Lead, Security Controls Assurance - SOX
$410kAnthropic
About Anthropic Anthropic’s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems.About the role Anthropic's Security Governance, Risk, and Compliance (GRC) team is the connective tissue that holds the company accountable to its security and control commitments. We translate regulatory, customer, and voluntary obligations into controls that teams act on, and give leadership a bird's-eye view of how well we're meeting them. We're building toward continuous assurance, to challenge and evidence the performance of controls continuously rather than through periodic audits. As Anthropic prepares for life as a public company, the Sarbanes-Oxley (SOX) control environment over our technology stack is one of the most consequential things this team owns. As part of Security GRC's technical controls assurance function, you will be the voice on what the IT general controls must achieve to support SOX 404 compliance. In partnership with Internal Audit, you will define control requirements and acceptance criteria for the in-scope engineering systems and infrastructure that underpin financial reporting. You will pair with engineering as they design and implement against those requirements, and validate that what ships actually meets the bar before Internal Audit and our external auditors test it. You are the product owner for control design methodology and continuous control monitoring, initially around ITGCs, but extending into other areas of security and compliance to drive visibility where and when we need it. Key responsibilities Define control requirements and acceptance criteria across the core ITGC domains of logical access, change management, computer operations, and program development for SOX in-scope systems, including home-built platforms where the control has to be designed into the system rather than bolted on. Set the bar for in-scope systems from day one. As financially significant systems are built, migrated, or replaced, define what the system must provide (auditability, segregation of duties, change control, immutable logging, evidence retention) before go-live, so controls are not retrofitted after the fact. Pressure-test changes for SOX impact during design. Review major infrastructure, system, and agent framework changes for control impact while decisions are still cheap, and maintain a clear view of which changes alter the SOX scope, key control population, or evidence requirements. Own second-line control monitoring and evidence readiness. Stand up continuous controls monitoring and automated evidence collection for ITGCs (control testing, walkthrough preparation, population and completeness validation, and mapping to the common controls framework). Materially raise automated evidence coverage and cut audit prep time. Drive control deficiency remediation with cross functional partners. Track and root-cause ITGC deficiencies surfaced by monitoring, Internal Audit, or external audit; partner with engineering owners on remediation design; and assess whether remediation actually closes the gap before re-testing. Assess scope changes through a SOX lens. When new products, entities, systems, or integrations come into scope, provide technical and compliance assessment of their impact on control design, evidence requirements, and engineering effort before commitments are made. Maintain alignment with the broader compliance portfolio. Where SOX ITGCs overlap with SOC 2, ISO 27001/42001, or other frameworks, ensure controls are designed once and evidenced once, and that changes made for one framework do not silently break another. Minimum qualifications Thrive at the pace of a hypergrowth company. You're comfortable making calls with incomplete information and reprioritizing as scope shifts. Have led or been a senior contributor to an ITGC program through SOX 404 readiness and/or at a public company, with a working command of PCAOB AS 2201, COSO 2013, and how external auditors scope, test, and evaluate technology controls and deficiencies. Have genuine engineering fluency, possibly from an earlier engineering career: you can read code and Terraform, follow a CI/CD pipeline end to end, and challenge a design on its technical merits. Have programming skills in Python or at least one systems language such as Go, Rust, or C/C++. Have deep familiarity with developer platform, release engineering, cloud infrastructure, or ERP/financial systems control domains. Understand the role of the second line: you can advise and challenge engineering without taking ownership of their controls, and you know where the line sits between your monitoring and Internal Audit's independent testing. Are a strong collaborator and communicator across Finance, Engineering, Internal Audit, and external auditors. Use Claude and other LLMs as daily working tools, and have grounded, specific views on which SOX assurance workflows AI can run today and which it can't yet. Translate SOX and framework language into acceptance criteria engineers can build against, and translate engineering reality back into assurance language auditors and leadership can rely on. Default to getting the requirement designed into the system rather than papering over the gap with procedure. Preferred qualifications A combination of audit or advisory experience (Big 4 or equivalent, ideally IT audit) with in-house experience at an AI-forward tech company, in either order. Taken a company through a first-year SOX 404(a) and 404(b) assessment, including a first external ITGC audit. Defined or assessed controls over home-built financially significant systems, usage-based billing, or revenue metering pipelines. Defined or assessed controls for AI/ML systems or agents acting in production environments. Stood up continuous controls monitoring or automated evidence programs. Experience with SOC 1 reliance, service organization control mapping, and complementary user entity controls. CISSP, CISA, CPA, or equivalent certification. The annual compensation range for this role is listed below. For sales roles, the range provided is the role’s On Target Earnings ("OTE") range, meaning that the range includes both the sales commissions/sales bonuses target and annual base salary for the role.Annual Salary:$410,000—$510,000 USDLogistics Minimum education: Bachelor’s degree or an equivalent combination of education, training, and/or experience Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience Minimum years of experience: Years of experience required will correlate with the internal job level requirements for the position Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices. Visa sponsorship: We do sponsor visas! However, we aren't able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this. We encourage you to apply even if you do not believe you meet every single qualification. Not all strong candidates will meet every single qualification as listed. Research shows that people who identify as being from underrepresented groups are more prone to experiencing imposter syndrome and doubting the strength of their candidacy, so we urge you not to exclude yourself prematurely and to submit an application if you're interested in this work. We think AI systems like the ones we're building have enormous social and ethical implications. We think this makes representation even more important, and we strive to include a range of diverse perspectives on our team.Your safety matters to us. To protect yourself from potential scams, remember that Anthropic recruiters only contact you from ****** email addresses. In some cases, we may partner with vetted recruiting agencies who will identify themselves as working on behalf of Anthropic. Be cautious of emails from other domains. Legitimate Anthropic recruiters will never ask for money, fees, or banking information before your first day. If you're ever unsure about a communication, don't click any links—visit anthropic.com/careers directly for confirmed position openings. How we're different We believe that the highest-impact AI research will be big science. At Anthropic we work as a single cohesive team on just a few large-scale research efforts. And we value impact — advancing our long-term goals of steerable, trustworthy AI — rather than work on smaller and more specific puzzles. We view AI research as an empirical science, which has as much in common with physics and biology as with traditional efforts in computer science. We're an extremely collaborative group, and we host frequent research discussions to ensure that we are pursuing the highest-impact work at any given time. As such, we greatly value communication skills. The easiest way to understand our research directions is to read our recent research. This research continues many of the directions our team worked on prior to Anthropic, including: GPT-3, Circuit-Based Interpretability, Multimodal Neurons, Scaling Laws, AI & Compute, Concrete Problems in AI Safety, and Learning from Human Preferences. Come work with us! Anthropic is a public benefit corporation headquartered in San Francisco. We offer competitive compensation and benefits, optional equity donation matching, generous vacation and parental leave, flexible working hours, and a lovely office space in which to collaborate with colleagues. Guidance on Candidates' AI Usage: Learn about our policy for using AI in our application process.
$150.1k - $227k
...to level-up your career at the company leading workforce transformation in the agentic... ...building a brand new Professional Services Security Assurance (PSSA) team — a true 0 to 1 opportunity... ...business risk, and recommend security controls that effectively balance security,...SuggestedFull time- ...Overview Mercor is collaborating with a leading AI lab to engage experienced audit and controls professionals — external audit and internal audit / SOX. You'll translate real audit and... ...auditors do. Focus Areas External audit & assurance · internal audit, risk & controls (...Suggested
- Anthropic is seeking a candidate for a Security GRC role in San Francisco where you'll define control frameworks and ensure compliance for AI systems. You will collaborate across teams to create an integrated risk ecosystem, challenge control implementations, and validate...Suggested
- JLL’s Global Security Technical Security team protects client and corporate environments with advanced physical security tech. You’ll lead access control programs, manage a skilled team, and partner with Global Security, Real Estate, clients, and technology groups. You...Suggested
- JLL is seeking a Physical Security Technology Lead in South San Francisco to manage day-to-day access control, intrusion, and video surveillance across client and corporate environments. You will guide a high-performing team and own ongoing enhancements within an Agile...Suggested
$99k - $232k
...SummaryThe OpportunityAs an Internal Audit/SOX Business Controls Manager, you will play a pivotal role... ...firm's success. You are expected to lead with integrity and authenticity, articulating... ...factors thoughtfully to establish a secure and trusted workplace for all....Full timeH1b- Solinius, located in San Francisco, is seeking a Lead, Internal Audit and SOX Compliance to enhance the internal controls program and engage cross-functional teams to ensure efficient operational audits. The ideal candidate will have over 8 years of experience in internal...Work at office
$185k - $220k
.... About The Role We are seeking a strategic and seasoned Lead, Internal Audit and SOX Compliance to join our Finance team reporting to the Head... ...You will help to establish and elevate Notion's internal controls program end to end — designing the governance framework, leading...Local area- ...San Francisco and backed by leading investors including Altos Ventures... ...has experience from Citadel Securities, Meta, Google, Silver Lake,... ...We're looking for a Quality Control Lead to own the final checkpoint... ...or leading a quality assurance/quality control function, ideally...Local area
- GRC Security compliance leader Job Description: Job Title: GRC Security... ...efforts to maintain Common controls implemented at individual... ...Standards. Help prepare security assurance materials for internal and... ...other relevant standards such as SOX (US role)-NIST 800- 53, CMMC....Contract workWork at officeRemote workEarly shift
- PwC in San Francisco seeks a SOX Business Process Controls Manager to lead end-to-end internal audit services across industries, focusing on SOX readiness, control optimization, and risk technology adoption. You will guide teams, mentor junior staff, and ensure client satisfaction...
- ...Description Job Description We are seeking an experienced Lead Technician to join our team. In this role, you will lead... ...of structured cabling systems (Cat6, fiber optic), access control systems, and security devices. A working knowledge of audiovisual (AV) systems...Full timeCurrently hiring
$167.28k - $196.8k
A cryptocurrency company is seeking a Senior Analyst, SOX IT to lead security and compliance initiatives. You will support the SOX roadmap, manage control assessments, and work closely with cross-functional teams. The ideal candidate has 5+ years of security/IT compliance...- Elevate Recruiting is seeking a Chartered Controller to lead accounting and financial controls for a large construction operating division in... ...project forecasting, and robust internal controls while ensuring SOX compliance and external audit #J-18808-Ljbffr Elevate...
- Position Overview We are seeking an experienced Lead Technician with a strong background in structured cabling, access control, and security systems to join our growing team. This individual will serve as the on‑site lead for installation and commissioning of low‑voltage...For subcontractor
- A leading technology installation firm located in California is seeking an experienced Lead Technician to oversee structured cabling, access control, and security system installations. The role requires a hands-on leader with 3-5+ years in the field who can mentor junior...
$249.6k - $312k
...team provides independent assurance that the company’s risk... ..., and internal control processes are operating... ...operational, regulatory, security, IT, and more. About the... ..., IT Internal Audit to lead the strategy, execution... ...of audits, including IT SOX, cybersecurity, data governance...Hourly payWork at officeLocal areaRemote workFlexible hours- Discord's Internal Audit team seeks an experienced Technology Risk Audit Manager to own IT SOX/ITGC controls, privacy and security domains, and AI-enabled testing. You will partner with Engineering to ensure proper access controls and SDLC governance, and guide risk assessments...
$144k - $329.1k
...We’re hiring an experienced Lead AI Software Architect that to... ...designing and implementing AI Agent Control. This role is for a software... ...architectural experts in AI, Security, Data and Infrastructure to... ...full spectrum of services in assurance, consulting, tax, strategy...Summer holidayFlexible hours- ...The Opportunity Complify is transforming SOX compliance with AI. In this client-facing... ...leaders at public companies to streamline control testing, documentation, and evidence gathering... ...shape the future of audit. What You’ll Do Lead multiple SOX engagements from scoping...
$200k - $300k
...around the globe. Valued at US$11 billion and backed by world-leading investors including T. Rowe Price, Visa, Mastercard, Robinhood... ...you, let’s build what’s next.About the teamThe Commercial Risk Control team sits in the first line of defence within the Commercial organisation...Temporary workLocal areaWorldwide$180k - $258k
...administrative friction for good.Role OverviewWe are seeking a Security GRC Lead to build our first in-house GRC program from the ground up.... ..., implement compliance-as-code, and establish continuous controls monitoring across our GCP infrastructure, identity systems,...$110k - $135k
...team as we help shape a brighter way forward. JLL - Physical Security Systems Lead (P3)Location: South San FranciscoReports to: Global Security... ...— of integrated security systems spanning access control, intrusion detection, alarm monitoring, and video surveillance...Full timeLocal area- ...Chai is at the forefront of this shift. Leading pharmaceutical companies like Eli Lilly,... ...on the road ahead. About the Role Security is what earns Chai the trust of the world... ...architecture, tenant isolation, egress controls, encryption, and key management. You'll...Shift work
$114.1k - $268.18k
...opportunities, a world-class training facility, and leading market tools, we help our people... ...seeking a Lead Specialist, Cloud Security to join our Managed Services practice.Responsibilities... ...including risk acceptance, compensating controls, renewals, reporting, and regulatory...H1bLocal area$264k - $330k
About SemgrepSemgrep, the leader in code security for builders, empowers invention without... ..., and giving security teams visibility, control, and confidence. Semgrep gets smarter as... ...Security Testing and is trusted by leading organizations, including Vanta, Lyft, and...Contract workCurrently hiringLocal areaRemote workFlexible hoursWeekend work- Discord’s Internal Audit team seeks a Technology Risk Audit Manager to own IT SOX/ITGC, system controls, and consumer trust domains. You will shape AI-native audit frameworks from day one and guide control design through platform changes, reporting to the VP of Internal...
$170k - $190k
...expertise to deliver independent assurance, practical insights, and... ...risks, governance, and control environment while helping... ....Reporting to the VP of SOX & Internal Audit, you will lead our Technology Risk &... ...Engineering, Information Security, Product, Enterprise Technology...H1bWork at officeLocal areaRemote workHome officeRelocation packageMonday to Thursday- ...Description Job Description At Vector Security We Think Big, Do the Right Thing, and... ...like to invite you to join our team as a Lead Systems Technician! We offer great benefits... ...Burglar and Fire Alarms, Access Control, and Video. Possesses strong technical aptitude...Temporary workLocal area
- ...We’ve built the gold standard for agent security & reliability, AIUC-1 with 100+ CISOs from... ...THE ROLE AIUC is growing into the leading voice on enterprise AI trust: ~250 F1000... ...closely linked functions — standard setting, assurance/red-teaming, and insurance — waiting to...Full time
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Lead, Security Controls Assurance - SOX. Be the first to apply!



