How to apply for Staff+ Application Security Engineer

Anthropic

About Anthropic

Anthropic is a frontier AI research and product company working on alignment, policy, and security. The company posts specific high-impact opportunities rather than recommending all roles. It also publishes concerns about doing harm by working at a frontier AI lab, which candidates should read before applying.

About the role

This role secures the systems that build, serve, and increasingly are Claude, including multi-agent orchestration, sandboxed code execution, delegated credentials, and untrusted tool output crossing trust boundaries. The team uses Claude as its primary tool for static analysis, vulnerability fixes as pull requests, bug bounty triage, and threat modeling. Engineers own systems end-to-end and build the systems that find vulnerabilities at scale.

A typical day

A typical day likely involves reviewing Claude-assisted static analysis output, triaging bug bounty reports, and drafting or reviewing vulnerability fixes as pull requests. You may also run threat models for design reviews, build automation for a system you own, and decide which findings matter most. Ask the team during interviews how work is divided between tooling, reviews, and incident response.

Who Anthropic is looking for

  • Ships production systems and also clears a hands-on threat-modeling bar.
  • Can find a vulnerability but prefers building the system that finds them all.
  • Has experience with application security problems that lack off-the-shelf playbooks, such as agent orchestration, sandboxed execution, or delegated credentials.
  • Uses or is willing to use AI models as primary tools for static analysis, drafting fixes, triage, and threat modeling, while applying human judgment for system-level reasoning.

Tips for this application

  • Read Anthropic's published concerns about doing harm by working at a frontier AI lab before writing anything, and decide whether you agree with the reasoning.
  • In your application, show concrete examples of production systems you shipped and threat models you performed, not just tools you used.
  • Describe a time you built an automated system that found or fixed vulnerabilities at scale, since the role values builders over one-off finders.
  • Mention any experience with agent systems, sandboxed code execution, delegated credentials, or untrusted tool output crossing trust boundaries.
  • Explain how you use Claude or another LLM in your security workflow, because the team uses Claude across static analysis, PR fixes, triage, and threat modeling.

What to cover in your cover letter

['Your hands-on threat-modeling experience on complex systems, especially ones without prior art.', 'A production system you shipped end-to-end and what you owned.', 'How you use AI models as tools in security work, including where you keep human judgment.', 'Your view on securing AI systems and why you want to work on this specific attack surface.']

Draft a cover letter

Research before applying

  • Read Anthropic's mission statement and its published concerns about working at a frontier AI lab.
  • Study Anthropic's product surface, especially Claude Code and any published security details about it.
  • Read Anthropic's alignment and policy publications to understand how security work connects to the company's goals.
  • Look for public writing or talks from Anthropic's security team about application security for AI systems.
Anthropic website

Likely interview topics

Based on the job description, expect questions about:

  • Walk through a threat model you built for a system with multiple trust boundaries.
  • How would you secure a multi-agent orchestration system where agents hold delegated credentials?
  • Describe a vulnerability you found and how you would build a system to find that class of vulnerability automatically.
  • How do you use Claude or another LLM for static analysis, bug bounty triage, or drafting fixes, and where do you not trust it?
  • How would you design sandboxed code execution for untrusted tool output?
Practise interview questions

Common mistakes to avoid

  • Applying as a pure bug hunter without showing you can build systems that find vulnerabilities at scale.
  • Ignoring Anthropic's published concerns about working at a frontier AI lab, which suggests you have not read the company's own materials.
  • Claiming AI security experience without concrete examples of agent orchestration, sandboxed execution, or delegated credentials.

Deadline

No deadline is listed. Roles without a deadline usually close once the employer has enough candidates, so apply soon if you are interested.