Security Audit & Controls, Security GRC

Anthropic•San Francisco, CA
•Hybrid

About The Position

Anthropic's Security Governance, Risk, and Compliance (GRC) team is responsible for ensuring the company adheres to its security commitments. This role, within the Audit & Assurance function, focuses on managing the Common Control Framework (CCF) and overseeing the assurance view across all control domains. The position involves translating regulatory, customer, and voluntary obligations into actionable controls, and providing leadership with insights into the company's security posture. A key aspect of this role is leveraging AI, specifically Claude, to continuously monitor control performance and evidence, moving beyond traditional periodic audits. The individual will work with control owners and GRC Partners to ensure control descriptions accurately reflect reality, build continuous monitoring systems, and drive the resolution of identified issues.

Requirements

  • Several years in IT audit, security compliance, or controls assurance.
  • Hands-on ownership of a control framework or control library across multiple frameworks (e.g., SOC 2, ISO 27001, FedRAMP, HIPAA).
  • Working command of audit mechanics: scoping, walkthroughs, sampling, design versus operating effectiveness, deficiency evaluation, and evidence reliability.
  • Experience writing control descriptions, control activities, and test procedures.
  • Experience with continuous controls monitoring or automated evidence collection.
  • Sufficient technical fluency to read and understand runbooks, configurations, or pipeline definitions.
  • Clear writing skills for control language and status reports.
  • Ability to influence control owners and partner teams to prioritize and close work without direct authority.

Nice To Haves

  • Designed or rebuilt a common controls framework and led the remapping of existing frameworks onto it.
  • Stood up continuous controls monitoring or automated evidence programs and can discuss coverage, false-positive rates, and outcomes.
  • Applied LLMs to assurance work (control drafting, framework mapping, evidence testing, monitoring).
  • Defined or assessed controls for AI systems or agents in production, or for home-built internal systems.
  • Provided requirements for a homegrown GRC platform and worked with engineers to build it.
  • Hold certifications such as CISA or CISSP.
  • Prior AI-industry experience.

Responsibilities

  • Own the Common Control Framework (CCF), including its mappings to frameworks like SOC 2, ISO 27001/42001, HIPAA, FedRAMP, and customer commitments, and manage the change process for controls.
  • Draft and validate control descriptions and activities with control owners to accurately document who does what, how often, in which system, and what evidence proves it.
  • Design and execute continuous monitoring of control efficacy, defining metrics, automated tests, and tuning out false positives to surface failures to owners proactively.
  • Build a controls maturity model to indicate the status of each control domain and outline steps for improvement.
  • Verify remediation efforts, advise on control design and implementation, and confirm fixes against audit requirements.
  • Standardize evidence collection and automate it where appropriate, integrating controls into the unified audit management program.
  • Map new frameworks and commitments onto the CCF and support gap assessments for new frameworks, certifications, products, or entities.
  • Support integrated and customer audits by preparing for readiness checks, walkthroughs, and evidence requests, and by analyzing external findings.
  • Evaluate the reliability of evidence, including system-generated reports and AI-generated evidence, and establish standards for audit-ready evidence.
  • Utilize AI tools like Claude to automate control mapping, evidence testing, and monitoring, verifying machine-drafted control language.

Benefits

  • Competitive compensation
  • Optional equity donation matching
  • Generous vacation
  • Generous parental leave
  • Flexible working hours
  • Office space for collaboration
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service