Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 3
Audit @ 3
Communication @ 6
Compliance @ 3
LLM
Scoping @ 3
Security @ 3
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Anthropic's Security Governance, Risk, and Compliance (GRC) team translates regulatory, customer, and voluntary obligations into actionable security controls and provides leadership with visibility into control performance. The Security Audit & Controls role owns the Common Control Framework (CCF) and the assurance view across all control domains.
Responsibilities
- Own the Common Control Framework, including its mappings to SOC 2, ISO 27001, ISO 42001, HIPAA, FedRAMP, and customer commitments.
- Manage the process for adding, retiring, and revising controls.
- Draft and validate control descriptions and activities with control owners, specifying responsibilities, frequency, systems, and required evidence.
- Design and run continuous monitoring of control effectiveness, including metrics, automated tests, false-positive tuning, failure escalation, and control maturity modeling.
- Verify remediation against auditor requirements and maintain a single source of truth for control and finding status.
- Standardize, automate, or continuously monitor evidence collection after remediation is complete.
- Map new frameworks and commitments onto the CCF and support gap assessments for new frameworks, certifications, products, and entities.
- Support integrated and customer audits through readiness checks, walkthrough preparation, evidence request lists, and external-finding readouts.
- Evaluate the completeness and accuracy of system-generated and AI-generated evidence.
- Use Claude to automate control mapping, evidence testing, and monitoring, while verifying machine-drafted control language.
Requirements
- Several years of experience in IT audit, security compliance, or controls assurance, including hands-on ownership of a control framework or control library across multiple frameworks.
- Working knowledge of audit scoping, walkthroughs, sampling, design and operating effectiveness, deficiency evaluation, and evidence reliability.
- Experience writing control descriptions, control activities, and test procedures used by internal teams and external auditors.
- Experience with continuous controls monitoring or automated evidence collection.
- Technical fluency sufficient to read runbooks, configurations, and pipeline definitions and assess whether they enforce stated controls.
- Strong written communication skills.
- Ability to coordinate control owners and partner teams to prioritize and close work without direct authority.
- Bachelor's degree in a related field or equivalent experience.
Preferred Qualifications
- Experience designing or rebuilding a common controls framework and remapping existing frameworks onto it.
- Experience establishing continuous controls monitoring or automated evidence programs.
- Experience applying LLMs to assurance work, including control drafting, framework mapping, evidence testing, or monitoring.
- Experience defining or assessing controls for AI systems, production agents, or internally developed systems.
- Experience providing requirements for a custom GRC platform and collaborating with its engineers.
- CISA, CISSP, or similar certifications are welcome but not required.
Work Policy
This is an individual contributor role with a hybrid policy. Staff are expected to work from one of Anthropic's offices at least 25% of the time, though some roles may require more office time. Anthropic sponsors visas, subject to role and candidate eligibility.
More jobs at Anthropic
Program Manager, Safeguards Policy, Enforcement, and Threat Intelligence
Anthropic · San Francisco, United States
USD 285,000-330,000 per year
Security Audit & Controls, Security GRC
Anthropic · New York City, United States, San Francisco, United States, Seattle, United States
USD 270,000-345,000 per year
Staff Research Engineer, Multi-Agent Scaling
Anthropic · New York City, United States, San Francisco, United States, Seattle, United States
USD 500,000-850,000 per year
Technical Program Manager, Life Sciences
Anthropic · New York City, United States, San Francisco, United States
USD 290,000-365,000 per year
Software Engineer, Sandboxing
Anthropic · New York City, United States, San Francisco, United States
USD 320,000-485,000 per year
Similar jobs
Lead, Security Controls Assurance - SOX
Anthropic · Washington, United States, New York City, United States, San Francisco, United States, Seattle, United States
USD 410,000-510,000 per year
Customer Trust Specialist
Anthropic · New York City, United States, San Francisco, United States, Seattle, United States
USD 255,000-270,000 per year
Forward Deployed Engineer (FDE), Financial Services – New York City
OpenAI · New York City, United States
USD 185,000-300,000 per year
Staff Workday Integration Engineer, Tech Foundations
Airbnb · United States
USD 180,000-225,000 per year
Senior Engineer - Enterprise Data Governance
Nvidia · Santa Clara, United States
USD 168,000-322,000 per year
Manager, Technical Deployment (Financial Services)
Anthropic · New York City, United States
USD 240,000-450,000 per year
Principal Engineer - Enterprise Content and AI Data Platform
Nvidia · Santa Clara, United States
USD 248,000-391,000 per year
Senior AI Engineer
Grafana Labs · United States
USD 154,400-185,300 per year