Head of Vulnerability Disclosure & Security Community
Core
Own and operate Anthropic's coordinated vulnerability disclosure program and CVE Numbering Authority (CNA), including public jailbreak programs, setting disclosure policies, and serving as the public face for model-level vulnerabilities.
Role type
Head of Vulnerability Disclosure & Security Community
Builds
Coordinated vulnerability disclosure programs, CVE numbering authority functions, and security research partnerships
Domain
AI Safety, Cybersecurity, Vulnerability Management
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure
Required skills
Coordinated vulnerability disclosure program operations, multi-party disclosure coordination, disclosure queue management with triage timelines, handling sensitive/embargoed vulnerability information (TLP-marked), building external security research partnerships, representing at security conferences, vulnerability-database ecosystem familiarity, external technical engagement on cyber safety, collaboration on disclosure findings for model-release decisions, hiring and mentoring analysts, tooling and AI-assisted triage implementation
Preferred skills
PSIRT operations, government party disclosure coordination, CVE authoring, presenting original research at security conferences, CNA operations, AI integration into disclosure/CNA processes, bug bounty program scaling, established relationships in the disclosure coordination community
Technologies
CVE Numbering Authority (CNA), TLP-marked material handling, AI-assisted triage tools, commercial bug bounty platforms
Responsibilities
Operate public coordinated-disclosure jailbreak program end-to-end, lead CVE Numbering Authority function, build and maintain partnerships with external security research community and threat-intelligence organizations, represent Anthropic at security conferences, maintain familiarity with vulnerability-database ecosystems, lead external technical engagement on cyber safety, collaborate with Senior Cyber Policy Lead on disclosure findings, build the function by hiring/mentoring analysts and implementing tooling
Seniority
Senior, hands-on IC with leadership responsibilities