About this role
Job title: Staff+ Application Security Engineer - M&A
About the Role Anthropic's Application Security team secures the systems that build, serve, and Claude — and as Anthropic's footprint grows, that mandate extends to codebases from outside. This role establishes that function: owning security due diligence and secure integration for acquisitions — assessing a target's security posture pre-close, delivering the security risk readout for leadership, and bringing acquired systems up to Anthropic's bar after close.
What You'll Do
- Lead pre-close security due diligence on prospective acquisitions — coordinate external penetration testing, threat-model the target's architecture, assess security controls, and deliver the security risk readout for leadership ahead of close and integration planning
- Drive post-close security integration — stand up static and dynamic analysis coverage on acquired codebases, track high- and critical-severity remediation to closure, fold acquired assets into bug bounty scope, and onboard repositories to Anthropic's automated vulnerability remediation and reporting systems
- Coordinate adjacent security engineering teams (supply chain, cloud, corporate security, detection & response) on their portions of each integration
- Work across a wide set of stakeholders on every deal — corporate development, legal, security leadership, and the engineering teams inheriting acquired systems internally
What We're Looking For
- Experience leading pre-close security due diligence on prospective acquisitions; ability to coordinate external penetration testing, threat-model the target's architecture, assess security controls, and deliver security risk readouts for leadership
- Experience driving post-close security integration — static and dynamic analysis on acquired codebases, remediation tracking to closure, onboarding acquired assets to bug bounty scope, and integration into automated vulnerability remediation and reporting systems
- Ability to coordinate cross-functional security engineering teams (supply chain, cloud, corporate security, detection & response) on integrations
- Strong collaboration and communication with corporate development, legal, security leadership, and engineering teams inheriting acquired systems