Third Party Risk Analyst, Security GRC
Remote • Remote-Friendly (Travel Required) | San Francisco, CA
Posted 8d ago
About the job
Anthropic's Third Party Risk Management (TPRM) team, within Security GRC, is responsible for managing risks associated with vendor and partner relationships. This role focuses on the highest-risk vendor portfolios, including mission-critical vendors like compute, data center, and data-pipeline providers, as well as vendors with deep access to our data and systems. The program is designed with an AI risk agent to handle initial tasks, allowing human focus on critical judgment, remediation, and high-priority vendors. You will be responsible for exit and failover planning, single-point-of-failure analysis, financial screening, and ensuring assessment depth aligns with vendor exposure.
Responsibilities
- Own the Mission Critical vendor portfolio, including tiered lists, business impact analysis alignment, exit/failover planning, and risk treatment for single points of failure.
- Manage the Highest-Risk vendor portfolio, ensuring security, privacy, and compliance assessment depth matches vendor exposure and driving remediation.
- Support vendor incident response by assessing impact, coordinating business owners, and managing post-incident risk treatment.
- Run inherent risk assessments through the intake workflow, reviewing agent-prefilled tiering and vendor controls.
- Operate the TPRM issue management workflow, documenting findings, assigning owners, and tracking treatment to closure.
- Tune and maintain the TPRM Risk Agent through prompt development, backtesting, error analysis, and output QA.
- Contribute to KPI/KRI reporting on portfolio coverage and cycle time.
Requirements
- Experience running third-party or vendor risk assessments end-to-end at a technology company.
- Working knowledge of risk fundamentals (inherent/residual risk, control effectiveness, compensating controls, risk acceptance) and applying them with incomplete evidence.
- Ability to assess vendors across security, privacy, compliance, and operational risk domains.
- Track record of driving risk treatment to closure through cross-team influence.
- Experience building or tuning an LLM-backed workflow, agent, or automation in a risk, compliance, or operations context.
- Experience building or operating issue management workflows.
- Hands-on experience with a procurement or GRC platform, understanding intake, tiering, and assessment routing.
- Working knowledge of business continuity, disaster recovery, and concentration risk concepts.
Benefits
- Annual compensation range: $255,000 - $270,000 USD