Security Risk Analyst, Risk Engineering

Anthropic•San Francisco, CA
•$270,000 - $345,000•Hybrid

About The Position

The Security Risk team at Anthropic is responsible for identifying, prioritizing, and driving the treatment of the company's most critical security risks. They are rebuilding risk management as an engineering function, leveraging automation, quantitative risk analysis, and AI-native platforms to inform decision-making. The role involves assessing risks across Anthropic's entire security landscape, requiring broad domain knowledge and the judgment to focus on critical areas. In close collaboration with Security Engineering, the Security Risk team helps define the security program and influences investment and treatment decisions. This role offers a direct line to CISO-level decisions, challenging conventional GRC playbooks not designed for frontier AI companies. The Security Risk Analyst will take risk questions from leadership and partner teams, driving them to a decision through structured qualitative or deep quantitative (FAIR-based) analysis. They will present clear positions, tradeoffs, and acknowledge uncertainty, defending their findings under scrutiny. Additionally, the analyst will contribute to turning quantitative risk into a usable product for partner teams and help establish standards for the growing risk function.

Requirements

  • Owned security or technology risk analysis end to end, both qualitative and quantitative, with demonstrable impact on decisions (e.g., funding, launch, remediation, acceptance).
  • Hands-on FAIR-style quantification experience, including scenario decomposition, calibrated estimation, and Monte Carlo simulation in Python, R, or spreadsheets, with experience briefing decision-makers.
  • Ability to thrive in ambiguity, frame moving questions into analyzable problems, select appropriate depth of analysis, and drive to decisions.
  • Skill in assigning defensible severity and likelihood to ambiguous problems, honestly stating uncertainty, and adapting positions based on evidence.
  • Sufficient technical security depth to decompose attack paths with security engineers and be credible in discussions.
  • Ability to condense complex risk positions into a concise paragraph for the CISO, making tradeoffs explicit and defending the position under questioning.
  • Experience using LLMs like Claude as daily working tools and critically reviewing model output.
  • Low ego, collaborative approach, building credibility through work, and a commitment to AI safety and the role of security risk.
  • Minimum education: Bachelor’s degree or an equivalent combination of education, training, and/or experience.
  • Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience.
  • Minimum years of experience: Years of experience required will correlate with the internal job level requirements for the position.

Nice To Haves

  • Applied FAIR-CAM or another structured approach to control effectiveness and attack path modeling.
  • Experience building or operating a cyber risk quantification program, or turning quantitative analysis into reusable tooling, templates, or training.
  • Experience helping define risk appetite or tolerance thresholds that were actually used for decision-making.
  • Background in security engineering, detection, threat intelligence, actuarial science, or decision science.
  • Familiarity with security risks specific to AI systems (e.g., goal or intent modification) and their impact on traditional threat models.

Responsibilities

  • Enable leadership and partner teams to make risk-informed decisions by taking ambiguous risk questions, driving them to a documented decision, and clearly communicating quantitative and qualitative tradeoffs.
  • Lead quantitative analysis of the company's top security risk scenarios using FAIR, calibrated estimation, and simulation, working with system-owning engineers and presenting actionable results to leadership.
  • Partner with Security Engineering to assess threat scenarios and control effectiveness, ensuring security investments are appropriately sized to actual risk and remediation is prioritized for maximum risk reduction.
  • Frame escalations and risk treatment decisions with a clear recommendation, an honest statement of uncertainty, and re-evaluation triggers, pressure-testing these decisions with risk owners.
  • Shape the analysis and narrative for leadership risk reviews, and help define the organization's risk appetite and key risk metrics.
  • Utilize AI and automation to scale risk analysis, owning the calibration and quality review to ensure trustworthy outputs.
  • Transform one-off analyses into reusable methods, templates, and training to promote self-service risk analysis for partner teams and improve the analytical quality of the risk register.

Benefits

  • Competitive compensation
  • Optional equity donation matching
  • Generous vacation
  • Parental leave
  • Flexible working hours
  • Visa sponsorship
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service