Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 4
Compliance @ 7
LLM @ 4
Security @ 7
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Anthropic’s Security Governance, Risk, and Compliance (GRC) team translates regulatory, customer, and voluntary obligations into controls and provides leadership visibility into security performance. The team is developing a GRC model that uses Claude, with humans in the loop, to continuously challenge and evidence control performance.
Responsibilities
- Serve as the security policy partner for AI agent governance, authoring policies and standards for how agents are built, deployed, and operated.
- Define review and approval criteria for when an agent may interact with sensitive or regulated data and which actions require human approval in relation to compliance frameworks.
- Serve as the GRC reviewer within existing engineering approval workflows.
- Define data governance requirements for agents, including least-privilege access, access reviews, and handling of regulated and sensitive data.
- Monitor agent behavior over time and adapt governance requirements in partnership with cross-functional security, research, and engineering teams.
- Map agent security and data controls to AI governance frameworks, including ISO 27001, ISO 42001, and the EU AI Act, strengthening Anthropic’s certification efforts and ensuring agent security is auditable.
- Assess and document agent-related security and compliance risks and drive them to resolution with engineering owners.
- Own the policy for agent-related risk acceptances and exceptions, including approval authority, duration, and re-review.
Requirements
- 8+ years of experience in security governance, risk, and compliance, including ownership of security policies and control standards at a technology company.
- Experience owning or meaningfully supporting efforts to compartmentalize sensitive data, personally identifiable information, or intellectual property.
- Understanding of how identity and access mechanisms implement or undermine protection boundaries.
- Ability to treat non-human identities as a distinct risk and control category and design least-privilege access and accountability controls for systems acting on a person’s behalf.
- Ability to reason from a threat model to a control and explain the tradeoffs to engineers and auditors.
- Experience defining risk-based review or approval criteria within engineering workflows and keeping them effective in high-change environments.
- Ability to deliver clear, precise written work for technical and non-technical audiences.
- Comfort working in ambiguous environments without an established industry playbook and proposing standards.
- Ability to educate and influence security outcomes as a security and risk authority.
Preferred Qualifications
- Understanding of the security properties of LLM agents through experience with an AI, developer-platform, or agent-tooling company, or comparable experience.
- Familiarity with AI governance frameworks and traditional security frameworks.
- Experience adapting controls from regulated or highly sensitive environments to an open, high-trust engineering culture.
- Relevant certifications such as CISSP, CISM, CRISC, CISA, CCSP, ISO 27001 Lead Implementer/Auditor, or ISO 42001 Lead Implementer/Auditor.
Candidates do not need to have completed every item listed. Anthropic values reasoning about access, accountability, and blast radius, particularly because few people have governed AI agents at scale.
Education and Logistics
- Minimum education: Bachelor’s degree or an equivalent combination of education, training, and experience.
- Required field of study: A field relevant to the role, as demonstrated through coursework, training, or professional experience.
- Minimum years of experience: Experience requirements correlate with the internal job level.
- Location-based hybrid policy: Staff are currently expected to work from one of Anthropic’s offices at least 25% of the time, although some roles may require more office time.
- Applications are accepted on a rolling basis with no stated deadline.
Benefits
Anthropic offers competitive compensation and benefits, optional equity donation matching, generous vacation and parental leave, flexible working hours, and office spaces for collaboration.
More jobs at Anthropic
Manager, Applied AI Engineering (Megas)
Anthropic · New York City, United States, San Francisco, United States, Seattle, United States
USD 320,000-405,000 per year
Security Risk Analyst, Risk Engineering
Anthropic · New York City, United States, San Francisco, United States
USD 270,000-345,000 per year
Staff + Software Security Engineer, Labs
Anthropic · New York City, United States, San Francisco, United States, Seattle, United States
USD 320,000-485,000 per year
US Public Sector Compliance, Security GRC
Anthropic · New York City, United States, San Francisco, United States
USD 255,000-270,000 per year
AV Engineer, Platform & Automation
Anthropic · New York City, United States, San Francisco, United States
USD 285,000-325,000 per year
Similar jobs
Technical Deployment Lead
Anthropic · Austin, United States, Boston, United States, New York City, United States, San Francisco, United States, Seattle, United States
USD 275,000-380,000 per year
Lead, Security Controls Assurance - SOX
Anthropic · Washington, United States, New York City, United States, San Francisco, United States, Seattle, United States
USD 410,000-510,000 per year
Security Audit & Controls, Security GRC
Anthropic · New York City, United States, San Francisco, United States, Seattle, United States
USD 270,000-345,000 per year
Product Manager, Claude Science
Anthropic · New York City, United States, San Francisco, United States, Seattle, United States
USD 305,000-385,000 per year
Staff Software Engineer, Claude Code
Anthropic · New York City, United States, San Francisco, United States, Seattle, United States
USD 320,000-625,000 per year
Senior Software Engineer, Full-Stack
Anthropic · New York City, United States, San Francisco, United States, Seattle, United States
USD 320,000 per year
Engineering Manager, GRC Platform
Anthropic · New York City, United States, San Francisco, United States, Seattle, United States
USD 320,000-405,000 per year
AI Deployment Specialist, Beneficial Deployments
Anthropic · New York City, United States, San Francisco, United States
USD 0 per year