About the job
About Anthropic
At Anthropic, we are dedicated to developing trustworthy, interpretable, and controllable AI systems. Our vision is to ensure that AI remains safe and beneficial for our users and society. Our rapidly expanding team consists of passionate researchers, engineers, policy specialists, and business leaders collaborating to create forward-thinking AI solutions.
About the Role
In the position of Technical Program Manager for Security, focusing on Coordinated Vulnerability Disclosure (CVD), you will establish and steer the initiatives that dictate how Anthropic responsibly reveals software vulnerabilities identified by our AI-driven tools, such as Claude, Patchy, and Claude Code. These advanced tools have already uncovered genuine zero-day vulnerabilities in critical software including Firefox and the Linux kernel. The challenge now extends beyond merely identifying vulnerabilities; it encompasses managing the fallout of these discoveries at an unprecedented scale and speed.
Conventional coordinated disclosure frameworks were designed for a time when a researcher might uncover a significant vulnerability every few weeks. The AI-powered discovery landscape has dramatically transformed this paradigm; for instance, Claude can identify hundreds of issues within a single codebase in just one day. Your role is crucial in guaranteeing that every finding is communicated to the appropriate maintainer, at the right speed, with the necessary context, while ensuring Anthropic adheres to its Responsible Scaling Policy (RSP) commitments.
You will oversee the complete CVD lifecycle: from internal assessment and human validation of AI-generated findings to tiered disclosure timelines and external coordination with vendors, open-source maintainers, and relevant organizations. This role necessitates extensive collaboration across Security Engineering, Legal, Communications, Product, and Frontier Red Team to ensure Anthropic serves as a responsible steward of the vulnerabilities its tools reveal.
Responsibilities:
- Lead the CVD program strategy and implementation: Define and steer the roadmap for coordinated vulnerability disclosure, from AI-generated findings to maintainer notifications, remediation tracking, and public disclosure. Ensure alignment with Anthropic’s security posture and RSP compliance requirements.
- Oversee internal triage and quality assurance: Establish and manage a human review process to validate all AI-generated findings before external disclosure. Set minimum confidence thresholds and deduplicate against known CVEs.

