Security Audit & Controls, Security GRC
OtherHybrid — San Francisco, CA | New York City, NY
Published on 2026-10-02
These details were extracted automatically from the original listing. They may not be complete or fully up to date — it's worth checking the original job post.
About this role
This role involves owning the Common Control Framework (CCF) and ensuring the effectiveness of security controls within the organization. The position focuses on drafting control descriptions, conducting continuous monitoring, and verifying remediation efforts in collaboration with various stakeholders.
About the company
Anthropic builds reliable and interpretable AI systems, including the Claude family of models, for businesses and developers. The company focuses on AI safety research and practical AI assistants for enterprise and consumer use.
The team
Security Audit & Controls team
What you'll do
- Own the Common Control Framework and its mappings
- Draft and validate control descriptions and activities
- Design and run continuous monitoring of control efficacy
- Verify remediation and carry it into steady state
- Map new frameworks onto the CCF
- Support integrated and customer audits
- Evaluate evidence reliability
- Build automation with Claude
What we're looking for
- Several years in IT audit or compliance
- Working command of audit mechanics
- Experience writing control descriptions
- Experience with continuous controls monitoring
- Technical fluency to read configurations
- Strong writing skills
- Ability to prioritize and close work with partners
Nice to have
- Experience designing a common controls framework
- Experience standing up continuous controls monitoring
- Applied LLMs to assurance work
- Defined controls for AI systems
- Provided requirements for GRC platforms
