Engineering Manager, GRC Platform
San Francisco, CA | New York City, NY | Seattle, WA
Posted 13d ago
About the job
We are seeking an Engineering Manager, GRC to join our GRC organization and build the technical foundation for how we scale our risk and compliance programs. In this role, you will lead the team that designs and implements automated workflows, data pipelines, and integrations that transform manual compliance processes into scalable engineering systems. This is a greenfield opportunity to establish the team, architecture, and integrations that will define how we approach governance, risk, and compliance at Anthropic. The core challenge is a data problem: compliance information lives across dozens of systems—cloud infrastructure, identity providers, HR platforms, ticketing tools, code repositories—and your job is to design systems that bring it together, normalize it, and make it actionable. Success in this role comes from understanding how systems connect and how data flows between them. At Anthropic, you'll also have a unique advantage: the ability to design AI-powered workflows where Claude acts as an extension of your team, handling tasks that would traditionally require additional headcount or manual effort. You'll need ingenuity to identify where agentic AI can accelerate evidence collection, interpret unstructured data, triage compliance gaps, and augment human judgment in risk assessments. Working closely with Security, IT, and Engineering teams, you'll translate compliance and regulatory requirements into solutions that support audit programs including SOC 2, ISO, HIPAA, and FedRAMP, building systems that combine traditional automation with AI capabilities to achieve scale that wouldn't otherwise be possible.
Responsibilities
- Lead the team that establishes foundational GRC processes and architecture, designing and building automated workflows for risk management and compliance to enable continuous monitoring.
- Build data pipelines to aggregate risk, control, and asset information from across the technology stack, solving data integration problems and creating unified views of compliance posture.
- Inform GRC platform strategy and implementation by planning for and building tooling that meets compliance requirements.
- Translate written policies and compliance requirements into policy-as-code, working with Engineering and Security teams to express requirements as enforceable rules and automated checks.
- Establish feedback loops between policy and implementation to surface divergences between technical controls and written requirements.
- Design and deploy agentic AI workflows using Claude to automate evidence analysis, monitor control effectiveness, draft audit responses, and interpret unstructured information.
- Design and maintain integrations connecting GRC tooling with cloud infrastructure, identity management systems, HRIS platforms, ticketing systems, version control, and CI/CD pipelines.
- Build and lead an AI-forward GRC engineering function by hiring team members, establishing practices, and defining the technical roadmap.
Requirements
- 12+ years of total experience and 3-4+ years of experience managing technical individual contributors or systems-focused teams, with a proven track record of building or scaling small teams (2-5 people) in security, compliance, automation, or operations functions.
- Systems thinking ability, understanding complex environments, data flow between systems, and integration points.
- 5+ years of experience designing automated workflows, data pipelines, or system integrations.
- Strong data integration skills, including pulling data from multiple sources, normalizing it, joining it meaningfully, and surfacing insights.
- Understanding of APIs and integration patterns (REST APIs, webhooks, authentication flows, polling vs. push architectures).
- Ability to work independently with minimal guidance, taking ownership of complex problems from design through implementation.
- Strong analytical and problem-solving skills with attention to detail.