CronJobs

security jobs

Supplier Security & Assurance, Security GRC

Anthropic · Remote-Friendly (Travel Required) | San Francisco, CA

remoteunknown$255,000–$255,000Posted Sep 18, 2026LLMSOC 2ISO 27001SSOSCIMDPA

Apply on the employer site

About this role

**About Anthropic** Anthropic’s mission is to create reliable, interpretable, and steerable AI systems—safe and beneficial for users and society. **About the role** Anthropic’s Supplier Security & Assurance (SSA) team sits within Security GRC. The team assesses the security of Anthropic’s suppliers by evaluating whether vendors meet security requirements, capturing deviations, and providing clear approval decisions the business can act on. You’ll run supplier security assessments end to end: reviewing evidence, verifying agent-drafted evaluations, determining inherent and residual risk, and driving findings to closure with vendors and business owners. You’ll also extend assurance beyond approval—covering contractual security terms, secure configuration baselines, continuous monitoring, and reassessment—while helping shape the tooling and requirements the program runs on. **Key responsibilities** - Run supplier security assessments: review agent-prefilled outputs, evaluate vendor controls and evidence, determine residual risk, and route to domain reviewers when deeper assessment is needed. - Operate supplier issue management and risk treatment: document findings (severity, owner, due date), drive remediation with vendors and business owners, record risk acceptances, and roll open issues up to the risk register. - Run continuous monitoring after approval: reopen assessments on defined triggers (e.g., data classification changes, new SOC 2 report, new subprocessor, vendor incident), investigate SaaS configuration/data/use-case drift signals, and queue reassessments when vendor scope changes. - Improve the program as you run it: identify gaps in coverage, questionnaires, requirements, and tooling; propose fixes; and carry roadmap items to mature supplier security. - Tune and maintain the Claude-powered assessment platform: prompt development, questionnaire/assessment design, calibration against assessor decisions, and output QA. - Contribute to KPI/KRI reporting on coverage, cycle time, residual risk, open issues, and reassessments due. **Minimum qualifications** - Experience running supplier security assessments end to end at a technology company (scoping, inherent risk, controls/evidence review, residual risk documentation, and driving findings to closure). - Working knowledge of risk fundamentals (inherent vs. residual risk, control effectiveness, compensating controls, risk acceptance) and the judgment to apply them when evidence is incomplete. - Ability to assess vendors across security domains and know when to close findings vs. escalate to domain specialists. - Track record of driving risk treatment to closure through influence across teams with competing priorities. - Experience building/tuning an LLM-backed workflow/agent/automation in a risk, compliance, or operations context (prompt tuning + reviewing model output for accuracy). - Experience building/operating issue management workflows (clear owner + due date, remediation tracking, escalation when stalled). - Technical knowledge of SaaS security configuration (e.g., SSO/SCIM, admin scoping, sharing defaults, audit log export) and standard vendor security contract terms (e.g., DPA, incident notification, subprocessors, audit/testing rights). - Ability to read SOC 2 reports or penetration tests and translate them into findings (control exceptions, mapping complementary controls, and judging what evidence does/does not prove). **Preferred qualifications** - Experience assessin

Listing freshness

CronJobs last confirmed this listing 2h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord