Head of Vulnerability Disclosure & Security Community
About the role
We're looking for a Head of Vulnerability Disclosure & Security Community to own Anthropic's coordinated vulnerability disclosure program and our CVE Numbering Authority (CNA) end to end, including our public coordinated-disclosure jailbreak program. You will have the authority to set Anthropic's disclosure policy and timelines and will be the public face of Anthropic's disclosure work and help shape how the industry handles model-level vulnerabilities. Your findings feed model-release decisions, and you will work as a peer of the Senior Cyber Policy Lead, building relationships with security researchers and threat-intelligence partners along the way.
Key responsibilities
Own and operate Anthropic's public, coordinated-disclosure jailbreak program end-to-end
Lead Anthropic's CVE Numbering Authority (CNA) function for vulnerability disclosure, including in open-source contexts
Build and maintain partnerships with the external security research community and threat-intelligence organizations
Represent Anthropic at security conferences and within the broader vulnerability-research community
Maintain close familiarity with vulnerability-database ecosystems to keep our program aligned with industry norms
Lead Anthropic's external technical engagement on cyber safety topics, including public and community-facing communication
Collaborate with the Senior Cyber Policy Lead to ensure disclosure findings inform evaluations and policy
Build the function: hire and mentor a future analyst, and put in place the tooling and AI-assisted triage the program needs to scale
Minimum qualifications
Experience operating or participating in a coordinated vulnerability disclosure program
Experience coordinating multi-party disclosures involving researchers, vendors, and open-source maintainers
Experience managing a disclosure queue with defined triage and response timelines
Experience handling sensitive or embargoed vulnerability information, including TLP-marked material
Preferred qualifications
Experience running or working inside a PSIRT
Experience coordinating disclosures that include government parties
A track record of authoring CVEs or vulnerability disclosures
Experience presenting original research at security conferences
Experience operating or supporting a CNA (CVE Numbering Authority), either internally or on behalf of third parties
Experience incorporating artificial intelligence into coordinated vulnerability disclosure or CNA processes, such as automated triage, severity assessment, or report handling
Experience operating or scaling a bug bounty program through a commercial platform
Established relationships across the disclosure coordination community and programs
The annual compensation range for this role is listed below.
For sales roles, the range provided is the role’s On Target Earnings ("OTE") range, meaning that the range includes both the sales commissions/sales bonuses target and annual base salary for the role.
Annual Salary:
$330,000—$395,000 USD