# Supplier Security & Assurance, Security GRC at Anthropic

- Company: Anthropic
- What the company does: Anthropic is an AI safety and research company that's working to build reliable, interpretable, and steerable AI systems. Backed by Accel, Bessemer and General Catalyst.
- Company website: https://www.anthropic.com/
- Type: Startups (AI role)
- Level: Mid level
- Location: San Francisco, CA | Seattle, WA | New York City, NY | Washington, DC
- Work setup: On-site
- Posted: 2026-09-17
- Apply by: 2026-11-01
- Apply: https://job-boards.greenhouse.io/anthropic/jobs/5427893008
- Page: https://www.1752.vc/careers/jobs/anthropic-supplier-security-and-assurance-security-grc/

## About the role

Anthropic's Supplier Security & Assurance (SSA) team sits within Security GRC and is responsible for assessing the security of our suppliers: evaluating whether vendors meet our security requirements, capturing the deviations, and giving the business a clear approval decision it can act on. We assess the vendor population a frontier AI lab actually depends on: SaaS and software, human data operations, compute and data center providers, hardware suppliers, and services firms.

## What they're looking for

- Experience running supplier security assessments end to end at a technology company: scoping the engagement, determining inherent risk, reviewing controls and evidence, documenting residual risk, and driving findings to closure
- Working knowledge of risk fundamentals (inherent and residual risk, control effectiveness, compensating controls, risk acceptance) and the judgment to apply them when the evidence is incomplete or the answer isn't in a framework
- Ability to assess a vendor across security domains, and to recognize which findings you can close yourself and which need a security domain specialist
- Track record of driving risk treatment to closure through influence across teams with competing priorities
- Experience building or tuning an LLM-backed workflow, agent, or automation in a risk, compliance, or operations context, including tuning prompts and reviewing model output for accuracy
- Experience building or operating issue management workflows: logging issues with a clear owner and due date, tracking remediation, and escalating when treatment stalls

Tags: Security
