Supplier Security & Assurance, Security GRC

San Francisco, CA | Seattle, WA | New York City, NY | Washington, DC

Posted 14h ago

Job Location

San Francisco, CA | Seattle, WA | New York City, NY | Washington, DC

Tech Stack

Remote Work Policy

On-site

Categories

Applied AI Engineer

About the job

Anthropic's Supplier Security & Assurance (SSA) team, part of Security GRC, is responsible for evaluating vendor security, identifying deviations from requirements, and providing clear approval decisions. The team assesses critical vendors for a frontier AI lab, including SaaS providers, human data operations, compute and data center providers, hardware suppliers, and service firms. This role involves running end-to-end supplier security assessments, reviewing evidence, verifying AI-generated evaluations, determining risk, and driving findings to closure. You will also manage aspects beyond approval, such as contractual terms, secure configurations, continuous monitoring, and reassessments, while contributing to the program's tooling and requirements.

Responsibilities

  • Run supplier security assessments, including reviewing AI-generated outputs, evaluating vendor controls and evidence, determining residual risk, and routing complex cases to domain specialists.
  • Manage supplier issue resolution and risk treatment by documenting findings with severity and owners, driving remediation with vendors and business stakeholders, recording risk acceptances, and escalating open issues.
  • Conduct post-approval continuous monitoring by reopening assessments based on triggers like data classification changes or new reports, investigating configuration and data drift, and initiating reassessments when vendor scope changes.
  • Enhance the program by identifying gaps in coverage, questionnaires, requirements, and tooling, proposing solutions, and contributing to roadmap items for overall supplier security improvement.
  • Tune and maintain the Claude-powered assessment platform, including prompt development, questionnaire design, calibration, and output quality assurance.
  • Contribute to Key Performance Indicator (KPI) and Key Risk Indicator (KRI) reporting on metrics such as coverage, cycle time, residual risk, and upcoming reassessments.

Requirements

  • Experience conducting end-to-end supplier security assessments at a technology company, including scoping, inherent risk determination, control and evidence review, residual risk documentation, and closure of findings.
  • Proficiency in risk fundamentals (inherent/residual risk, control effectiveness, compensating controls, risk acceptance) and the ability to apply this judgment with incomplete evidence.
  • Capability to assess vendors across various security domains and identify findings manageable independently versus those requiring a specialist.
  • Proven ability to drive risk treatment to closure through influence across teams with competing priorities.
  • Experience building or tuning LLM-backed workflows, agents, or automations in a risk, compliance, or operations setting, including prompt tuning and output review.
  • Experience building or operating issue management workflows, including logging issues with clear ownership and due dates, tracking remediation, and escalating stalled treatments.
  • Working technical knowledge of SaaS security configurations (SSO/SCIM, admin scoping, sharing defaults, audit logs) and standard vendor security contract terms (DPAs, incident notification, subprocessors, audit rights).
  • Ability to analyze SOC 2 reports or penetration tests to identify control exceptions, map complementary controls, and assess the validity of evidence.

About Anthropic

Get new AI jobs in your inbox

A weekly digest of the newest AI engineering roles.

© 2026 AI Job Board. All rights reserved.