Security Controls Assurance Lead
San Francisco, CA | New York City, NY | Washington, DC
Posted 13d ago
About the job
Anthropic's Security Governance, Risk, and Compliance (GRC) team is seeking a Security Controls Assurance Lead to translate regulatory, customer, and voluntary obligations into actionable controls. This role will define control requirements and acceptance criteria for global compliance obligations across the software development lifecycle, partnering with engineering teams to ensure implemented controls meet defined standards. The goal is to build an integrated compliance and risk ecosystem that serves as a trust engine and an independent risk advisor for Anthropic.
Responsibilities
- Define control framework and requirements for autonomous AI operators, including change review, human-in-the-loop, and evidence collection, and assess implementations against these requirements.
- Evaluate control impact of major infrastructure, system, and agent framework changes during the design phase.
- Set compliance standards for internal systems, defining requirements for auditability, segregation of duties, and change control.
- Determine criteria for AI operation, supplementation, or replacement of manual processes/controls, including human-in-the-loop thresholds and evidence documentation.
- Establish validation, evidence, and governance standards for AI-performed and AI-assisted processes to withstand external audits.
- Assess the impact of new compliance frameworks and scope changes on control design, evidence requirements, and engineering effort.
- Develop or advise on audit workflows, including Claude-driven control testing and automated evidence collection, to improve efficiency and coverage.
Requirements
- Ability to thrive in a fast-paced environment, make decisions with incomplete information, and adapt to shifting priorities.
- Experience supporting technology control programs through SOX readiness, as a public company, or with equivalent rigor (e.g., FedRAMP, large SOC 2/ISO portfolios).
- Strong engineering fluency, including the ability to read code and Terraform, understand CI/CD pipelines, and assess technical designs.
- Programming skills in Python or a systems language like Go, Rust, or C/C++.
- Deep familiarity with developer platforms, release engineering, or infrastructure control domains.
- Excellent collaboration and communication skills.
- Experience using LLMs like Claude for daily work, with informed views on AI's current and future capabilities in audit and assurance.
- Ability to translate regulatory language into engineering acceptance criteria and engineering realities into auditor-friendly assurance language.
- Preference for designing requirements into systems rather than relying solely on procedural workarounds.