Security Risk & Compliance, Agent Security

USD 255,000-345,000 per year
SENIOR
✅ Hybrid
✅ Visa Sponsorship

Tech Stack

AI @ 4 Compliance @ 7 LLM @ 4 Security @ 7

Details

Anthropic’s Security Governance, Risk, and Compliance (GRC) team translates regulatory, customer, and voluntary obligations into controls and provides leadership visibility into security performance. The team is developing a GRC model that uses Claude, with humans in the loop, to continuously challenge and evidence control performance.

Responsibilities

  • Serve as the security policy partner for AI agent governance, authoring policies and standards for how agents are built, deployed, and operated.
  • Define review and approval criteria for when an agent may interact with sensitive or regulated data and which actions require human approval in relation to compliance frameworks.
  • Serve as the GRC reviewer within existing engineering approval workflows.
  • Define data governance requirements for agents, including least-privilege access, access reviews, and handling of regulated and sensitive data.
  • Monitor agent behavior over time and adapt governance requirements in partnership with cross-functional security, research, and engineering teams.
  • Map agent security and data controls to AI governance frameworks, including ISO 27001, ISO 42001, and the EU AI Act, strengthening Anthropic’s certification efforts and ensuring agent security is auditable.
  • Assess and document agent-related security and compliance risks and drive them to resolution with engineering owners.
  • Own the policy for agent-related risk acceptances and exceptions, including approval authority, duration, and re-review.

Requirements

  • 8+ years of experience in security governance, risk, and compliance, including ownership of security policies and control standards at a technology company.
  • Experience owning or meaningfully supporting efforts to compartmentalize sensitive data, personally identifiable information, or intellectual property.
  • Understanding of how identity and access mechanisms implement or undermine protection boundaries.
  • Ability to treat non-human identities as a distinct risk and control category and design least-privilege access and accountability controls for systems acting on a person’s behalf.
  • Ability to reason from a threat model to a control and explain the tradeoffs to engineers and auditors.
  • Experience defining risk-based review or approval criteria within engineering workflows and keeping them effective in high-change environments.
  • Ability to deliver clear, precise written work for technical and non-technical audiences.
  • Comfort working in ambiguous environments without an established industry playbook and proposing standards.
  • Ability to educate and influence security outcomes as a security and risk authority.

Preferred Qualifications

  • Understanding of the security properties of LLM agents through experience with an AI, developer-platform, or agent-tooling company, or comparable experience.
  • Familiarity with AI governance frameworks and traditional security frameworks.
  • Experience adapting controls from regulated or highly sensitive environments to an open, high-trust engineering culture.
  • Relevant certifications such as CISSP, CISM, CRISC, CISA, CCSP, ISO 27001 Lead Implementer/Auditor, or ISO 42001 Lead Implementer/Auditor.

Candidates do not need to have completed every item listed. Anthropic values reasoning about access, accountability, and blast radius, particularly because few people have governed AI agents at scale.

Education and Logistics

  • Minimum education: Bachelor’s degree or an equivalent combination of education, training, and experience.
  • Required field of study: A field relevant to the role, as demonstrated through coursework, training, or professional experience.
  • Minimum years of experience: Experience requirements correlate with the internal job level.
  • Location-based hybrid policy: Staff are currently expected to work from one of Anthropic’s offices at least 25% of the time, although some roles may require more office time.
  • Applications are accepted on a rolling basis with no stated deadline.

Benefits

Anthropic offers competitive compensation and benefits, optional equity donation matching, generous vacation and parental leave, flexible working hours, and office spaces for collaboration.

More jobs at Anthropic

Similar jobs