Lead, Security Controls Assurance - SOX
📍 New York City, United States
📍 San Francisco, United States
📍 Seattle, United States
Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 4
Audit @ 4
CI/CD @ 6
Change Management
Communication @ 7
Compliance
Go @ 6
LLM
Machine Learning
Python @ 6
Rust @ 6
Security
Terraform @ 6
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Anthropic's Security Governance, Risk, and Compliance (GRC) team translates regulatory, customer, and voluntary obligations into controls and provides leadership visibility into control performance. The team is building toward continuous assurance through continuous control challenge and evidence collection rather than periodic audits.
As Anthropic prepares to become a public company, the SOX control environment covering its technology stack is a key responsibility. This role leads technical controls assurance for SOX IT general controls (ITGCs), defining control requirements and acceptance criteria for engineering systems and infrastructure supporting financial reporting. The role partners with Engineering to design and implement controls, validates that systems meet requirements before Internal Audit and external auditor testing, and owns control design methodology and continuous control monitoring.
Responsibilities
- Define control requirements and acceptance criteria across logical access, change management, computer operations, and program development for SOX in-scope systems, including internally built platforms.
- Establish requirements for auditability, segregation of duties, change control, immutable logging, and evidence retention before financially significant systems go live.
- Review infrastructure, system, and agent framework changes for SOX impact during the design phase, including changes to SOX scope, key control populations, and evidence requirements.
- Own second-line control monitoring and evidence readiness, including continuous controls monitoring, automated evidence collection, control testing, walkthrough preparation, population and completeness validation, and mapping to the common controls framework.
- Drive remediation of ITGC deficiencies identified by monitoring, Internal Audit, or external audit; partner with engineering owners on remediation design and assess whether remediation closes the gap before re-testing.
- Assess the impact of new products, entities, systems, and integrations on control design, evidence requirements, and engineering effort.
- Maintain alignment across SOX ITGCs, SOC 2, ISO 27001/42001, and other compliance frameworks so controls are designed and evidenced consistently.
Requirements
- Experience leading or serving as a senior contributor to an ITGC program through SOX 404 readiness and/or at a public company.
- Working knowledge of PCAOB AS 2201, COSO 2013, and how external auditors scope, test, and evaluate technology controls and deficiencies.
- Engineering fluency, including the ability to read code and Terraform, follow CI/CD pipelines end to end, and challenge technical designs.
- Programming skills in Python or at least one systems language such as Go, Rust, or C/C++.
- Deep familiarity with developer platforms, release engineering, cloud infrastructure, or ERP and financial systems control domains.
- Understanding of the second-line function, including advising and challenging Engineering without owning its controls and distinguishing second-line monitoring from Internal Audit’s independent testing.
- Strong collaboration and communication skills across Finance, Engineering, Internal Audit, and external auditors.
- Experience using Claude and other LLMs as daily working tools, with informed views on which SOX assurance workflows AI can currently perform.
- Ability to translate SOX and framework requirements into engineering acceptance criteria and translate engineering implementation details into assurance language.
- Bachelor’s degree or equivalent education, training, and/or experience in a relevant field.
Preferred Qualifications
- Audit or advisory experience, ideally IT audit, combined with in-house experience at an AI-focused technology company.
- Experience taking a company through first-year SOX 404(a) and 404(b) assessments, including a first external ITGC audit.
- Experience defining or assessing controls for internally built financially significant systems, usage-based billing, or revenue metering pipelines.
- Experience defining or assessing controls for AI/ML systems or production agents.
- Experience establishing continuous controls monitoring or automated evidence programs.
- Experience with SOC 1 reliance, service organization control mapping, and complementary user entity controls.
- CISSP, CISA, CPA, or equivalent certification.
Compensation
- Annual salary: $410,000–$510,000 USD
Work Arrangement
Anthropic currently expects staff to work from one of its offices at least 25% of the time, though some roles may require more office time.
Visa Sponsorship
Anthropic sponsors visas and makes reasonable efforts to obtain visas for candidates when an offer is extended, with assistance from an immigration lawyer.