Назад
4 дня назад

Staff+ Application Security Engineer (AI)

320 000 - 485 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Staff+ Application Security Engineer (AI): Building and operating Claude-powered security systems for code analysis, vulnerability remediation, threat modeling, and bug bounty triage with an accent on securing agentic AI, code execution, delegated credentials, and tool-use boundaries. Focus on designing novel threat models, owning production security automation end-to-end, and handling vulnerability escalations and incident response.

Location: Remote-friendly with required travel; based in San Francisco, Seattle, or New York City. Staff are expected to work from one of the offices at least 25% of the time.

Annual salary: $320,000–$485,000 USD

Company

Anthropic builds reliable, interpretable, and steerable AI systems designed to be safe and beneficial for users and society.

What you will do

  • Design, build, operate, and own Claude-powered security systems for LLM-driven code analysis, automated vulnerability remediation, and AI-assisted threat modeling.
  • Lead secure design reviews and threat modeling for novel AI systems, including agentic orchestration, code execution, delegated credentials, and tool-use boundaries.
  • Evolve a public bug bounty program using automation for routine triage and root-cause analysis while handling escalations and complex cases.
  • Partner with Product, Infrastructure, and Research teams as an embedded security owner for launches, architecture, and security decisions.
  • Participate in on-call operations covering bounty escalations, incident response, and production launch consultations.

Requirements

  • Hands-on application and infrastructure security experience in cloud and containerized environments.
  • Production-quality coding ability in Python, Go, Rust, or TypeScript, with experience building durable systems.
  • Practical threat-modeling and vulnerability-identification skills based on real systems and vulnerabilities.
  • Ability to work autonomously in ambiguous environments and communicate clearly with engineers and leadership.
  • Minimum education: bachelor’s degree or equivalent education, training, or experience in a relevant field.
  • 7+ years of application security, security engineering, or security-focused software engineering experience is preferred.

Nice to have

  • Experience securing agentic, code-execution, or LLM-integrated systems.
  • Ownership of a bug bounty, vulnerability disclosure, or vulnerability-management program at scale.
  • Experience building security automation or developer-facing security tooling.
  • Offensive security or penetration testing experience.
  • Regular use of LLMs as part of security engineering work.

Culture & Benefits

  • Collaborative work across research, engineering, policy, and business functions.
  • Flexible working hours and an office environment for collaboration.
  • Generous vacation and parental leave.
  • Competitive compensation and optional equity donation matching.
  • Visa sponsorship is available when feasible for the role and candidate, with immigration lawyer support.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →