Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 4
Audit @ 4
CI/CD @ 6
Communication @ 7
Compliance
Go @ 6
LLM
Leadership @ 6
Machine Learning
Python @ 6
Rust @ 6
Security
Terraform @ 6
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Anthropic’s Security Governance, Risk, and Compliance (GRC) team translates regulatory, customer, and voluntary obligations into actionable controls and provides leadership with visibility into the effectiveness of the security control environment. The technical controls assurance function defines control requirements and acceptance criteria for global compliance obligations, partners with engineering throughout the software development lifecycle, and validates that shipped systems meet those requirements.
Responsibilities
- Define the control framework and requirements for autonomous AI operators in collaboration with Security, Internal Audit, and Engineering, including change review and approvals, human-in-the-loop requirements, and evidence collection.
- Assess implementations against control requirements.
- Pressure-test major infrastructure, system, and agent framework changes for control impact during design.
- Set compliance requirements for internally developed systems, including auditability, segregation of duties, and change control.
- Define criteria for where and when AI can operate, supplement, or replace manual processes or controls, including human-in-the-loop thresholds and evidence documentation.
- Establish validation, evidence, and governance standards for AI-performed and AI-assisted processes and controls to withstand external audit and regulatory scrutiny.
- Assess new compliance frameworks and changes in scope, including regulations, certifications, products, and entities, and evaluate their impact on control design, evidence requirements, and engineering effort.
- Establish or advise on audit workflows, including Claude-driven control testing, automated evidence collection, walkthrough preparation, and framework mapping against the common controls framework.
- Increase automated evidence coverage and reduce audit preparation time.
Requirements
- Experience supporting technology control programs through SOX readiness, as a public company, or with equivalent rigor such as FedRAMP or large multi-framework SOC 2/ISO portfolios.
- Engineering fluency, including the ability to read code and Terraform, follow a CI/CD pipeline end to end, and challenge designs on their technical merits.
- Programming skills in Python or a systems language such as Go, Rust, or C/C++.
- Deep familiarity with developer platforms, release engineering, or infrastructure control domains.
- Strong collaboration and communication skills.
- Daily use of Claude and other LLMs, with specific views on which audit and assurance workflows AI can perform today and which it cannot yet.
- Ability to translate framework and regulatory language into acceptance criteria engineers can build against, and translate engineering realities into assurance language for auditors and leadership.
- Preference for designing requirements into systems rather than addressing gaps solely through procedures.
- A bachelor’s degree or equivalent combination of education, training, and experience in a field relevant to the role.
Preferred Qualifications
- A combination of audit or advisory experience, such as Big Four or equivalent, and in-house experience at an AI-focused technology company.
- Experience defining or assessing controls for AI/ML systems or agents operating in production environments.
- Experience establishing continuous controls monitoring or automated evidence programs.
Additional Information
The role does not require writing production code day to day, but requires sufficient technical fluency to review, challenge, and specify requirements. The annual salary range is $270,000–$345,000 USD. Anthropic expects staff to work from one of its offices at least 25% of the time under its location-based hybrid policy. Anthropic explicitly states that it sponsors visas, although sponsorship is evaluated by role and candidate. The company offers competitive compensation and benefits, optional equity donation matching, vacation and parental leave, flexible working hours, and office space for collaboration.