Senior Manager, IT SOX
San Francisco, CA
Posted 12d ago
About the job
Anthropic is seeking a Senior Manager, IT SOX to join the Internal Audit team. This role is a hands-on technical contributor responsible for executing the IT SOX compliance program, with a strong emphasis on IT General Controls, IT Application Controls, and system risk assessments. The ideal candidate is comfortable with ambiguity, thrives in a fast-paced environment, and enjoys solving complex problems. This is a high-impact opportunity to collaborate with various teams to establish a robust control environment for an AI-first company, acting as a trusted advisor on technology controls for Engineering, GRC, Security, and Finance teams as the organization scales towards pre-IPO readiness. You will bring technical depth, a focus on automation, and the ability to partner effectively with both technical teams and external auditors.
Responsibilities
- Advise on the design of a control environment for an AI-first company, including controls for automated DevOps pipelines and emerging agentic identity models.
- Partner with Engineering, Security, IT, and DevOps teams to assess the design and implementation of scalable and sustainable controls.
- Assess new system implementations and changes.
- Identify opportunities for automation and tooling to improve control efficiency and monitoring, and contribute to continuous monitoring capabilities.
- Assist in scoping and planning for annual SOX IT assessments.
- Execute IT SOX testing across IT General Controls and IT Application Controls, including access management, change management, and computer operations.
- Perform system and process risk assessments to identify control gaps and recommend remediation.
- Own control documentation and ensure audit-ready evidence is current and complete.
- Evaluate IT automated controls and support the transition from manual to automated control reliance.
- Scale the IT SOX program as the company grows by rationalizing scope, standardizing testing approaches, and building repeatable processes.
- Guide and direct the work of internal team members and co-sourced partners, setting priorities, reviewing workpapers, and ensuring quality.
- Build strong working relationships with process and control owners across the organization.
- Translate technical control requirements for non-technical stakeholders and vice versa.
- Support SEC cybersecurity disclosure requirements and related risk monitoring efforts.
- Coordinate with external auditors on IT SOX matters, including evidence requests, walkthroughs, and testing schedules.
- Track and assist with remediation of audit findings, communicating status to stakeholders.
Requirements
- Hands-on IT audit or IT SOX compliance experience, preferably in a fast-paced technology environment.
- Deep working knowledge of ITGCs, ITACs, and IT risk assessment methodologies.
- Experience auditing highly automated DevOps environments (CI/CD pipelines, infrastructure-as-code, automated deployments) and adapting traditional controls.
- Experience designing, testing, and documenting controls for access management, change management, and computer operations.
- Demonstrated comfort with ambiguity and ability to operate effectively in a high-pace, rapidly changing environment.
- Ability to effectively guide and direct the work of internal team members and/or co-sourced partners.
- Ability to work independently on complex, ambiguous workstreams while communicating proactively with senior stakeholders.
- Strong project management and organizational skills with close attention to detail.
- Clear, effective communication skills, able to work across technical and non-technical audiences.