Security Audit & Controls, Security GRC

Remote • San Francisco, CA | New York City, NY

Posted 5h ago

Remote Work Policy

Fully remote

Categories

Applied AI Engineer

About the job

Anthropic is building reliable, interpretable, and steerable AI systems to be safe and beneficial for users and society. The Security Governance, Risk, and Compliance (GRC) team ensures the company meets its security commitments by translating obligations into actionable controls and providing leadership with oversight. This role focuses on owning the Common Control Framework (CCF) across all control domains, ensuring accuracy, testing, and trust. You will work with control owners to define and validate controls, build continuous monitoring systems, and drive remediation efforts. A key aspect of this role involves leveraging Claude to assist in drafting and mapping controls, testing evidence, and monitoring control health, with human judgment guiding the process.

Responsibilities

  • Own the Common Control Framework, including its mappings to various frameworks and commitments, and manage the change process for controls.
  • Draft and validate control descriptions and activities with control owners, detailing responsibilities, frequency, systems, and evidence.
  • Design and execute continuous monitoring of control effectiveness, defining metrics, automated tests, and a controls maturity model.
  • Verify remediation efforts and ensure they are integrated into steady-state operations, advising on control design and implementation.
  • Map new frameworks and commitments onto the CCF and support gap assessments for new entities or products.
  • Support integrated and customer audits through readiness checks, walkthrough preparation, and evidence requests.
  • Evaluate the reliability of evidence, including system-generated and AI-generated reports, and establish standards for audit-ready evidence.
  • Utilize Claude to automate control mapping, evidence testing, and monitoring, verifying machine-drafted content.

Requirements

  • Several years of experience in IT audit, security compliance, or controls assurance, with hands-on ownership of a control framework across multiple standards (e.g., SOC 2, ISO 27001, FedRAMP, HIPAA).
  • Proficiency in audit mechanics, including scoping, walkthroughs, sampling, assessing design vs. operating effectiveness, deficiency evaluation, and evidence reliability.
  • Experience writing control descriptions, activities, and test procedures relied upon by internal teams and external auditors.
  • Experience with continuous controls monitoring or automated evidence collection.
  • Sufficient technical fluency to understand runbooks, configurations, or pipeline definitions and assess their alignment with control requirements.
  • Excellent writing skills for control language and status reports.
  • Ability to influence control owners and partner teams to prioritize and complete work without direct authority.

About Anthropic

Get new AI jobs in your inbox

A weekly digest of the newest AI engineering roles.

© 2026 AI Job Board. All rights reserved.