# Staff+ Application Security Engineer  - M&A

**Company**: Anthropic
**Location**: San Francisco, CA
**Work arrangement**: remote
**Experience**: staff
**Job type**: full-time
**Salary**: $320,000-$485,000 USD
**Category**: Engineering
**Industry**: Technology
**Wikidata**: https://www.wikidata.org/wiki/Q116758847

**Apply**: https://job-boards.greenhouse.io/anthropic/jobs/5311463008?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_4743aff3-e2c

## Description

## Job Overview

You'll join Anthropic's Application Security team as a Staff+ Application Security Engineer, focusing on M&A activities. Your primary responsibility will be to establish and lead the security due diligence and secure integration process for Anthropic's acquisitions.

## Key Responsibilities

- Lead pre-close security due diligence on prospective acquisitions, including coordinating external penetration testing, threat modeling, and assessing security controls.

- Drive post-close security integration, such as setting up static and dynamic analysis coverage, tracking high- and critical-severity remediation, and onboarding acquired assets to Anthropic's vulnerability management systems.

- Collaborate with various stakeholders, including corporate development, legal, security leadership, and engineering teams.

- Formalize and scale Anthropic's M&A security playbook, risk-scoring model, and tooling, leveraging Claude-powered automation where possible.

- Participate in the team's operational on-run rotation and contribute to core AppSec projects between deals.

## Requirements

- Hands-on experience in application and infrastructure security, including cloud and containerized environments.

- Ability to rapidly assess unfamiliar codebases and produce clear risk assessments.

- Production-quality coding skills in languages like Python, Go, Rust, or TypeScript.

- Practical threat modeling and vulnerability identification skills.

- Comfort working with high autonomy, ambiguity, and confidential context.

- Strong written and verbal communication skills.

## Preferred Qualifications

- 7+ years of experience in application security, security consulting, or security architecture.

- Prior M&A security due diligence or technical due diligence experience.

- Experience with SAST/DAST, bug bounty, or vulnerability management.

- Familiarity with using Large Language Models (LLMs) in security workflows.

- Experience securing agentic, code-execution, or LLM-integrated systems.

## Compensation

The annual compensation range for this role is $320,000-$485,000 USD.

## Skills

### Required
- application security
- infrastructure security
- cloud security
- containerized environments
- Python
- Go
- Rust
- TypeScript
- threat modeling
- vulnerability identification

### Nice to have
- M&A security due diligence
- technical due diligence
- SAST/DAST
- bug bounty
- vulnerability management
- Large Language Models (LLMs)
- agentic systems
- code-execution systems
- LLM-integrated systems

---

Source: [Apply at job-boards.greenhouse.io](https://job-boards.greenhouse.io/anthropic/jobs/5311463008?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
