Security Audit & Controls, Security GRC
Anthropic · San Francisco, CA | New York City, NY | Seattle, WA
About this role
**Security Audit & Controls — Security GRC (Anthropic)** ## About Anthropic Anthropic’s mission is to create reliable, interpretable, and steerable AI systems—so AI is safe and beneficial for users and society. ## About the team Anthropic’s **Security Governance, Risk, and Compliance (GRC)** team translates regulatory, customer, and voluntary obligations into controls teams can act on, and provides leadership visibility into how well commitments are being met. Within Security GRC, **Compliance & Audit Programs** runs the integrated audit across frameworks and maintains the **Common Control Framework (CCF)**—the canonical set of controls the program is built on. This role sits in **Audit & Assurance** and owns the framework and assurance view across every control domain. ## About the role As part of the **Security Audit & Controls** team, you will **own the CCF across every control domain**, including access and change management, logging, encryption, and people controls. You’ll ensure each control is: - clearly defined (what it says) - accurately mapped to frameworks and commitments (how it maps) - proven to be working (whether it’s effective) You’ll work with control owners and GRC partners to draft and validate control descriptions and activities that reflect reality, build **continuous monitoring** to demonstrate operating effectiveness (not just periodic audits), and drive monitoring findings to closure. You’ll also collaborate on building with **Claude**, including drafting/mapping controls, testing evidence, and deciding where human judgment stays in the loop. This is an **individual contributor** role for someone who works independently, writes clearly, and enjoys maintaining a control set that auditors and engineers can trust. ## Key responsibilities - **Own the Common Control Framework (CCF):** canonical control set, mappings to **SOC 2, ISO 27001/42001, HIPAA, FedRAMP**, and customer commitments; manage the change process for adding, retiring, or rewording controls. - **Draft and validate control descriptions/activities** with control owners so each control states: who does what, how often, in which system, and what evidence proves it. - **Design and run continuous monitoring** of control efficacy: define metrics and automated tests, tune false positives, surface failures early, and build a controls maturity model. - **Verify remediation and move to steady state:** advise on control design/implementation, confirm fixes match what auditors asked for, and maintain a single source of truth for control and finding status. - **Map new frameworks and commitments onto the CCF** and support gap assessments for new frameworks, certifications, products, or entities. - **Support integrated and customer audits:** readiness checks, walkthrough preparation, evidence request lists, and readouts of external findings. - **Evaluate evidence reliability**, including completeness/accuracy of system-generated and AI-generated evidence, and set the standard for audit-ready evidence. - **Build with Claude:** automate control mapping, evidence testing, and monitoring; verify machine-drafted control language before it becomes the record. ## Minimum qualifications - Several years in **IT audit, security compliance, or controls assurance**, including hands-on ownership of a control framework/library across multiple frameworks (e.g., SOC 2, ISO 27001, FedRAMP, HIPAA). - Strong audit mechanics knowledge: scoping, walkthroughs, sampling, design v
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.