Head of Vulnerability Disclosure & Security Community
Anthropic · New York City
Job description
About the role
Anthropic is seeking a Head of Vulnerability Disclosure & Security Community to lead its coordinated vulnerability disclosure program and CVE Numbering Authority. The role will shape Anthropic’s disclosure policies, engage with the security research community, and influence industry handling of model-level vulnerabilities.
Key responsibilities
- Own and operate Anthropic's public, coordinated-disclosure jailbreak program end‑to‑end.
- Lead the CVE Numbering Authority (CNA) function for vulnerability disclosure, including in open‑source contexts.
- Build and maintain partnerships with external security researchers and threat‑intelligence organizations.
- Represent Anthropic at security conferences and within the broader vulnerability‑research community.
- Maintain familiarity with vulnerability‑database ecosystems to keep the program aligned with industry norms.
- Lead external technical engagement on cyber‑safety topics, including public and community‑facing communication.
- Collaborate with the Senior Cyber Policy Lead to ensure disclosure findings inform evaluations and policy.
- Hire and mentor a future analyst and implement tooling and AI‑assisted triage to scale the program.
Required profile
- Experience operating or participating in a coordinated vulnerability disclosure program.
- Experience coordinating multi‑party disclosures involving researchers, vendors, and open‑source maintainers.
- Experience managing a disclosure queue with defined triage and response timelines.
- Experience handling sensitive or embargoed vulnerability information, including TLP‑marked material.
- Preferred: experience running or working inside a PSIRT.
- Preferred: experience coordinating disclosures that include government parties.
- Preferred: a track record of authoring CVEs or vulnerability disclosures.
- Preferred: experience presenting original research at security conferences.
- Preferred: experience operating or supporting a CNA, either internally or for third parties.
- Preferred: experience incorporating artificial intelligence into coordinated vulnerability disclosure or CNA processes (automated triage, severity assessment, report handling).
Required skills
- Coordinated vulnerability disclosure
- CVE Numbering Authority (CNA) operation
- PSIRT processes
- AI‑assisted triage
- Severity assessment
- Report handling
- TLP‑marked information handling
- Multi‑party disclosure coordination
- Threat‑intelligence engagement
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in the United States.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 1 month ago
Expires 3 weeks from now
15 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
Anthropic
New York City
Related job offers
-
Security Engineer - Threat Intel
Anthropic New York City -
Safeguards Enforcement Lead, User Well-Being
Anthropic New York City -
Safeguards Enforcement Analyst – Conventional Weapons
Anthropic New York City -
Armed Security Officer
The University of Tulsa Tulsa -
Armed Security Officer (Part‑Time)
The University of Tulsa Tulsa