Startups · AI

Lead, Security Controls Assurance - SOX

Anthropic · San Francisco, CA | Seattle, WA | New York City, NY | Washington, DC · On-site

← All jobs
About Anthropic

Anthropic is an AI safety and research company that's working to build reliable, interpretable, and steerable AI systems. Backed by Accel, Bessemer and General Catalyst.

About the role

Anthropic's Security Governance, Risk, and Compliance (GRC) team is the connective tissue that holds the company accountable to its security and control commitments. We translate regulatory, customer, and voluntary obligations into controls that teams act on, and give leadership a bird's-eye view of how well we're meeting them. We're building toward continuous assurance, to challenge and evidence the performance of controls continuously rather than through periodic audits.

What they're looking for

  • Thrive at the pace of a hypergrowth company. You're comfortable making calls with incomplete information and reprioritizing as scope shifts
  • Have led or been a senior contributor to an ITGC program through SOX 404 readiness and/or at a public company, with a working command of PCAOB AS 2201, COSO 2013, and how external auditors scope, test, and evaluate technology controls and deficiencies
  • Have genuine engineering fluency, possibly from an earlier engineering career: you can read code and Terraform, follow a CI/CD pipeline end to end, and challenge a design on its technical merits
  • Have programming skills in Python or at least one systems language such as Go, Rust, or C/C++
  • Have deep familiarity with developer platform, release engineering, cloud infrastructure, or ERP/financial systems control domains
  • Understand the role of the second line: you can advise and challenge engineering without taking ownership of their controls, and you know where the line sits between your monitoring and Internal Audit's independent testing
More about this role

Anthropic’s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems.

Anthropic's Security Governance, Risk, and Compliance (GRC) team is the connective tissue that holds the company accountable to its security and control commitments. We translate regulatory, customer, and voluntary obligations into controls that teams act on, and give leadership a bird's-eye view of how well we're meeting them. We're building toward continuous assurance, to challenge and evidence the performance of controls continuously rather than through periodic audits.

As Anthropic scales to meet public-company standards, the Sarbanes-Oxley (SOX) control environment over our technology stack is one of the most consequential things this team owns. As part of Security GRC's technical controls assurance function, you will be the voice on what the IT general controls must achieve to support SOX 404 compliance. In partnership with Internal Audit, you will define...

Read the full posting on Anthropic's site ↗

Security

Build your edge while you search

Free tools for founders and investors, plus VC Unfiltered, our take on startups, venture and the people who build them.