Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 3
Audit @ 3
Change Management
Communication @ 6
Compliance @ 3
LLM
Scoping @ 3
Security @ 3
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Anthropic's Security Governance, Risk, and Compliance team translates regulatory, customer, and voluntary obligations into security controls and provides leadership with visibility into control performance. The Security Audit & Controls team owns the Common Control Framework (CCF) and the assurance view across all control domains.
This individual contributor role owns the CCF across access and change management, logging, encryption, people controls, and other domains. The role involves drafting and validating control descriptions, building continuous monitoring, driving remediation to closure, and using Claude to assist with control mapping, evidence testing, and monitoring while maintaining appropriate human judgment.
Responsibilities
- Own the Common Control Framework, including its canonical control set, mappings to SOC 2, ISO 27001/42001, HIPAA, FedRAMP, and customer commitments, as well as the process for adding, retiring, or revising controls.
- Draft and validate control descriptions and activities with control owners, specifying who performs each activity, how often it occurs, which system is involved, and what evidence demonstrates completion.
- Design and operate continuous monitoring of control effectiveness, including metrics, automated tests, false-positive tuning, early identification of failures, and a controls maturity model.
- Verify remediation and transition fixes into steady state by advising on control design and implementation, confirming fixes against auditor requirements, maintaining authoritative control and finding status, and standardizing or automating evidence collection where appropriate.
- Map new frameworks and commitments onto the CCF and support gap assessments for new frameworks, certifications, products, or entities.
- Support integrated and customer audits through readiness checks, walkthrough preparation, evidence request lists, and communication of external findings to GRC.
- Evaluate the completeness and accuracy of system-generated and AI-generated evidence and define standards for audit-ready evidence.
- Use Claude to automate control mapping, evidence testing, and monitoring, and verify machine-drafted control language before it becomes the official record.
Requirements
- Several years of experience in IT audit, security compliance, or controls assurance, including hands-on ownership of a control framework or control library across multiple frameworks such as SOC 2, ISO 27001, FedRAMP, or HIPAA.
- Working knowledge of audit scoping, walkthroughs, sampling, design and operating effectiveness, deficiency evaluation, and evidence reliability.
- Experience writing control descriptions, control activities, and test procedures used by internal teams and external auditors.
- Experience with continuous controls monitoring or automated evidence collection, whether through building, operating, or auditing such programs.
- Sufficient technical fluency to read a runbook, configuration, or pipeline definition and assess whether it enforces the stated control.
- Strong written communication skills.
- Ability to influence control owners and partner teams to prioritize and close work without direct authority.
- A bachelor's degree in a related field or equivalent experience.
Preferred Qualifications
- Experience designing or rebuilding a common controls framework and remapping existing frameworks onto it.
- Experience establishing continuous controls monitoring or automated evidence programs, including assessing coverage and false-positive rates.
- Experience applying large language models to assurance work, such as control drafting, framework mapping, evidence testing, or monitoring.
- Experience defining or assessing controls for AI systems, production agents, or internally developed systems.
- Experience defining requirements for a homegrown GRC platform and collaborating with its engineers.
- CISA, CISSP, or similar certification is welcome but not required.
- Prior AI-industry experience is not required.
Work Arrangement and Benefits
The role follows a location-based hybrid policy, with staff expected to work from one of Anthropic's offices at least 25% of the time, although some roles may require more office time. Anthropic offers competitive compensation and benefits, optional equity donation matching, generous vacation and parental leave, flexible working hours, and office collaboration space. Anthropic sponsors visas, although sponsorship is evaluated based on the role and candidate.