7 days ago

Application Security Engineer

Anthropic

On Site
Full Time
$350,000
Seattle, WA

Job Overview

Job TitleApplication Security Engineer
Job TypeFull Time
CategoryCommerce
Experience5 Years
DegreeMaster
Offered Salary$350,000
LocationSeattle, WA

Who's the hiring manager?

Sign up to PitchMeAI to discover the hiring manager's details for this job. We will also write them an intro email for you.

Uncover Hiring Manager

Job Description

About Anthropic

Anthropic’s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems.

About The Role

The Application Security team is at the forefront of building security into every phase of the software development lifecycle at Anthropic. In this hands-on technical role, you will partner closely with our software engineers and researchers to ensure that security is a core consideration from initial design through implementation. You will lead threat modeling and secure design reviews to proactively identify and mitigate risks early, and help with continuous risk assessment. You will build tools and systems to support developers shipping code securely, adhering to secure coding best practices.

Your insights will shape our tooling, detection capabilities, and defenses against emerging threats to AI/ML. You'll develop the standards, processes, and educational resources that enable all Anthropic engineers to be security champions. This high-impact role demands a security practitioner who can think like an attacker, has a developer mindset, and can build strong relationships.

Responsibilities

  • Help secure AI products and internal tools that are introducing industry-novel security risks and pushing established security boundaries.
  • Lead “shift left” security efforts to build security into the software development lifecycle.
  • Conduct secure design reviews and threat modeling. Identify and prioritize risks, attack surfaces, and vulnerabilities.
  • Develop tooling to scale security code reviews and respond to developer questions, including advising developers on remediating vulnerabilities and following secure coding practices.
  • Manage Anthropic's vulnerability management program, including integrating data ingestion pipelines, coding logic to prioritize vulnerability fixes, supporting teams remediating vulnerabilities and developing automated systems at scale.
  • Oversee Anthropic's bug bounty program. Set scope, validate submissions, perform root cause analysis, coordinate remediation with engineering teams, and award bounties. Cultivate relationships with the ethical hacker community.
  • Collaborate closely with product engineers and researchers to instill security best practices. Advocate for secure architecture, design, and development.
  • Develop and document security policies, standards, and playbooks. Conduct security awareness training for engineers.

You May Be a Good Fit If You

  • Have 5+ years of hands-on experience in application and infrastructure security, including securing cloud-based and containerized environments.
  • Strong proficiency in at least one programming language (e.g., Python, Rust, Go, Java).
  • Lead with empathy, a collaborative spirit, and a learning mindset to work cross-functionally with engineers of all levels to build security into the software development life cycle.
  • Leverage creative and strategic thinking to reduce risk through secure design and simplicity, not just controls.
  • Possess broad security knowledge to connect the dots across domains and identify holistic ways to decrease the overall threat surface.
  • Are keen to distill complex security concepts into clear actions and drive consensus without direct authority.
  • Embody a proactive mindset to thread security throughout the product lifecycle through activities like threat modeling, secure code review, and education.
  • Have a strong grasp of offensive security to anticipate risks from an adversary's perspective, not just check compliance boxes.
  • Bring experience with modern application stacks, infrastructure, and security tools to implement pragmatic defenses.
  • Are practiced at collaborating cross-functionally and effectively balancing security requirements with business objectives.
  • Advocate for security fundamentals like least privilege, defense-in-depth, and eliminating complexity that could sub-linearly scale security through smart design.

Strong Candidates May Also

  • Hands-on technical expertise securing complex cloud environments and microservices architectures leveraging technologies like Kubernetes, Docker, and AWS / GCP.
  • Exposure to offensive security techniques like vulnerability testing, bug bounty, pen testing, and red team exercises.
  • Familiarity with AI/ML security risks such as prompt injection, data poisoning, model extraction, etc. and mitigations.
  • Experience building security tools, applications, and automated tools.
  • Solid foundational knowledge of both software and security engineering principles and are keen to continue learning.
  • Excellent communication skills, able to distill complex security topics for broad audiences.
  • Worked and thrived in fast-paced environments, and comfortable navigating ambiguity.

Key skills/competency

  • Application Security
  • Cloud Security
  • Threat Modeling
  • Secure SDLC
  • Vulnerability Management
  • Bug Bounty Program
  • Offensive Security
  • AI/ML Security
  • Python Programming
  • Secure Architecture Design

Tags:

Application Security Engineer
application security
cloud security
threat modeling
vulnerability management
bug bounty
secure SDLC
AI security
devsecops
secure coding
incident response
Python
AWS
GCP
Kubernetes
Docker
AI/ML
offensive security
security tooling
microservices
secure design

Share Job:

How to Get Hired at Anthropic

  • Research Anthropic's mission: Deeply understand their commitment to reliable, interpretable, and steerable AI systems and safety.
  • Customize your resume: Highlight extensive experience in application security, cloud environments, and securing complex software development lifecycles.
  • Showcase technical expertise: Emphasize proficiency in Python (or similar), cloud platforms like AWS/GCP, Kubernetes, Docker, and offensive security.
  • Prepare for behavioral questions: Focus on demonstrating empathy, collaboration, problem-solving, and the ability to drive consensus on security initiatives.
  • Illustrate AI/ML security understanding: Discuss familiarity with prompt injection, data poisoning, and model extraction risks and potential mitigations.

Frequently Asked Questions

Find answers to common questions about this job opportunity

Explore similar opportunities that match your background