Security Risk Analyst, Risk Engineering
$270k - $345k • Remote • San Francisco, CA | New York City, NY
Posted 9h ago
About the job
The Security Risk team at Anthropic is responsible for identifying, prioritizing, and managing the company's most critical security risks. This role involves rebuilding risk management as an engineering function, leveraging automation, quantitative analysis, and AI-native platforms to inform decision-making across Anthropic's entire security landscape. You will partner closely with Security Engineering to define the security program and shape investment and treatment decisions. This position offers a direct line to CISO-level decisions, challenging the conventional GRC playbook and defining its successor.
Responsibilities
- Enable leadership and partner teams to make risk-informed decisions by driving ambiguous risk questions to documented conclusions and clearly communicating quantitative and qualitative tradeoffs.
- Lead quantitative analysis of top security risk scenarios using FAIR, calibrated estimation, and simulation, presenting results to leadership.
- Partner with Security Engineering to assess threat scenarios and control effectiveness, ensuring security investments are appropriately sized to actual risk.
- Frame escalations and risk treatment decisions with clear recommendations, honest uncertainty statements, and re-evaluation triggers.
- Shape the analysis and narrative for leadership risk reviews, and help define risk appetite and key organizational risk metrics.
- Utilize AI and automation to scale risk analysis, owning calibration and quality review for trustworthy outputs.
- Transform one-off analyses into reusable methods, templates, and training to enable self-service risk analysis for partner teams and improve the risk register's analytical quality.
Requirements
- Experience owning security or technology risk analysis end-to-end, both qualitative and quantitative, with a demonstrated impact on decisions.
- Hands-on experience with FAIR-style quantification, including scenario decomposition, calibrated estimation, and Monte Carlo simulation using Python, R, or spreadsheets, and briefing decision-makers.
- Ability to thrive in ambiguity, frame moving questions into analyzable problems, and drive to decisions.
- Proficiency in assigning defensible severity and likelihood to ambiguous problems, stating uncertainty honestly, and adapting positions based on evidence.
- Sufficient technical security depth to decompose attack paths with security engineers and maintain credibility.
- Ability to condense complex risk positions into concise summaries for leadership and defend them under scrutiny.
- Experience using LLMs like Claude as daily working tools and critically reviewing model outputs.
- Low ego, collaborative approach, building credibility through work, and a commitment to AI safety.
Benefits
- Annual compensation range: $270,000 - $345,000 USD