Security Audit & Controls, Security GRC

USD 270,000-345,000 per year
MIDDLE
✅ Hybrid
✅ Visa Sponsorship

Tech Stack

AI @ 3 Audit @ 3 Change Management Communication @ 6 Compliance @ 3 LLM Scoping @ 3 Security @ 3

Details

Anthropic's Security Governance, Risk, and Compliance team translates regulatory, customer, and voluntary obligations into security controls and provides leadership with visibility into control performance. The Security Audit & Controls team owns the Common Control Framework (CCF) and the assurance view across all control domains.

This individual contributor role owns the CCF across access and change management, logging, encryption, people controls, and other domains. The role involves drafting and validating control descriptions, building continuous monitoring, driving remediation to closure, and using Claude to assist with control mapping, evidence testing, and monitoring while maintaining appropriate human judgment.

Responsibilities

  • Own the Common Control Framework, including its canonical control set, mappings to SOC 2, ISO 27001/42001, HIPAA, FedRAMP, and customer commitments, as well as the process for adding, retiring, or revising controls.
  • Draft and validate control descriptions and activities with control owners, specifying who performs each activity, how often it occurs, which system is involved, and what evidence demonstrates completion.
  • Design and operate continuous monitoring of control effectiveness, including metrics, automated tests, false-positive tuning, early identification of failures, and a controls maturity model.
  • Verify remediation and transition fixes into steady state by advising on control design and implementation, confirming fixes against auditor requirements, maintaining authoritative control and finding status, and standardizing or automating evidence collection where appropriate.
  • Map new frameworks and commitments onto the CCF and support gap assessments for new frameworks, certifications, products, or entities.
  • Support integrated and customer audits through readiness checks, walkthrough preparation, evidence request lists, and communication of external findings to GRC.
  • Evaluate the completeness and accuracy of system-generated and AI-generated evidence and define standards for audit-ready evidence.
  • Use Claude to automate control mapping, evidence testing, and monitoring, and verify machine-drafted control language before it becomes the official record.

Requirements

  • Several years of experience in IT audit, security compliance, or controls assurance, including hands-on ownership of a control framework or control library across multiple frameworks such as SOC 2, ISO 27001, FedRAMP, or HIPAA.
  • Working knowledge of audit scoping, walkthroughs, sampling, design and operating effectiveness, deficiency evaluation, and evidence reliability.
  • Experience writing control descriptions, control activities, and test procedures used by internal teams and external auditors.
  • Experience with continuous controls monitoring or automated evidence collection, whether through building, operating, or auditing such programs.
  • Sufficient technical fluency to read a runbook, configuration, or pipeline definition and assess whether it enforces the stated control.
  • Strong written communication skills.
  • Ability to influence control owners and partner teams to prioritize and close work without direct authority.
  • A bachelor's degree in a related field or equivalent experience.

Preferred Qualifications

  • Experience designing or rebuilding a common controls framework and remapping existing frameworks onto it.
  • Experience establishing continuous controls monitoring or automated evidence programs, including assessing coverage and false-positive rates.
  • Experience applying large language models to assurance work, such as control drafting, framework mapping, evidence testing, or monitoring.
  • Experience defining or assessing controls for AI systems, production agents, or internally developed systems.
  • Experience defining requirements for a homegrown GRC platform and collaborating with its engineers.
  • CISA, CISSP, or similar certification is welcome but not required.
  • Prior AI-industry experience is not required.

Work Arrangement and Benefits

The role follows a location-based hybrid policy, with staff expected to work from one of Anthropic's offices at least 25% of the time, although some roles may require more office time. Anthropic offers competitive compensation and benefits, optional equity donation matching, generous vacation and parental leave, flexible working hours, and office collaboration space. Anthropic sponsors visas, although sponsorship is evaluated based on the role and candidate.

More jobs at Anthropic

Similar jobs