The opportunity
Anthropic's Supplier Security & Assurance (SSA) team sits within Security GRC and is responsible for assessing the security of our suppliers: evaluating whether vendors meet our security requirements, capturing the deviations, and giving the business a clear approval decision it…
What you'll do
Run supplier security assessments: review agent-prefilled outputs, evaluate vendor controls and evidence, determine residual risk, route to domain reviewers where deeper assessment is warranted
Operate supplier issue management and risk treatment: document each finding with a severity, an owner, and a due date, drive remediation with the vendor and the business owner, record risk acceptances, and roll open issues up to the risk register
Run continuous monitoring after approval: reopen an assessment on defined triggers (data classification change, new SOC 2 report, new subprocessor, vendor incident), investigate SaaS configuration, data, and use case drift signals, and queue a reassessment where the vendor's scope has moved
Improve the program as you run it: identify gaps in coverage, questionnaires, requirements, and tooling that surface during assessments, propose the fix, and carry roadmap items that mature supplier security overall
Tune and maintain our Claude-powered assessment platform alongside the team:: prompt development, questionnaire and assessment type design, calibration against assessor decisions, and output QA
Contribute to KPI and KRI reporting on coverage, cycle time, residual risk, open issues, and reassessments due
What they're looking for
- Experience assessing cloud infrastructure, data center, or data-pipeline vendors
- Experience supporting SOX, SOC 2, or ISO 27001 third party or vendor management controls
- Experience assessing additional, more specialized vendor cohorts from a: security risk perspective: human data operations or data labeling vendors, hardware suppliers, compute providers and neoclouds, and others
- Experience with post-approval supplier continuous monitoring: configuration, data, and use case drift detection, shadow IT & SaaS detection, vendor incident management, or evidence-based vendor audits/site visits