Head of Vulnerability Disclosure & Security Community
Anthropic- Compensation
- $330k–$395k Published range · Top quartile for Security (54 listings)
- Location
- Hybrid - New York City, San Francisco, or Washington DC (at least 25% in office) Remote eligibility
- Employment
- Full-time Director+
About the job
About the role
We're looking for a Head of Vulnerability Disclosure & Security Community to own Anthropic's coordinated vulnerability disclosure program and our CVE Numbering Authority (CNA) end to end, including our public coordinated-disclosure jailbreak program. You will have the authority to set Anthropic's disclosure policy and timelines and will be the public face of Anthropic's disclosure work and help shape how the industry handles model-level vulnerabilities. Your findings feed model-release decisions, and you will work as a peer of the Senior Cyber Policy Lead, building relationships with security researchers and threat-intelligence partners along the way.
Key responsibilities
- Own and operate Anthropic's public, coordinated-disclosure jailbreak program end-to-end
- Lead Anthropic's CVE Numbering Authority (CNA) function for vulnerability disclosure, including in open-source contexts
- Build and maintain partnerships with the external security research community and threat-intelligence organizations
- Represent Anthropic at security conferences and within the broader vulnerability-research community
- Maintain close familiarity with vulnerability-database ecosystems to keep our program aligned with industry norms
- Lead Anthropic's external technical engagement on cyber safety topics, including public and community-facing communication
- Collaborate with the Senior Cyber Policy Lead to ensure disclosure findings inform evaluations and policy
- Build the function: hire and mentor a future analyst, and put in place the tooling and AI-assisted triage the program needs to scale
Minimum qualifications
- Experience operating or participating in a coordinated vulnerability disclosure program
- Experience coordinating multi-party disclosures involving researchers, vendors, and open-source maintainers
- Experience managing a disclosure queue with defined triage and response timelines
- Experience handling sensitive or embargoed vulnerability information, including TLP-marked material
Preferred qualifications
- Experience running or working inside a PSIRT
- Experience coordinating disclosures that include government parties
- A track record of authoring CVEs or vulnerability disclosures
- Experience presenting original research at security conferences
- Experience operating or supporting a CNA (CVE Numbering Authority), either internally or on behalf of third parties
- Experience incorporating artificial intelligence into coordinated vulnerability disclosure or CNA processes, such as automated triage, severity assessment, or report handling
- Experience operating or scaling a bug bounty program through a commercial platform
- Established relationships across the disclosure coordination community and programs
Compensation
Annual Salary: $330,000—$395,000 USD
Logistics
Minimum education: Bachelor’s degree or an equivalent combination of education, training, and/or experience. Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience. Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. Visa sponsorship: We do sponsor visas!
Skills & tags
Compare the essentials before you leave: pay, remote scope, employment type, source, and the employer apply destination.