Legal, Communications, and Product teams

Nice to have

  • Experience building vulnerability disclosure or coordinated response programs from the ground up in high-growth technol

What the JD emphasized

  • AI-powered discovery has changed that equation entirely
  • Claude can surface hundreds of findings in a single codebase in a single day
  • managing the consequences of finding them at unprecedented scale and speed
  • Own end-to-end CVD program strategy and execution
  • Lead internal triage and quality assurance
  • Build and manage pacing and submission models
  • Lead external coordination and partner engagement