Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 6
AWS @ 4
Audit @ 4
Azure @ 4
CI/CD @ 4
Change Management @ 4
Communication @ 7
Compliance @ 4
DevOps @ 4
GCP @ 4
GitHub @ 3
Project Management @ 7
Salesforce @ 3
Security
Software Development @ 4
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Join Anthropic’s Internal Audit team as a hands-on technical contributor and key executor of the IT SOX compliance program, focusing on IT General Controls, IT Application Controls, and system risk assessments. The role partners with Engineering, GRC, Security, Finance, IT, and DevOps teams to establish a scalable control environment for an AI-first company and reports to the Head of IT SOX.
Responsibilities
- Advise on control environments for highly automated DevOps pipelines and emerging agentic identity models.
- Partner with Engineering, Security, IT, and DevOps teams to assess scalable and sustainable controls.
- Assess new system implementations and changes.
- Identify automation and tooling opportunities and contribute to continuous monitoring capabilities.
- Assist with annual SOX IT assessment scoping and planning.
- Execute IT SOX testing across IT General Controls and IT Application Controls, including access management, change management, and computer operations.
- Perform system and process risk assessments, identify control gaps, and recommend remediation.
- Own control documentation and maintain current, complete, audit-ready evidence.
- Evaluate automated IT controls and support the transition from manual to automated control reliance.
- Scale the IT SOX program by rationalizing scope, standardizing testing approaches, and building repeatable processes.
- Guide internal team members and co-sourced partners, including setting priorities and reviewing workpapers.
- Build relationships with process and control owners and translate technical control requirements for technical and non-technical stakeholders.
- Support SEC cybersecurity disclosure requirements and related risk monitoring.
- Coordinate with external auditors on evidence requests, walkthroughs, and testing schedules.
- Track audit finding remediation and communicate status to stakeholders.
Requirements
- Hands-on IT audit or IT SOX compliance experience, ideally in a fast-paced technology environment.
- Deep knowledge of ITGCs, ITACs, and IT risk assessment methodologies.
- Experience auditing automated DevOps environments, including CI/CD pipelines, infrastructure-as-code, and automated deployments.
- Experience designing, testing, and documenting access management, change management, and computer operations controls.
- Ability to work independently on complex and ambiguous workstreams and communicate with senior stakeholders.
- Ability to guide internal team members and co-sourced partners.
- Strong project management, organizational, communication, and attention-to-detail skills.
- Bachelor’s degree or equivalent combination of education, training, and experience.
Preferred Qualifications
- 8+ years of hands-on IT audit and SOX compliance experience, including Big 4 or comparable experience.
- Experience with cloud environments such as GCP, AWS, and/or Azure.
- Experience scaling compliance, audit, or SOX programs to public-company standards during rapid growth.
- Familiarity with Workday, Salesforce, or GitHub.
- Experience evaluating SDLC controls in modern software development environments.
- CISA, CIA, CISSP, CPA, or equivalent certification.
- Interest in applying AI to audit work and evaluating controls in AI-embedded processes.
Compensation
Annual salary: $230,000–$300,000 USD.
Benefits
Anthropic offers competitive compensation and benefits, optional equity donation matching, generous vacation and parental leave, flexible working hours, and an office space for collaboration.
Work Arrangement
The role follows a location-based hybrid policy, with staff expected to work from an Anthropic office at least 25% of the time. Anthropic states that it sponsors visas and will make reasonable efforts to support visa applications, although sponsorship is not guaranteed for every role or candidate.