Lead, Security Controls Assurance - SOX
San Francisco, CA | Seattle, WA | New York City, NY | Washington, DC
Posted 5d ago
About the job
Anthropic's Security Governance, Risk, and Compliance (GRC) team is responsible for ensuring the company meets its security and control commitments. This role focuses on the Sarbanes-Oxley (SOX) control environment over the technology stack, crucial for a public company. The position involves defining control requirements and acceptance criteria for IT general controls (ITGCs) in partnership with Internal Audit, and validating that implemented systems meet these requirements. The role also encompasses owning product management for control design methodology and continuous control monitoring, initially for ITGCs and expanding to other security and compliance areas.
Responsibilities
- Define control requirements and acceptance criteria for ITGC domains (logical access, change management, computer operations, program development) for SOX-in-scope systems, including custom platforms.
- Establish system requirements for auditability, segregation of duties, change control, immutable logging, and evidence retention for new or migrated financially significant systems before go-live.
- Review major infrastructure, system, and agent framework changes for SOX impact during the design phase, identifying changes affecting SOX scope, key control populations, or evidence requirements.
- Implement and manage second-line control monitoring and automated evidence collection for ITGCs, aiming to increase automated evidence coverage and reduce audit preparation time.
- Drive control deficiency remediation by tracking and root-causing ITGC deficiencies, partnering with engineering owners on remediation design, and assessing remediation effectiveness.
- Assess the SOX impact of new products, entities, systems, or integrations on control design, evidence requirements, and engineering effort.
- Ensure alignment with other compliance frameworks (e.g., SOC 2, ISO 27001/42001) by designing controls once and evidencing them once, preventing cross-framework conflicts.
Requirements
- Ability to thrive in a fast-paced environment, making decisions with incomplete information and reprioritizing as needed.
- Experience leading or significantly contributing to an ITGC program through SOX 404 readiness and/or at a public company.
- Working knowledge of PCAOB AS 2201, COSO 2013, and external auditor methodologies for technology controls.
- Genuine engineering fluency, including the ability to read code and Terraform, understand CI/CD pipelines, and challenge technical designs.
- Programming skills in Python or a systems language like Go, Rust, or C/C++.
- Deep familiarity with control domains such as developer platforms, release engineering, cloud infrastructure, or ERP/financial systems.
- Understanding of the second-line role, advising and challenging engineering without taking ownership of their controls.
- Strong collaboration and communication skills with Finance, Engineering, Internal Audit, and external auditors.
- Experience using LLMs like Claude as daily working tools, with practical insights into AI's current capabilities in SOX assurance workflows.
- Ability to translate SOX and framework language into actionable engineering criteria and communicate engineering realities back to auditors and leadership.
- A preference for designing requirements into systems rather than relying solely on procedural workarounds.