Security Audit & Controls, Security GRC

USD 0 per year
MIDDLE
✅ Hybrid
✅ Visa Sponsorship

Tech Stack

AI @ 3 Audit @ 3 Communication @ 6 Compliance @ 3 LLM Scoping @ 3 Security @ 3

Details

Anthropic's Security Governance, Risk, and Compliance (GRC) team translates regulatory, customer, and voluntary obligations into actionable security controls and provides leadership with visibility into control performance. The Security Audit & Controls role owns the Common Control Framework (CCF) and the assurance view across all control domains.

Responsibilities

  • Own the Common Control Framework, including its mappings to SOC 2, ISO 27001, ISO 42001, HIPAA, FedRAMP, and customer commitments.
  • Manage the process for adding, retiring, and revising controls.
  • Draft and validate control descriptions and activities with control owners, specifying responsibilities, frequency, systems, and required evidence.
  • Design and run continuous monitoring of control effectiveness, including metrics, automated tests, false-positive tuning, failure escalation, and control maturity modeling.
  • Verify remediation against auditor requirements and maintain a single source of truth for control and finding status.
  • Standardize, automate, or continuously monitor evidence collection after remediation is complete.
  • Map new frameworks and commitments onto the CCF and support gap assessments for new frameworks, certifications, products, and entities.
  • Support integrated and customer audits through readiness checks, walkthrough preparation, evidence request lists, and external-finding readouts.
  • Evaluate the completeness and accuracy of system-generated and AI-generated evidence.
  • Use Claude to automate control mapping, evidence testing, and monitoring, while verifying machine-drafted control language.

Requirements

  • Several years of experience in IT audit, security compliance, or controls assurance, including hands-on ownership of a control framework or control library across multiple frameworks.
  • Working knowledge of audit scoping, walkthroughs, sampling, design and operating effectiveness, deficiency evaluation, and evidence reliability.
  • Experience writing control descriptions, control activities, and test procedures used by internal teams and external auditors.
  • Experience with continuous controls monitoring or automated evidence collection.
  • Technical fluency sufficient to read runbooks, configurations, and pipeline definitions and assess whether they enforce stated controls.
  • Strong written communication skills.
  • Ability to coordinate control owners and partner teams to prioritize and close work without direct authority.
  • Bachelor's degree in a related field or equivalent experience.

Preferred Qualifications

  • Experience designing or rebuilding a common controls framework and remapping existing frameworks onto it.
  • Experience establishing continuous controls monitoring or automated evidence programs.
  • Experience applying LLMs to assurance work, including control drafting, framework mapping, evidence testing, or monitoring.
  • Experience defining or assessing controls for AI systems, production agents, or internally developed systems.
  • Experience providing requirements for a custom GRC platform and collaborating with its engineers.
  • CISA, CISSP, or similar certifications are welcome but not required.

Work Policy

This is an individual contributor role with a hybrid policy. Staff are expected to work from one of Anthropic's offices at least 25% of the time, though some roles may require more office time. Anthropic sponsors visas, subject to role and candidate eligibility.

More jobs at Anthropic

Similar jobs