Security Controls Assurance Lead
$345kAnthropic
About Anthropic Anthropic’s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems. About the role Anthropic's Security Governance, Risk, and Compliance (GRC) team is the connective tissue that holds the company accountable to its security commitments. We translate regulatory, customer, and voluntary obligations into controls that teams act on, and give leadership a bird's-eye view of how well we're meeting them. We're building toward a fundamentally different kind of GRC: one that directs Claude, with the right humans in the loop, to challenge and evidence the performance of controls continuously rather than through periodic audits. We are designing an integrated compliance and risk ecosystem that serves as a trust engine and an independent risk advisor as Anthropic governs itself at a level beyond frameworks. As part of Security GRC's technical controls assurance function, you will be the voice on what the control environment must achieve. You will define control requirements and acceptance criteria for our global compliance obligations (e.g. SOC 2, ISO 27001/42001, HIPAA, public sector) across the software development lifecycle, pair with engineering as they design and implement against those requirements, and validate that what ships actually meets the bar. Key responsibilities Define the control framework and requirements for autonomous AI operators in collaboration with Security, Internal Audit, and Engineering, including change review and approvals, human-in-the-loop, and evidence collection. Assess implementations against those requirements. Pressure-test major infrastructure, system, and agent framework changes for control impact during design, before decisions become expensive rework. Set the compliance bar for home-built systems. Collaborate with teams to define what the internal system must provide from day one, such as auditability, segregation of duties, and change control over the tool itself. Define the criteria for where and when AI can operate, supplement, or replace a manual process or control, including the human-in-the-loop thresholds and evidence documentation. Establish the validation, evidence, and governance standards that allow AI-performed and AI-assisted processes and controls to withstand external audit and regulatory scrutiny. Assess the introduction of new compliance frameworks and changes in scope (new regulations, certifications, products, or entities), providing a sufficient technical and compliance lens on their impact to control design, evidence requirements, and engineering effort before commitments are made. Stand up or advise on audit workflows for the assurance team, including Claude-driven control testing, automated evidence collection, walkthrough preparation, and framework mapping against our common controls framework, materially raising automated evidence coverage and cutting audit prep time. Minimum qualifications Thrive at the pace of a hypergrowth company. You’re comfortable making calls with incomplete information and reprioritizing as scope shifts. Have supported technology control programs through SOX readiness or as a public company or with equivalent rigor (FedRAMP, large multi-framework SOC 2/ISO portfolios). Have genuine engineering fluency, possibly from an earlier engineering career: you can read code and Terraform, follow a CI/CD pipeline end to end, and challenge a design on its technical merits. Have programming skills in Python or at least one systems language such as Go, Rust, or C/C++. Have deep familiarity with developer platform, release engineering, or infrastructure control domains. Are a strong collaborator and communicator. Use Claude and other LLMs as daily working tools, and have grounded, specific views on which audit and assurance workflows AI can run today and which it can't yet. Translate framework and regulatory language into acceptance criteria engineers can build against, and translate engineering reality back into assurance language auditors and leadership can rely on. Default to getting the requirement designed into the system rather than papering over the gap with procedure. Preferred qualifications Have a combination of audit or advisory experience (Big 4 or equivalent) with in-house experience at an AI-forward tech company — in either order Have defined or assessed controls for AI/ML systems or agents acting in production environments Have stood up continuous controls monitoring or automated evidence programs Candidates need not have Done everything on this list. This role does not require writing production code day to day. We encourage and expect you to ship, but the bar is fluency sufficient to review, challenge, and specify. Nor does it require depth in every framework we hold; Security GRC has specialists. The scarce combination this role exists for is requirement experience plus engineering credibility. The annual compensation range for this role is listed below. For sales roles, the range provided is the role’s On Target Earnings ("OTE") range, meaning that the range includes both the sales commissions/sales bonuses target and annual base salary for the role. Annual Salary:
$345,000—$345,000 USD
Logistics Minimum education: Bachelor’s degree or an equivalent combination of education, training, and/or experience Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience Minimum years of experience: Years of experience required will correlate with the internal job level requirements for the position Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices. Visa sponsorship: We do sponsor visas! However, we aren't able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this. We encourage you to apply even if you do not believe you meet every single qualification. Not all strong candidates will meet every single qualification as listed. Research shows that people who identify as being from underrepresented groups are more prone to experiencing imposter syndrome and doubting the strength of their candidacy, so we urge you not to exclude yourself prematurely and to submit an application if you're interested in this work. We think AI systems like the ones we're building have enormous social and ethical implications. We think this makes representation even more important, and we strive to include a range of diverse perspectives on our team. Your safety matters to us. To protect yourself from potential scams, remember that Anthropic recruiters only contact you from @anthropic.com email addresses. In some cases, we may partner with vetted recruiting agencies who will identify themselves as working on behalf of Anthropic. Be cautious of emails from other domains. Legitimate Anthropic recruiters will never ask for money, fees, or banking information before your first day. If you're ever unsure about a communication, don't click any links—visit anthropic.com/careers directly for confirmed position openings. How we're different We believe that the highest-impact AI research will be big science. At Anthropic we work as a single cohesive team on just a few large-scale research efforts. And we value impact — advancing our long-term goals of steerable, trustworthy AI — rather than work on smaller and more specific puzzles. We view AI research as an empirical science, which has as much in common with physics and biology as with traditional efforts in computer science. We're an extremely collaborative group, and we host frequent research discussions to ensure that we are pursuing the highest-impact work at any given time. As such, we greatly value communication skills. The easiest way to understand our research directions is to read our recent research. This research continues many of the directions our team worked on prior to Anthropic, including: GPT-3, Circuit-Based Interpretability, Multimodal Neurons, Scaling Laws, AI & Compute, Concrete Problems in AI Safety, and Learning from Human Preferences. Come work with us! Anthropic is a public benefit corporation headquartered in San Francisco. We offer competitive compensation and benefits, optional equity donation matching, generous vacation and parental leave, flexible working hours, and a lovely office space in which to collaborate with colleagues. Guidance on Candidates' AI Usage: Learn about our policy for using AI in our application process.$320k - $405k
...About the team The Data Center Security Engineering team owns the... ...and owns the supply chain and assurance side of that interface: making... ...You'll independently scope and lead Anthropic's data center... ...supply chain and media protection control families, or equivalent) and...SuggestedContract workVisa sponsorship$95k - $135k
...BDO Capital Advisors, LLC in San Francisco seeks an Assurance Experienced Senior to coordinate audit duties, manage staff, and ensure compliance with accounting standards. This role involves preparing financial statements, communicating with clients, and supervising audit...Suggested- ...leader in real estate solutions is seeking a Technology Risk and Controls Manager to improve risk management across its cloud-native... ...Responsibilities include assessing emerging threats, evaluating security measures, and collaborating closely with senior leadership. The...Suggested
$172.5k - $260.1k
...to level-up your career at the company leading workforce transformation in the agentic... ...Title: Sr. Manager, Technology Risk and Controls (Revenue) About the Role Salesforce... ...partners (e.g., Internal Audit, Finance, Security, and DET Revenue technology teams to...SuggestedWork experience placement- ...Title-IT Manager - Controls & Risk Management Location-Westborough, Massachusetts... ...Wednesday and Thursday Our client is a leading publicly traded technology operator. They... ...Management to bolster their Information Security group. This team supports the control framework...SuggestedWork experience placement
- ...San Francisco, is seeking a Manager to join the Enterprise Risk team. The role involves assessing and monitoring risks, enhancing controls, and providing risk insights across various departments in a dynamic fintech environment. The ideal candidate will have 6-8 years...Flexible hours
$90k - $115k
...the San Francisco Bay Area. POSITION SUMMARY The Senior Quality Control (QC) Underwriter re-underwrites and re-verifies simple to... ...for insurance. Identifies quality trends and underlying causes leading to QC findings and recommends parties to the transaction for targeted...Work experience placement$216k - $240k
OpenAI is seeking a Senior Manager, Financial Risk Management in San Francisco to lead risk and controls across finance-critical domains. This role requires 10+ years of experience in financial risk management, operational risk, or internal controls, with a focus on designing...$190k - $275k
...About Decagon Decagon is the leading conversational AI platform empowering every brand... ...as a team. About the Team The Security Engineering team at Decagon protects the... ...evidence collection, ensuring all controls are properly documented and audit-ready...Full timeFor contractorsWork at officeLocal area$300k - $360k
...of GRC, you will define and lead Ripple's Governance, Risk & Compliance... ...role at the nexus of security, regulatory compliance, and business... ...function, from continuous control monitoring and automated... .... Own the Customer Security Assurance Program, ensuring enterprise...Full timeLocal areaWorldwideShift work- ...Compliance (GRC) Founded in 2000, Ivalua is a leading global provider of cloud‑based... ..., and serve as subject‑matter expert on security frameworks and standards. What You Will... ...continuous compliance and monitor security controls to ensure ongoing adherence to standards...Work at officeWorldwide3 days per week
$244k - $390.58k
...in our products. Docusign's security program is vital to that trust... ...compliance with scalable security controls built directly into... ...This position will leverage leading security frameworks like NIST... ..., managing customer security assurance, ensuring audit readiness in...Contract workWork experience placementWork at officeLocal areaRemote workShift work2 days per week- ...NAVA Software solutions is looking for a Security Risk Manager Details: Security Risk Manager Duration: 10 months... ...efforts including the design and effectiveness of operational controls, based on industry best practice models in accordance w/ risk and...
$146.4k - $235.38k
...do Docusign is looking for a Senior Security Risk Manager to join our Security Governance... ...) team. In this hands-on role, you will lead and manage modern, data-driven security... ...Response, etc.) Review holistically Risk, Control, and Issue data to culminate...Contract workWork at officeLocal areaRemote work2 days per week- A leading AI research firm in San Francisco is seeking a Revenue Manager to enhance its financial risk and controls related to revenue processes. You will collaborate with cross-functional teams to design and implement effective revenue-related controls. The ideal candidate...Work at officeRelocation package
$141.2k - $262.2k
...highly motivated and experienced Sterility Assurance Director. This role is strategic and... ...implementation of the comprehensive Contamination Control Strategy (CCS) for the new facility,... ...for improvement Root Cause Analysis: Lead complex microbiological investigations (e...Full timeLocal areaRelocation package$317.5k - $365k
...VP, Global Head Of Product Security & Risk Circle is building the next generation of global... ...Security & Risk, you will define and lead the enterprise framework that enables Circle... ..., and operated with strong, risk-based controls from inception through global scale. As...Worldwide$85k - $105k
A leading audit firm in California is seeking an experienced Audit & Assurance Senior to join their team. The role requires 2-4 years of public accounting experience, excellent communication skills, and the ability to perform audits effectively. The position offers a supportive...$89.8k - $170.5k
...A leading professional services firm in Detroit is seeking an Assurance Manager specializing in Industrial Goods. The ideal candidate will have a BS/BA in Accounting, CPA or CA certification, and over 5 years of experience in public accounting. Responsibilities include...$136.85k - $185.15k
...us. The Boeing Defense, Space & Security (BDS) - Phantom Works organization is... ...engineer to serve as the Signature Assurance and Verification Lead Engineer. This role is pivotal in... ...accepted until Jun. 23, 2026 Export Control Requirements: This position must...Permanent employmentImmediate startRelocationVisa sponsorshipWork visaRelocation packageFlexible hoursShift workDay shift$266k - $295k
...risk management leader to establish and lead its global insurance function within Treasury... ...will also work across Finance, Legal, Security, People, Real Estate, Infrastructure, Engineering... ...Internal Audit on insurance accounting, controls, compliance, and governance matters....Work at officeRelocation package$175k - $205k
...help businesses tackle cyber risk head on. By combining industry-leading insurance with world-class cybersecurity technology, At-Bay... ...critical than ever. At-Bay helps its 40,000+ customers close their security technology and skills gap all through their cyber insurance...$150k - $175k
...compensation and occupational accident claims by running loss control surveys and training for teams involved in the claims reporting... ...About Instawork Founded in 2015, Instawork is the nation's leading online labor marketplace for food services, hospitality, light...Hourly payLocal areaFlexible hoursShift work$120k - $350k
...address, we will use that email address to communicate with you about this and other positions. We use an email quality control service to maintain security and a remove and dead address filter. To cancel receiving email communications, simply send an email from your...Contract workSecond jobWork at officeRelocation packageFlexible hours$100k - $135k
...team and Specialty Risks. Comply with Beazley's underwriting control standards for business written through Lloyd's, Beazley's... ...delivered by your line manager, the People & Sustainability or assurance teams (compliance, risk, internal audit) either directly, via e...Contract workTemporary workWork at officeImmediate startHome officeFlexible hours- ...team and Specialty Risks. Comply with Beazley's underwriting control standards for business written through Lloyd's, or Beazley's... ...procedures as delivered by your line manager, the Culture & People or assurance teams (compliance, risk, internal audit) either directly, via e...Contract workTemporary workImmediate startHome officeFlexible hours
- A fast-growing accounting firm located in the San Francisco Bay Area is seeking an Assurance Senior Manager. In this role, you will oversee audit engagements, focus on privately held companies, and ensure accuracy in financial reporting. The ideal candidate will hold a...
- ...: San Francisco Bay Area Headquarters (primarily on-site) A leading organization in the Bay Area is seeking a highly experienced leader... ...Substantial background in overseeing claims, implementing loss control initiatives, and coordinating with external vendors. ~ Prior...
- Our client, a fast-growing insurance software AI startup, is hiring an Insurance Solutions Lead with 5+ years of insurance brokerage experience to serve as the bridge between their sales, customer success, and product teams. You'll be a generalist account management expert...
- Brain Co. is seeking a dedicated insurance GTM lead in San Francisco to build and manage enterprise insurance accounts. Ideal candidates have a strong background in the insurance industry, active relationships with decision-makers, and experience in enterprise sales. You...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Controls Assurance Lead. Be the first to apply!

