At a Glance
- Tasks: Secure AI products by integrating security into the software development lifecycle and leading threat assessments.
- Company: Join Anthropic, a leader in AI safety and innovation.
- Benefits: Comprehensive health insurance, flexible time off, and competitive salary with equity options.
- Other info: Dynamic work environment with opportunities for continuous learning and growth.
- Why this job: Make a real impact on AI security while collaborating with top engineers and researchers.
- Qualifications: 7+ years in application security, strong programming skills, and a proactive mindset.
The predicted salary is between 500 - 500 £ per month.
The Application Security team is at the forefront of building security into every phase of the software development lifecycle at Anthropic. In this hands-on technical role, you will partner closely with our software engineers and researchers to ensure that security is a core consideration from initial design through implementation.
You will lead threat modeling and secure design reviews to proactively identify and mitigate risks early, and help with continuous risk assessment. You will build tools and systems to support developers shipping code securely, adhering to secure coding best practices. Your insights will shape our tooling, detection capabilities, and defenses against emerging threats to AI/ML.
You’ll develop the standards, processes, and educational resources that enable all Anthropic engineers to be security champions. This high-impact role demands a security practitioner who can think like an attacker, has a developer mindset, and can build strong relationships.
- Help secure AI products and internal tools that are introducing industry-novel security risks and pushing established security boundaries.
- Lead “shift left” security efforts to build security into the software development lifecycle.
- Conduct secure design reviews and threat modeling. Identify and prioritize risks, attack surfaces, and vulnerabilities.
- Develop tooling to scale security code reviews and respond to developer questions, including advising developers on remediating vulnerabilities and following secure coding practices.
- Manage Anthropic’s vulnerability management program, including integrating data ingestion pipelines, coding logic to prioritize vulnerability fixes, supporting teams remediating vulnerabilities and developing automated systems at scale.
- Oversee Anthropic’s bug bounty program. Set scope, validate submissions, perform root cause analysis, coordinate remediation with engineering teams, and award bounties. Cultivate relationships with the ethical hacker community.
- Collaborate closely with product engineers and researchers to instill security best practices. Advocate for secure architecture, design, and development.
- Develop and document security policies, standards, and playbooks. Conduct security awareness training for engineers.
Benefits include comprehensive health, dental, and vision insurance for you and your dependents, inclusive fertility benefits via Carrot Fertility, 22 weeks of paid parental leave, flexible paid time off and absence policies, mental health support for you and your dependents, competitive salary and equity packages, optional equity donation matching at a 1:1 ratio, retirement plans with competitive matching, life and income protection plans, a $500/month flexible wellness and time saver stipend, commuter benefits, annual education stipend, home office stipends, relocation support for those moving for Anthropic, and daily meals and snacks in the office.
We are looking for candidates who bring experience with modern application stacks, infrastructure, and security tools to implement pragmatic defenses. Candidates should be practiced at collaborating cross-functionally and effectively balancing security requirements with business objectives.
Requirements include:
- 7+ years of hands-on experience in application and infrastructure security, including securing cloud-based and containerized environments.
- A proactive mindset to thread security throughout the product lifecycle through activities like threat modeling, secure code review, and education.
- Ability to lead with empathy, a collaborative spirit, and a learning mindset to work cross-functionally with engineers of all levels.
- Strong ability to distill complex security concepts into clear actions and drive consensus without direct authority.
- Broad security knowledge to connect the dots across domains and identify holistic ways to decrease the overall threat surface.
- Advocacy for security fundamentals like least privilege, defense-in-depth, and eliminating complexity that could sub-linearly scale security through smart design.
- A strong grasp of offensive security to anticipate risks from an adversary’s perspective.
- Strong proficiency in at least one programming language (e.g., Python, Rust, Go, Java).
- Creative and strategic thinking to reduce risk through secure design and simplicity.
Minimum education: Bachelor’s degree or an equivalent combination of education, training, and/or experience. Minimum years of experience: Years of experience required will correlate with the internal job level requirements for the position. Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience.
We encourage you to apply even if you do not believe you meet every single qualification. Not all strong candidates will meet every single qualification as listed. Research shows that people who identify as being from underrepresented groups are more prone to experiencing imposter syndrome and doubting the strength of their candidacy, so we urge you not to exclude yourself prematurely and to submit an application if you’re interested in this work.
Hands-on technical expertise securing complex cloud environments and microservices architectures leveraging technologies like Kubernetes, Docker, and AWS / GCP. Exposure to offensive security techniques like vulnerability testing, bug bounty, pen testing, and red team exercises. Familiarity with AI/ML security risks such as prompt injection, data poisoning, model extraction, etc. and mitigations. Solid foundational knowledge of both software and security engineering principles and are keen to continue learning. Experience building security tools, applications, and automated tools. Excellent communication skills, able to distill complex security topics for broad audiences. Worked and thrived in fast-paced environments, and comfortable navigating ambiguity.
Staff Application Security Engineer employer: Anthropic
At Anthropic, we pride ourselves on being an exceptional employer that fosters a culture of innovation and collaboration. Our team-oriented environment encourages personal growth and empowers employees to take ownership of their projects, making a meaningful impact in the tech landscape. Located in a vibrant area, we offer competitive benefits and unique opportunities for professional development, ensuring that our engineers thrive both personally and professionally.
StudySmarter Expert Advice🤫
We think this is how you could land Staff Application Security Engineer
✨Join Local Tech Meetups
Get out there and mingle with fellow developers by joining local tech meetups. It’s a fantastic way to meet people who might be working at Anthropic or know someone who does. Plus, you can pick up some trendy tech skills and trends while you're at it!
✨Contribute to Open Source Projects
Show off your coding chops by jumping into open-source projects. Not only does this give you practical experience, but it also gets you noticed in the dev community. You'll create a killer portfolio that speaks volumes about your skills to Anthropic.
✨Tap into Online Developer Communities
Don’t underestimate the power of online developer communities like GitHub, Stack Overflow, and even Reddit. Participate in discussions, share your projects, and build your visibility. We can often find opportunities through these channels that can lead to a full-time gig at companies like Anthropic.
✨Explore Job Boards Specifically for Tech Roles
Keep your eyes peeled on job boards that focus on tech roles. Sites like TechCareers or Stack Overflow Jobs can often have listings for companies like Anthropic that might not show up on broader job sites. Make it a habit to check these regularly, and don’t hesitate to apply directly through our website!
We think you need these skills to ace Staff Application Security Engineer
Some tips for your application 🫡
Show off your coding skills:When applying for a software engineering role, it's super important to showcase your coding skills. Make sure your CV includes your tech stack, any relevant programming languages you’re comfortable with, and examples of projects you've worked on. If you have a GitHub profile, link it up! We love to see code in action.
Tailor your portfolio:For a full-time role, we’d expect to see some solid examples of your work in your portfolio. Make sure to include at least two or three projects that highlight your problem-solving skills and your ability to work with different technologies. Focus on the projects that are most relevant to the position at Anthropic.
Craft a killer cover letter:Your cover letter is your chance to stand out—make it personal! Explain why you want to work at Anthropic and how your skills align with the role. Show us your passion for software development. We dig enthusiastic candidates who understand the value of collaboration and continuous learning!
Be clear and concise:When it comes to writing your CV and cover letter, clarity is key. Avoid jargon that could confuse us and stick to simple, direct language. Highlight your achievements with quantifiable results where possible, and keep everything easy to read. A well-organised application goes a long way!
How to prepare for a job interview at Anthropic
✨Brush Up on Your Coding Skills
For a full-time software engineering role, it's crucial that we stay sharp with our coding abilities. Expect technical questions that might involve solving problems on the spot or discussing algorithms. Practise on platforms like LeetCode or HackerRank to get comfortable with the types of questions that often come up.
✨Know Your Tools and Frameworks
Make sure we’re well-acquainted with the tools and technologies listed in the job description. Familiarise ourselves with any specific frameworks or programming languages mentioned. If Anthropic uses React or Node.js, for instance, be ready to discuss how we’ve used them in previous projects or coursework.
✨Showcase Your Projects
Bring along a portfolio that highlights our best work. This could be code samples, GitHub repositories, or any side projects we’ve built. Make sure we can talk through our thought process for each project, especially the challenges we faced and how we solved them—this shows our problem-solving skills in action.
✨Prepare for Behavioural Questions
While technical skills are key, full-time positions also require cultural fit. Be ready to discuss our previous experiences and how we handle teamwork, conflict, and deadlines. Brush up on the STAR method—Situation, Task, Action, Result—to clearly articulate our past experiences when discussing how we've contributed to a team.