How to apply for Staff+ Application Security Engineer - M&A

Anthropic

About Anthropic

Anthropic is an AI research and product company that builds the Claude models. The company states its mission is to create reliable, interpretable, and steerable AI systems. It also notes that it posts specific high-impact opportunities and does not necessarily recommend working at other positions there.

About the role

This is the first dedicated application security role for Anthropic's mergers and acquisitions. You will run security due diligence on acquisition targets, write the security risk readout for leadership, and after close bring acquired systems up to Anthropic's bar. You will also be a full member of the Application Security team, including its on-call rotation and tooling, and you are expected to automate the repeatable parts of diligence and integration.

A typical day

A typical day mixes Application Security team work, such as code review or on-call, with M&A tasks like reviewing a target's codebase or drafting a security risk readout. You would also spend time building or improving tooling so the next diligence and integration cycle takes less manual effort. The exact split will depend on active deals, so ask the hiring team how they expect the role to balance AppSec and M&A work.

Who Anthropic is looking for

  • Has deep application security experience: threat modeling, secure code review, and finding real vulnerabilities in web, API, and cloud systems.
  • Has done security due diligence or integration work for acquisitions, or has assessed third-party or acquired codebases and written risk readouts for leadership.
  • Can build tooling and automation, and will use Claude as a primary tool to make each acquisition's diligence and integration easier than the last.
  • Is comfortable working in a remote US role and participating in an on-call rotation alongside other application security engineers.

Tips for this application

  • In your resume, lead with concrete examples of security due diligence or post-acquisition integration work: what you assessed, what you found, and what you changed.
  • Show how you have automated security work. Name the tools or scripts you built and the manual effort they removed.
  • Reference Anthropic's stated mission and the 80,000 Hours career review linked in the job post. Explain why you want to work on security at a frontier AI company despite the concerns raised there.
  • Apply through Anthropic's own job posting and tailor your materials to this exact role title. Do not send a generic application security resume.
  • Because the job description is cut off mid-sentence, use the application or recruiter conversation to ask what the full scope of the M&A security function includes.

What to cover in your cover letter

['Your direct experience with security due diligence or integrating acquired systems, including writing risk readouts for leadership.', 'How you approach application security in practice: threat modeling, code review, and on-call work on real product surfaces.', 'A specific example of automating a repeatable security process, ideally with Claude or another LLM as part of the workflow.', 'Why this role at Anthropic specifically: the M&A security function is new, and you want to formalize the playbook, risk model, and tooling.']

Draft a cover letter

Research before applying

  • Read Anthropic's mission statement and its published research and policy positions on AI safety.
  • Read the 80,000 Hours career review on working at an AI lab, which the job post links directly.
  • Look at Anthropic's public product and engineering material on Claude and its agentic surfaces, since the AppSec team secures those systems.
  • Check Anthropic's public statements or news about acquisitions so you can speak to how security fits into its M&A activity.
Anthropic website

Likely interview topics

Based on the job description, expect questions about:

  • Walk through a security due diligence you led or supported. How did you scope it, what did you find, and how did you present risk to leadership?
  • How would you bring an acquired company's codebase and infrastructure up to Anthropic's application security bar after close?
  • Describe a time you automated a manual security process. What did you build, and what was the measurable result?
  • How do you use Claude or other LLMs in your application security work today?
  • How do you handle on-call and incident response for application security issues, and what would you change about your current process?
Practise interview questions

Common mistakes to avoid

  • Treating this as a standard application security role and ignoring the M&A due diligence and integration responsibilities.
  • Claiming AI security expertise without evidence of using Claude or other LLMs in your actual security workflow.
  • Applying without addressing the ethical concerns the job post itself raises about working at a frontier AI company.

Deadline

No deadline is listed. Roles without a deadline usually close once the employer has enough candidates, so apply soon if you are interested.