The opportunity
Anthropic's Security Governance, Risk, and Compliance (GRC) team is the connective tissue that holds the company accountable to its security and control commitments. We translate regulatory, customer, and voluntary obligations into controls that teams act on, and give leadership…
What you'll do
Define control requirements and acceptance criteria across the core ITGC: domains of logical access, change management, computer operations, and program development for SOX in-scope systems, including home-built platforms where the control has to be designed into the system rather than bolted on.
Set the bar for in-scope systems from day one. As financially significant: systems are built, migrated, or replaced, define what the system must provide (auditability, segregation of duties, change control, immutable logging, evidence retention) before go-live, so controls are not retrofitted after the fact.
Pressure-test changes for SOX impact during design. Review major: infrastructure, system, and agent framework changes for control impact while decisions are still cheap, and maintain a clear view of which changes alter the SOX scope, key control population, or evidence requirements.
Own second-line control monitoring and evidence readiness. Stand up: continuous controls monitoring and automated evidence collection for ITGCs (control testing, walkthrough preparation, population and completeness validation, and mapping to the common controls framework). Materially raise automated evidence coverage and cut audit prep time.
Drive control deficiency remediation with cross functional partners. Track: and root-cause ITGC deficiencies surfaced by monitoring, Internal Audit, or external audit; partner with engineering owners on remediation design; and assess whether remediation actually closes the gap before re-testing.
Assess scope changes through a SOX lens. When new products, entities,: systems, or integrations come into scope, provide technical and compliance assessment of their impact on control design, evidence requirements, and engineering effort before commitments are made.
What they're looking for
- A combination of audit or advisory experience (Big 4 or equivalent, ideally: IT audit) with in-house experience at an AI-forward tech company, in either order.
- Taken a company through a first-year SOX 404(a) and 404(b) assessment, including a first external ITGC audit.
- Defined or assessed controls over home-built financially significant systems,: usage-based billing, or revenue metering pipelines.
- Defined or assessed controls for AI/ML systems or agents acting in production environments.
- Stood up continuous controls monitoring or automated evidence programs.
- Experience with SOC 1 reliance, service organization control mapping, and complementary user entity controls.
- CISSP, CISA, CPA, or equivalent certification.