Security Audit & Controls, Security GRC

Anthropic•Seattle, WA
•$270,000 - $345,000•Hybrid

About The Position

Anthropic's Security Governance, Risk, and Compliance (GRC) team is responsible for ensuring the company adheres to its security commitments. This role, within the Audit & Assurance function of Compliance & Audit Programs, focuses on owning the Common Control Framework (CCF) across all control domains. The CCF is the foundation of the security program, translating regulatory, customer, and voluntary obligations into actionable controls. The team is working towards a novel GRC approach that leverages AI, like Claude, for continuous control performance monitoring and evidence validation, with human oversight for critical judgment. This individual contributor role requires strong independence, clear writing, and a dedication to maintaining an accurate and trusted control set.

Requirements

  • Several years in IT audit, security compliance, or controls assurance.
  • Hands-on ownership of a control framework or control library across multiple frameworks (e.g., SOC 2, ISO 27001, FedRAMP, HIPAA).
  • Working command of audit mechanics: scoping, walkthroughs, sampling, design vs. operating effectiveness, deficiency evaluation, and evidence reliability.
  • Experience writing control descriptions, control activities, and test procedures.
  • Experience with continuous controls monitoring or automated evidence collection.
  • Sufficient technical fluency to read and understand runbooks, configurations, or pipeline definitions.
  • Clear writing skills for control language and status reports.
  • Ability to influence control owners and partner teams to prioritize and complete work without direct authority.

Nice To Haves

  • Designed or rebuilt a common controls framework and led remapping of existing frameworks.
  • Stood up continuous controls monitoring or automated evidence programs and can discuss coverage, false-positive rates, and outcomes.
  • Applied LLMs to assurance work (control drafting, framework mapping, evidence testing, monitoring).
  • Defined or assessed controls for AI systems or agents operating in production, or for homegrown internal systems.
  • Provided requirements for a homegrown GRC platform and worked with engineers.

Responsibilities

  • Own the Common Control Framework (CCF), including its mappings to frameworks like SOC 2, ISO 27001/42001, HIPAA, FedRAMP, and customer commitments, and manage the change process for controls.
  • Draft and validate control descriptions and activities with control owners to accurately reflect operational reality.
  • Design and execute continuous monitoring of control effectiveness, defining metrics, automated tests, and building a control maturity model.
  • Verify remediation efforts, advise on control design and implementation, and confirm fixes against audit requirements.
  • Map new frameworks and commitments onto the CCF and support gap assessments for new certifications, products, or entities.
  • Support integrated and customer audits by preparing for readiness checks, walkthroughs, and evidence requests.
  • Evaluate the reliability of evidence, including system-generated reports and AI-generated evidence, and establish standards for audit-ready evidence.
  • Utilize AI tools like Claude to automate control mapping, evidence testing, and monitoring, verifying machine-drafted control language.

Benefits

  • Competitive compensation
  • Optional equity donation matching
  • Generous vacation
  • Parental leave
  • Flexible working hours
  • Office space for collaboration
  • Visa sponsorship
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service