Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Audit @ 3
Compliance @ 3
LLM @ 3
Scoping @ 3
Security @ 3
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Anthropic’s Supplier Security & Assurance team, within Security GRC, assesses the security of suppliers across SaaS and software, human data operations, compute and data center providers, hardware suppliers, and services firms. The program is designed to be agent-first, allowing people to focus on judgment, remediation, and high-priority vendors.
The role runs supplier security assessments end to end, verifies agent-drafted evaluations, determines inherent and residual risk, drives findings to closure, and extends assurance through contractual security terms, secure configuration baselines, continuous monitoring, and reassessment. The role also helps shape the tooling and requirements used by the program.
Responsibilities
- Run supplier security assessments by reviewing agent-prefilled outputs, evaluating vendor controls and evidence, determining residual risk, and routing assessments to domain reviewers when deeper analysis is required.
- Operate supplier issue management and risk treatment by documenting findings with severity, ownership, and due dates; driving remediation with vendors and business owners; recording risk acceptances; and escalating open issues to the risk register.
- Run continuous monitoring after approval, including reopening assessments following data classification changes, new SOC 2 reports, new subprocessors, or vendor incidents.
- Investigate SaaS configuration, data, and use-case drift signals and queue reassessments when vendor scope changes.
- Improve questionnaires, requirements, tooling, and program coverage, and carry roadmap items that mature supplier security.
- Tune and maintain the Claude-powered assessment platform through prompt development, questionnaire and assessment-type design, calibration against assessor decisions, and output quality assurance.
- Contribute to KPI and KRI reporting on coverage, cycle time, residual risk, open issues, and reassessments due.
Requirements
- Experience running supplier security assessments end to end at a technology company, including scoping engagements, determining inherent risk, reviewing controls and evidence, documenting residual risk, and driving findings to closure.
- Working knowledge of risk fundamentals, including inherent and residual risk, control effectiveness, compensating controls, and risk acceptance.
- Ability to assess vendors across security domains and identify which findings can be closed independently versus those requiring a security domain specialist.
- Track record of driving risk treatment to closure through influence across teams with competing priorities.
- Experience building or tuning an LLM-backed workflow, agent, or automation in a risk, compliance, or operations context, including prompt tuning and model-output accuracy review.
- Experience building or operating issue-management workflows with clear owners, due dates, remediation tracking, and escalation.
- Working technical knowledge of SaaS security configuration, including SSO and SCIM, administrator scoping, sharing defaults, and audit-log export.
- Knowledge of standard vendor security contract terms, including DPAs, incident notification, subprocessors, and audit and testing rights.
- Ability to read SOC 2 reports or penetration tests, identify control exceptions and carve-outs, map complementary user entity controls, and determine what evidence does and does not prove.
- Bachelor’s degree or an equivalent combination of education, training, and experience. Relevant field of study demonstrated through coursework, training, or professional experience.
Preferred Qualifications
- Experience assessing cloud infrastructure, data center, or data-pipeline vendors.
- Experience supporting SOX, SOC 2, or ISO 27001 third-party or vendor-management controls.
- Experience assessing human data operations or data-labeling vendors, hardware suppliers, compute providers, neoclouds, and other specialized vendor cohorts from a security-risk perspective.
- Experience with post-approval supplier continuous monitoring, including configuration, data, and use-case drift detection, shadow IT and SaaS detection, vendor incident management, or evidence-based vendor audits and site visits.
Benefits
Anthropic offers competitive compensation and benefits, optional equity donation matching, generous vacation and parental leave, flexible working hours, and an office space for collaboration.