Security Risk Analyst, Risk Engineering

USD 270,000-345,000 per year
MIDDLE
✅ Hybrid
✅ Visa Sponsorship

Tech Stack

AI @ 2 LLM Python @ 3 R @ 3 Security @ 5

Details

Anthropic’s Security Risk team identifies, prioritizes, and drives treatment of the company’s most important security risks. The team is rebuilding risk management as an engineering function, using automation, quantitative risk, and AI-native platforms to support decision-making. The role covers Anthropic’s full security landscape and partners closely with Security Engineering to define the security program and investment decisions.

The Security Risk Analyst will take risk questions from leadership and partner teams and drive them to decisions. This may involve structured qualitative assessments or deep FAIR-based quantitative analysis. The role will communicate clear positions, tradeoffs, and uncertainty to leadership, help turn quantitative risk into reusable products and methods, and define standards for a growing risk function.

Responsibilities

  • Enable leadership and partner teams to make risk-informed decisions by driving ambiguous risk questions to documented decisions and clearly communicating quantitative and qualitative tradeoffs.
  • Lead quantitative analysis of the company’s top security risk scenarios using FAIR, calibrated estimation, and Monte Carlo simulation in Python, R, or spreadsheet tooling.
  • Work with engineers who own relevant systems and present analysis in terms leadership can act on.
  • Partner with Security Engineering to assess threat scenarios and control effectiveness, right-size security investment, and sequence remediation according to risk reduction.
  • Frame escalations and risk treatment decisions with clear recommendations, honest statements of uncertainty, and re-evaluation triggers.
  • Pressure-test decisions with risk owners.
  • Shape the analysis and narrative for leadership risk reviews.
  • Help define risk appetite and the risk metrics the organization should measure.
  • Use AI and automation to scale risk analysis and own calibration and quality review for trustworthy outputs.
  • Turn one-off analyses into reusable methods, templates, and training so risk analysis becomes increasingly self-service for partner teams.
  • Improve the analytical quality of the risk register.

Requirements

  • Experience owning security or technology risk analysis end to end, including both qualitative and quantitative analysis, with evidence that the work influenced a decision such as funding, launch, remediation sequencing, or documented risk acceptance.
  • Hands-on FAIR-style quantification experience, including scenario decomposition, calibrated estimation, and Monte Carlo simulation using Python, R, or spreadsheet tooling.
  • Ability to frame ambiguous and changing questions into analyzable problems and select an appropriate level of analytical depth.
  • Ability to assess severity and likelihood, communicate uncertainty honestly, and update conclusions when evidence changes.
  • Sufficient technical security depth to decompose attack paths with security engineers.
  • Ability to summarize complex risk positions concisely for CISO-level audiences, make tradeoffs explicit, and defend recommendations under questioning.
  • Experience using Claude or other LLMs as daily working tools, with the ability to critically review model output.
  • Collaborative, low-ego working style and an interest in AI safety and the role of security risk.

Additional Qualifications

  • Experience applying FAIR-CAM or another structured approach to control effectiveness and attack path modeling.
  • Experience building or operating a cyber risk quantification program, or turning quantitative analysis into tooling, templates, or training.
  • Experience defining risk appetite or tolerance thresholds used for organizational decisions.
  • Background in security engineering, detection, threat intelligence, actuarial science, or decision science.
  • Familiarity with security risks specific to AI systems, such as goal or intent modification, and their impact on traditional threat models.

Education and Experience

  • Minimum education: Bachelor’s degree or an equivalent combination of education, training, and experience.
  • Required field of study: A field relevant to the role, demonstrated through coursework, training, or professional experience.
  • Required years of experience correlate with the internal job level requirements for the position.

Work Policy

Anthropic currently expects all staff to work from one of its offices at least 25% of the time, although some roles may require more office time.

Compensation

The annual salary range is $270,000–$345,000 USD.

Benefits

Anthropic offers competitive compensation and benefits, optional equity donation matching, generous vacation and parental leave, flexible working hours, and office space for collaboration.

More jobs at Anthropic

Similar jobs