Supplier Security & Assurance, Security GRCPosted today$255K

The opportunity

Anthropic's Supplier Security & Assurance (SSA) team sits within Security GRC and is responsible for assessing the security of our suppliers: evaluating whether vendors meet our security requirements, capturing the deviations, and giving the business a clear approval decision it…

What you'll do

  • Run supplier security assessments: review agent-prefilled outputs, evaluate vendor controls and evidence, determine residual risk, route to domain reviewers where deeper assessment is warranted

  • Operate supplier issue management and risk treatment: document each finding with a severity, an owner, and a due date, drive remediation with the vendor and the business owner, record risk acceptances, and roll open issues up to the risk register

  • Run continuous monitoring after approval: reopen an assessment on defined triggers (data classification change, new SOC 2 report, new subprocessor, vendor incident), investigate SaaS configuration, data, and use case drift signals, and queue a reassessment where the vendor's scope has moved

  • Improve the program as you run it: identify gaps in coverage, questionnaires, requirements, and tooling that surface during assessments, propose the fix, and carry roadmap items that mature supplier security overall

  • Tune and maintain our Claude-powered assessment platform alongside the team:: prompt development, questionnaire and assessment type design, calibration against assessor decisions, and output QA

  • Contribute to KPI and KRI reporting on coverage, cycle time, residual risk, open issues, and reassessments due

What they're looking for

  • Experience assessing cloud infrastructure, data center, or data-pipeline vendors
  • Experience supporting SOX, SOC 2, or ISO 27001 third party or vendor management controls
  • Experience assessing additional, more specialized vendor cohorts from a: security risk perspective: human data operations or data labeling vendors, hardware suppliers, compute providers and neoclouds, and others
  • Experience with post-approval supplier continuous monitoring: configuration, data, and use case drift detection, shadow IT & SaaS detection, vendor incident management, or evidence-based vendor audits/site visits