Security Audit & Controls, Security GRC
Remote • San Francisco, CA | New York City, NY | Seattle, WA
Posted 8h ago
Job Location
San Francisco, CA | New York City, NY | Seattle, WA
Tech Stack
Remote Work Policy
Fully remote
Categories
Applied AI Engineer
About the job
Anthropic is seeking a Security Audit & Controls professional to join their Security GRC team. This role will own the Common Control Framework (CCF) across all control domains, ensuring its accuracy, mapping to various frameworks, and validating control effectiveness. You will work with control owners to define and test controls, build continuous monitoring systems, and drive remediation efforts. A significant aspect of the role involves leveraging Claude (Anthropic's AI) to automate tasks like control mapping, evidence testing, and monitoring, with human oversight for critical judgments. This is an individual contributor position for someone who excels at independent work, clear writing, and ensuring the integrity of control sets.
Responsibilities
- Own the Common Control Framework, including its mappings to various frameworks (SOC 2, ISO 27001/42001, HIPAA, FedRAMP) and customer commitments, and manage its change process.
- Draft and validate control descriptions and activities with control owners, ensuring clarity on responsibilities, systems, and evidence.
- Design and execute continuous monitoring of control effectiveness, defining metrics, automated tests, and surfacing failures to owners.
- Verify remediation efforts, advise on control design and implementation, and confirm fixes against audit requirements.
- Map new frameworks and commitments onto the CCF and support gap assessments for new scopes.
- Support integrated and customer audits by preparing for readiness checks, walkthroughs, and evidence requests.
- Evaluate the reliability of evidence, including system-generated and AI-generated reports.
- Utilize Claude to automate control mapping, evidence testing, and monitoring, verifying machine-drafted content.
Requirements
- Several years of experience in IT audit, security compliance, or controls assurance, with ownership of a control framework across multiple frameworks (e.g., SOC 2, ISO 27001, FedRAMP, HIPAA).
- Proficiency in audit mechanics, including scoping, walkthroughs, sampling, design vs. operating effectiveness, deficiency evaluation, and evidence reliability.
- Experience writing control descriptions, activities, and test procedures.
- Experience with continuous controls monitoring or automated evidence collection.
- Sufficient technical fluency to understand runbooks, configurations, or pipeline definitions.
- Clear writing skills for control language and status reports.
- Ability to influence control owners and partner teams to prioritize and close work without direct authority.