Head of Vulnerability Disclosure & Security Community
Anthropic
- Location
- New York City, NY; Remote-Friendly (Travel-Required) | San Francisco, CA | Washington, DC
- Work model
- Remote
- Level
- Staff
- Salary
- $330k/yr
- Posted
- 1h ago
About this role
About Anthropic
Anthropic’s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems.
About the role
We're looking for a Head of Vulnerability Disclosure & Security Community to own Anthropic's coordinated vulnerability disclosure program and our CVE Numbering Authority (CNA) end to end, including our public coordinated-disclosure jailbreak program. You will have the authority to set Anthropic's disclosure policy and timelines and will be the public face of Anthropic's disclosure work and help shape how the industry handles model-level vulnerabilities. Your findings feed model-release decisions, and you will work as a peer of the Senior Cyber Policy Lead, building relationships with security researchers and threat-intelligence partners along the way.
Key responsibilities
• Own and operate Anthropic's public, coordinated-disclosure jailbreak program end-to-end
• Lead Anthropic's CVE Numbering Authority (CNA) function for vulnerability disclosure, including in open-source contexts
• Build and maintain partnerships with the external security research community and threat-intelligence organizations
• Represent Anthropic at security conferences and within the broader vulnerability-research community
• Maintain close familiarity with vulnerability-database ecosystems to keep our program aligned with industry norms
• Lead Anthropic's external technical engagement on cyber safety topics, including public and community-facing communication
• Collaborate with the Senior Cyber Policy Lead to ensure disclosure findings inform evaluations and policy
• Build the function: hire and mentor a future analyst, and put in place the tooling and AI-assisted triage the program needs to scale
Minimum qualifications
• Experience operating or participating in a coordinated vulnerability disclosure program
• Experience coordinating multi-party disclosures involving researchers, vendors, and open-source maintainers
• Experience managing a disclosure queue with defined triage and response timelines
• Experience handling sensitive or embargoed vulnerability information, including TLP-marked material
Preferred qualifications
• Experience running or working inside a PSIRT
• Experience coordinating disclosures that include government parties
• A track record of authoring CVEs or vulnerability disclosures
• Experience presenting original research at security conferences
• Experience operating or supporting a CNA (CVE Numbering Authority), either internally or on behalf of third parties
• Experience incorporating artificial intelligence into coordinated vulnerability disclosure or CNA processes, such as automated triage, severity assessment, or report handling
• Experience operating or scaling a bug bounty program through a commercial platform
• Established relationships across the disclosure coordination community and programs
The annual compensation range for this role is listed below.
For sales roles, the range provided is the role’s On Target Earnings ("OTE") range, meaning that the range includes both the sales commissions/sales bonuses target and annual base salary for the