2

Remote Security Risk Assessment Jobs in Sunnyvale, CA

Assess, prioritize, and communicate security risks across the business * Develop third-party risk management strategies and enterprise risk reporting programs * Policy & Governance * Manage the ...

Product Security Engineer

San Jose, CA ยท On-site +1

$74.16 - $92.70/hr

Product Security Engineer Full-time Remote You'll be joining Adobe on a contract opportunity ... Experience with vulnerability triage, risk assessment, and incident response * Knowledge of ...

Cyber Security Program Manager

Sunnyvale, CA ยท On-site +1

$130K - $176K/yr

Coordination of risk assessments, vulnerability management activities, and security training ... Open to Remote candidates. Preferred * Industry-recognized certifications such as CISA, CISSP, or ...

Remote Job Overview We are seeking experienced Pharmacovigilance Experts to contribute their drug ... Assess safety findings, signal evaluations, and benefit-risk conclusions for accuracy and ...

Cyber Security Program Manager

San Jose, CA ยท On-site +1

$144K - $195K/yr

Coordination of risk assessments, vulnerability management activities, and security training ... Open to Remote candidates. Preferred * Industry-recognized certifications such as CISA, CISSP, or ...

Sr. Security Engineer

San Francisco, CA ยท On-site +1

$180K - $230K/yr

Our partners will continue to manage structured assessments including Penetration Testing and ... Ownership in our approach to AI-related security risk, including: * Securing our own AI/ML systems ...

This is a remote first role. You will partner closely with teams across the company and focus on ... Perform technical security assessments, code audits, and design reviews for new AI infrastructure ...

next page

Showing results 1-20

Remote Security Risk Assessment information

See Sunnyvale, CA salary details

$12

$59

$82

How much do remote security risk assessment jobs pay per hour?

As of Aug 21, 2026, the average hourly pay for remote security risk assessment in Sunnyvale, CA is $59.16, according to ZipRecruiter salary data. Most workers in this role earn between $47.98 and $70.53 per hour, depending on experience, location, and employer.

What is a remote security risk assessment?

A Remote Security Risk Assessment is a process where security professionals evaluate an organization's security risks, vulnerabilities, and threats without being physically present on-site. This assessment is typically conducted through virtual meetings, digital questionnaires, and remote access to systems and documentation. The goal is to identify potential security gaps and recommend improvements to protect sensitive data and systems from cyber threats. Remote assessments have become increasingly popular due to their flexibility, cost-effectiveness, and ability to serve organizations regardless of location.

What are the key skills and qualifications needed to thrive as a remote security risk assessor?

To thrive as a Remote Security Risk Assessor, you need expertise in cybersecurity principles, risk analysis, and a relevant degree or certifications such as CISSP, CISM, or CRISC. Familiarity with tools like vulnerability scanners, security information and event management (SIEM) systems, and risk assessment frameworks (e.g., NIST, ISO 27001) is essential. Strong analytical thinking, communication skills, and attention to detail help in accurately identifying and communicating risks to stakeholders. These skills and qualities are vital to ensure organizations can proactively mitigate threats and maintain robust security postures in remote or distributed environments.

What are some common challenges faced by professionals in remote security risk assessment roles?

Professionals in remote security risk assessment often encounter challenges such as limited on-site visibility, reliance on digital communication, and the need to assess complex IT environments from afar. Effective collaboration with on-site staff and stakeholders is essential to gather accurate information and implement recommendations. Additionally, staying up-to-date with evolving cybersecurity threats and maintaining clear documentation are vital for success in this role.

What is the difference between Remote Security Risk Assessment vs Cybersecurity Analyst?

AspectRemote Security Risk AssessmentCybersecurity Analyst
CredentialsCertifications like CISSP, CISA, CISMCertifications like CompTIA Security+, CISSP, CEH
Work EnvironmentRemote or on-site, focusing on risk evaluationRemote or on-site, focusing on security monitoring and incident response
Industry UsageUsed in risk management, compliance, and audit contextsUsed in security operations, threat analysis, and incident handling

Remote Security Risk Assessments and Cybersecurity Analysts both require security certifications and often work in similar environments. However, risk assessors focus on evaluating vulnerabilities and compliance, while analysts handle ongoing security monitoring and incident response. Understanding these differences helps organizations assign the right roles for their security needs.

What are popular job titles related to Remote Security Risk Assessment jobs in Sunnyvale, CA?

For Remote Security Risk Assessment jobs in Sunnyvale, CA, the most frequently searched job titles are:

What job categories do people searching Remote Security Risk Assessment jobs in Sunnyvale, CA look for?

The top searched job categories for Remote Security Risk Assessment jobs in Sunnyvale, CA are:

What cities near Sunnyvale, CA are hiring for Remote Security Risk Assessment jobs?

Cities near Sunnyvale, CA with the most Remote Security Risk Assessment job openings:

Staff+ Application Security Engineer - M&A

Anthropic

San Francisco, CA โ€ข On-site, Remote

$69.25 - $92.50/hr

Full-time

PTO

Re-posted 11 days ago


Job description

About Anthropic
Anthropic's mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems.
About the role
Anthropic's Application Security team secures the systems that build, serve, and increasingly are Claude - and as Anthropic's footprint grows, that mandate now extends to companies and codebases we bring in from outside. This role establishes that function.
You'll own security due diligence and secure integration for Anthropic's acquisitions - assessing a target's security posture pre-close, writing the security risk readout for leadership, and after close, bringing acquired systems up to Anthropic's bar. Security has been part of every deal to date, but this is the first dedicated role for it: you'll formalize the playbook, the risk model, and the tooling, and make them repeatable.
This is an AppSec role first. You'll be an active member of the Application Security team - same rituals, same on-run rotation, same tooling, working alongside engineers securing Anthropic's own agentic product surfaces. The expectation is the same too: we use Claude as our primary tool, and you're expected to automate the repeatable parts of diligence and integration as you go, so each acquisition is easier than the last. When deal flow is quiet, you'll pick up core AppSec project work; when it's active, M&A is your priority.
We're upfront that the center of gravity here is M&A rather than core product security. It's burstier, more assessment-heavy, and operates on confidential, time-sensitive work. If you like parachuting into an unfamiliar codebase under time pressure and turning it into a clear risk picture for leadership, this is that job.
Key responsibilities
  • Lead pre-close security due diligence on prospective acquisitions - coordinate external penetration testing, threat-model the target's architecture, assess security controls, and deliver the security risk readout for leadership ahead of close and integration planning
  • Drive post-close security integration - stand up static and dynamic analysis coverage on acquired codebases, track high- and critical-severity remediation to closure, fold acquired assets into bug bounty scope, and onboard repositories to Anthropic's automated vulnerability remediation and reporting systems
  • Coordinate adjacent security engineering teams (supply chain, cloud, corporate security, detection & response) on their portions of each integration
  • Work across a wide set of stakeholders on every deal - corporate development, legal, security leadership, and the engineering teams inheriting acquired systems internally; engineering and security counterparts at the target company externally - translating between them and keeping the security workstream legible to all of them
  • Formalize and scale Anthropic's M&A security playbook - risk-scoring model, diligence runbook, integration checklist - and turn as much of it as possible into Claude-powered tooling rather than manual process
  • Share the team's operational on-run rotation (bug bounty escalations, launch consults, incident response), swapping out during periods of active deal work
  • Contribute to core AppSec projects between deals - secure design reviews, threat modeling for agentic systems, and the team's security automation roadmap
Minimum qualifications
  • Hands-on application and infrastructure security experience, including cloud and containerized environments
  • Demonstrated ability to rapidly assess an unfamiliar codebase or architecture and produce a clear, prioritized risk assessment for a non-security audience
  • Production-quality coding ability in at least one of Python, Go, Rust, or TypeScript
  • Practical threat-modeling and vulnerability-identification skills - you've found and reasoned about real bugs in real systems
  • Comfort operating with high autonomy, ambiguity, and tightly-held confidential context
  • Clear written and verbal communication across varied audiences - executives, legal and corporate development partners, and engineering counterparts at an acquired company
Preferred qualifications
  • 7+ years in application security, security consulting, or security architecture
  • Prior M&A security due diligence, third-party security assessment, or technical due diligence experience
  • Experience standing up or scaling SAST/DAST, bug bounty, or vulnerability management coverage across multiple codebases
  • Track record of building security automation or tooling rather than relying solely on manual review
  • Familiarity with using LLMs as a core part of your security workflow
  • Experience securing agentic, code-execution, or LLM-integrated systems
Representative projects
  • Point Anthropic's internal LLM-driven code analysis and AI-assisted scanning at an acquired repository nobody here has seen, and turn the output into a prioritized remediation plan in days rather than weeks
  • Design the risk-scoring framework Anthropic uses to compare security posture across acquisitions of different shapes and sizes
  • Build the automation that onboards an acquired codebase to Anthropic's vulnerability dashboard, dependency auto-patching, and bounty scope without a human running a checklist
  • Write the security risk memo for a live deal and present it to corporate development and security leadership

The annual compensation range for this role is listed below.
For sales roles, the range provided is the role's On Target Earnings ("OTE") range, meaning that the range includes both the sales commissions/sales bonuses target and annual base salary for the role.
Annual Salary:
$320,000-$485,000 USD
Logistics
Minimum education: Bachelor's degree or an equivalent combination of education, training, and/or experience
Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience
Minimum years of experience: Years of experience required will correlate with the internal job level requirements for the position
Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices.
Visa sponsorship: We do sponsor visas! However, we aren't able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this.
We encourage you to apply even if you do not believe you meet every single qualification. Not all strong candidates will meet every single qualification as listed. Research shows that people who identify as being from underrepresented groups are more prone to experiencing imposter syndrome and doubting the strength of their candidacy, so we urge you not to exclude yourself prematurely and to submit an application if you're interested in this work. We think AI systems like the ones we're building have enormous social and ethical implications. We think this makes representation even more important, and we strive to include a range of diverse perspectives on our team.
Your safety matters to us. To protect yourself from potential scams, remember that Anthropic recruiters only contact you from @anthropic.com email addresses. In some cases, we may partner with vetted recruiting agencies who will identify themselves as working on behalf of Anthropic. Be cautious of emails from other domains. Legitimate Anthropic recruiters will never ask for money, fees, or banking information before your first day. If you're ever unsure about a communication, don't click any links-visit anthropic.com/careers directly for confirmed position openings.
How we're different
We believe that the highest-impact AI research will be big science. At Anthropic we work as a single cohesive team on just a few large-scale research efforts. And we value impact - advancing our long-term goals of steerable, trustworthy AI - rather than work on smaller and more specific puzzles. We view AI research as an empirical science, which has as much in common with physics and biology as with traditional efforts in computer science. We're an extremely collaborative group, and we host frequent research discussions to ensure that we are pursuing the highest-impact work at any given time. As such, we greatly value communication skills.
The easiest way to understand our research directions is to read our recent research. This research continues many of the directions our team worked on prior to Anthropic, including: GPT-3, Circuit-Based Interpretability, Multimodal Neurons, Scaling Laws, AI & Compute, Concrete Problems in AI Safety, and Learning from Human Preferences.
Come work with us!
Anthropic is a public benefit corporation headquartered in San Francisco. We offer competitive compensation and benefits, optional equity donation matching, generous vacation and parental leave, flexible working hours, and a lovely office space in which to collaborate with colleagues. Guidance on Candidates' AI Usage: Learn about our policy for using AI in our application process.