Skip to content
← Back to job listings

Staff+ Application Security Engineer (Mergers & Acquisitions)

Anthropic · New York, United States

External listingfull-time15 days ago

About The Role

Join Anthropic, a leading AI safety and research company, as a Staff+ Application Security Engineer focused on Mergers & Acquisitions. In this role, you will be responsible for security due diligence and secure integration for Anthropic's acquisitions, assessing a target's security posture pre-close, writing the security risk readout for leadership, and bringing acquired systems up to Anthropic's security standards post-close. You will also formalize and scale Anthropic's M&A security playbook and contribute to core AppSec projects between deals.

  • Lead pre-close security due diligence on prospective acquisitions, coordinating external penetration testing and delivering the security risk readout for leadership.
  • Drive post-close security integration by standing up static and dynamic analysis coverage on acquired codebases, tracking remediation to closure, and onboarding repositories to automated systems.
  • Formalize and scale Anthropic's M&A security playbook, turning as much of it as possible into Claude-powered tooling rather than manual processes.
  • If you like parachuting into an unfamiliar codebase under time pressure and turning it into a clear risk picture for leadership, this is that job
  • Practical threat-modeling and vulnerability-identification skills — you've found and reasoned about real bugs in real systems
  • Demonstrated ability to rapidly assess an unfamiliar codebase or architecture and produce a clear, prioritized risk assessment for a non-security audience
  • Production-quality coding ability in at least one of Python, Go, Rust, or TypeScript
  • Hands-on application and infrastructure security experience, including cloud and containerized environments
  • Clear written and verbal communication across varied audiences — executives, legal and corporate development partners, and engineering counterparts at an acquired company
  • Comfort operating with high autonomy, ambiguity, and tightly-held confidential context
  • Track record of building security automation or tooling rather than relying solely on manual review
  • Experience securing agentic, code-execution, or LLM-integrated systems
  • 7+ years in application security, security consulting, or security architecture
  • Prior M&A security due diligence, third-party security assessment, or technical due diligence experience
  • Experience standing up or scaling SAST/DAST, bug bounty, or vulnerability management coverage across multiple codebases
  • Familiarity with using LLMs as a core part of your security workflow
  • We encourage you to apply even if you do not believe you meet every single qualification

This is an external listing. JobSpring does not represent or verify the employer. Report this listing