Talent.com
Application Security Engineer
Application Security EngineerAnthropic • San Francisco, CA, United States
Application Security Engineer

Application Security Engineer

Anthropic • San Francisco, CA, United States
7 days ago
Job type
  • Full-time
Job description
Application Security Engineer

The Application Security team is at the forefront of building security into every phase of the software development lifecycle at Anthropic. In this hands-on technical role, you will partner closely with our software engineers and researchers to ensure that security is a core consideration from initial design through implementation. You will lead threat modeling and secure design reviews to proactively identify and mitigate risks early, and help with continuous risk assessment. You will build tools and systems to support developers shipping code securely, adhering to secure coding best practices.

Your insights will shape our tooling, detection capabilities, and defenses against emerging threats to AI/ML. You'll develop the standards, processes, and educational resources that enable all Anthropic engineers to be security champions. This high-impact role demands a security practitioner who can think like an attacker, has a developer mindset, and can build strong relationships.

Responsibilities:
  • Help secure AI products and internal tools that are introducing industry-novel security risks and pushing established security boundaries
  • Lead "shift left" security efforts to build security into the software development lifecycle.
  • Conduct secure design reviews and threat modeling. Identify and prioritize risks, attack surfaces, and vulnerabilities.
  • Develop tooling to scale security code reviews and respond to developer questions, including advising developers on remediating vulnerabilities and following secure coding practices.
  • Manage Anthropic's vulnerability management program, including integrating data ingestion pipelines, coding logic to prioritize vulnerability fixes, supporting teams remediating vulnerabilities and developing automated systems at scale.
  • Oversee Anthropic's bug bounty program. Set scope, validate submissions, perform root cause analysis, coordinate remediation with engineering teams, and award bounties. Cultivate relationships with the ethical hacker community.
  • Collaborate closely with product engineers and researchers to instill security best practices. Advocate for secure architecture, design, and development.
  • Develop and document security policies, standards, and playbooks. Conduct security awareness training for engineers.
You May Be A Good Fit If You:
  • Have 5+ years of hands-on experience in application and infrastructure security, including securing cloud-based and containerized environments.
  • Strong proficiency in at least one programming language (e.g., Python, Rust, Go, Java)
  • Lead with empathy, a collaborative spirit, and a learning mindset to work cross-functionally with engineers of all levels to build security into the software development life cycle.
  • Leverage creative and strategic thinking to reduce risk through secure design and simplicity, not just controls.
  • Possess broad security knowledge to connect the dots across domains and identify holistic ways to decrease the overall threat surface.
  • Are keen to distill complex security concepts into clear actions and drive consensus without direct authority.
  • Embody a proactive mindset to thread security throughout the product lifecycle through activities like threat modeling, secure code review, and education.
  • Have a strong grasp of offensive security to anticipate risks from an adversary's perspective, not just check compliance boxes.
  • Bring experience with modern application stacks, infrastructure, and security tools to implement pragmatic defenses.
  • Are practiced at collaborating cross-functionally and effectively balancing security requirements with business objectives.
  • Advocate for security fundamentals like least privilege, defense-in-depth, and eliminating complexity that could sub-linearly scale security through smart design.
Strong Candidates May Also:
  • Hands-on technical expertise securing complex cloud environments and microservices architectures leveraging technologies like Kubernetes, Docker, and AWS / GCP.
  • Exposure to offensive security techniques like vulnerability testing, bug bounty, pen testing, and red team exercises.
  • Familiarity with AI/ML security risks such as prompt injection, data poisoning, model extraction, etc. and mitigations.
  • Experience building security tools, applications, and automated tools.
  • Solid foundational knowledge of both software and security engineering principles and are keen to continue learning.
  • Excellent communication skills, able to distill complex security topics for broad audiences.
  • Worked and thrived in fast-paced environments, and comfortable navigating ambiguity.

The annual compensation range for this role is listed below.

Annual Salary: $300,000 - $405,000 USD

Logistics

Education requirements: We require at least a Bachelor's degree in a related field or equivalent experience. Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices.

Visa sponsorship: We do sponsor visas! However, we aren't able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this.

We encourage you to apply even if you do not believe you meet every single qualification. Not all strong candidates will meet every single qualification as listed. Research shows that people who identify as being from underrepresented groups are more prone to experiencing imposter syndrome and doubting the strength of their candidacy, so we urge you not to exclude yourself prematurely and to submit an application if you're interested in this work. Your safety matters to us. To protect yourself from potential scams, remember that Anthropic recruiters only contact you from @anthropic.com email addresses. In some cases, we may partner with vetted recruiting agencies who will identify themselves as working on behalf of Anthropic. Be cautious of emails from other domains. Legitimate Anthropic recruiters will never ask for money, fees, or banking information before your first day. If you're ever unsure about a communication, don't click any linksvisit anthropic.com/careers directly for confirmed position openings.

How We're Different

We believe that the highest-impact AI research will be big science. At Anthropic we work as a single cohesive team on just a few large-scale research efforts. And we value impact advancing our long-term goals of steerable, trustworthy AI rather than work on smaller and more specific puzzles. We view AI research as an empirical science, which has as much in common with physics and biology as with traditional efforts in computer science. We're an extremely collaborative group, and we host frequent research discussions to ensure that we are pursuing the highest-impact work at any given time. As such, we greatly value communication skills.

The easiest way to understand our research directions is to read our recent research. This research continues many of the directions our team worked on prior to Anthropic, including: GPT-3, Circuit-Based Interpretability, Multimodal Neurons, Scaling Laws, AI & Compute, Concrete Problems in AI Safety, and Learning from Human Preferences.

Come Work With Us!

Anthropic is a public benefit corporation headquartered in San Francisco. We offer competitive compensation and benefits, optional equity donation matching, generous vacation and parental leave, flexible working hours, and a lovely office space in which to collaborate with colleagues. Guidance on Candidates' AI Usage: Learn about our policy for using AI in our application process

Create a job alert for this search

Application Security Engineer • San Francisco, CA, United States

Similar jobs
Application Security Engineer

Application Security Engineer

Pantera Capital • San Francisco, CA, United States
Full-time
Perplexity is seeking a highly skilled, experienced and hands-on Application Security Engineer to join our dynamic security team, revolutionizing the way people search and interact with the interne...Show more
Last updated: 30+ days ago • Promoted
Senior Application Security Engineer

Senior Application Security Engineer

ZipHQ, Inc. • San Francisco, CA, United States
Full-time
The simple task of buying software, services, or tools at work has become hopelessly complicated at even the most innovative companies in the world.Today, enterprises spend $120T+ per year globally...Show more
Last updated: 30+ days ago • Promoted
Senior Application Security Engineer

Senior Application Security Engineer

Zip • San Francisco, CA, United States
Full-time
The simple task of buying software, services, or tools at work has become hopelessly complicated at even the most innovative companies in the world.Today, enterprises spend $120T+ per year globally...Show more
Last updated: 30+ days ago • Promoted
Remote Application Security Engineer — Scale Security Programs

Remote Application Security Engineer — Scale Security Programs

Bugcrowd Inc. • San Francisco, CA, United States
Remote
Full-time
A cybersecurity company is seeking an Application Security Engineer to manage vulnerability submissions for various bug bounty programs.The ideal candidate should have a Bachelor’s degree or equiva...Show more
Last updated: 30+ days ago • Promoted
Lead Application Security Engineer

Lead Application Security Engineer

Coupa • San Francisco, CA, United States
Full-time
Lead Application Security Engineer.Coupa makes margins multiply through its community-generated AI and industry-leading total spend management platform for businesses large and small.We empower you...Show more
Last updated: 8 days ago • Promoted
Security Engineer, Application Security

Security Engineer, Application Security

OpenAI • San Francisco, CA, United States
Full-time
Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity.The Security team protects OpenAI’s technology, people, and products.We are...Show more
Last updated: 30+ days ago • Promoted
Senior Application Security Engineer

Senior Application Security Engineer

Gemini • San Francisco, CA, United States
Full-time
Gemini is a global crypto and Web3 platform founded by Cameron and Tyler Winklevoss in 2014, offering a wide range of simple, reliable, and secure crypto products and services to individuals and in...Show more
Last updated: 1 day ago • Promoted
Senior & Lead Application Security Engineer

Senior & Lead Application Security Engineer

Verticalmove, Inc • San Francisco, CA, United States
Full-time
Senior & Lead Application Security Engineer.Get AI-powered advice on this job and more exclusive features.ATTN - PLEASE READ CAREFULLY: WE CAN NOT SPONSOR NEW VISAS OR TRANSFER EXISTING VISAS.AT TH...Show more
Last updated: 30+ days ago • Promoted
Security engineer, enterprise security

Security engineer, enterprise security

Jobright.ai • San Francisco, CA, United States
Full-time
Security engineer, enterprise security.Be among the first 25 applicants.Security engineer, enterprise security.Jobright is an AI-powered career platform that helps job seekers discover the top oppo...Show more
Last updated: 30+ days ago • Promoted
Senior Application Security Engineer

Senior Application Security Engineer

Kubelt • San Francisco, CA, United States
Full-time
World is a network of real humans, built on privacy-preserving proof-of-human technology, and powered by a globally inclusive financial network that enables the free flow of digital assets for all....Show more
Last updated: 30+ days ago • Promoted
Software Development Engineer - Security, AiDP

Software Development Engineer - Security, AiDP

San Francisco Staffing • San Francisco, CA, United States
Full-time
Envision the boundless possibilities that lie ahead here.At Apple, innovative concepts have a remarkable ability to transform into exceptional products, services, and customer experiences within a ...Show more
Last updated: 21 days ago • Promoted
Senior Security Software Engineer, Application Security

Senior Security Software Engineer, Application Security

Roblox • San Mateo, CA, United States
Full-time
Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers...Show more
Last updated: 6 days ago • Promoted
Lead Application Security Engineer - 11006

Lead Application Security Engineer - 11006

Qplusequality • San Francisco, CA, United States
Full-time
Coupa makes margins multiply through its community-generated AI and industry-leading total spend management platform for businesses large and small.Coupa AI is informed by trillions of dollars of d...Show more
Last updated: 30+ days ago • Promoted
Senior Application Security Engineer

Senior Application Security Engineer

Brex • San Francisco, CA, United States
Full-time
Brex is the AI-powered spend platform.We help companies spend with confidence with integrated corporate cards, banking, and global payments, plus intuitive software for travel and expenses.Tens of ...Show more
Last updated: 30+ days ago • Promoted
Senior Application Security Engineer

Senior Application Security Engineer

ZIP • San Francisco, CA, United States
Full-time
The simple task of buying software, services, or tools at work has become hopelessly complicated at even the most innovative companies in the world.Today, enterprises spend $120T+ per year globally...Show more
Last updated: 13 days ago • Promoted
Web Application Security Engineer

Web Application Security Engineer

Direct Staffing Inc • San Francisco, CA, United States
Full-time
Web Application Security Engineer.Retail / Wholesale - Corporate.Web Application Security Engineer.Visa candidates are welcome to apply.Shopping has changed more in the past five years than in the ...Show more
Last updated: 6 days ago • Promoted
Remote Application Security Engineer - Zetachain

Remote Application Security Engineer - Zetachain

Blockchain Works • San Francisco, CA, United States
Remote
Full-time
ZetaChain aims to be the only blockchain you’ll ever need.It is a layer 1 blockchain and developer platform that connects any L1 and L2, from Ethereum to Bitcoin and beyond.Access all of crypto in ...Show more
Last updated: 2 days ago • Promoted
Product Security Engineer

Product Security Engineer

Chime • San Francisco, CA, United States
Full-time
We are looking for an early-career Security Engineer to join our Product Security team, someone who has a builder's mindset, is eager to learn, and is excited to contribute to both planned initiati...Show more
Last updated: 12 days ago • Promoted