New The Skills of Tomorrow: how AI-exposed is every skill in 2026? See the data →
Anthropic

Supplier Security & Assurance, Security GRC

Anthropic
Apply →
hybrid senior full-time $255,000-$270,000 USD San Francisco, CA

First indexed 18 Sept 2026

Description

About the role

Anthropic's Supplier Security & Assurance (SSA) team sits within Security GRC and is responsible for assessing the security of suppliers: evaluating whether vendors meet security requirements, capturing deviations, and providing clear approval decisions.

As a member of the SSA team, you will run supplier security assessments end-to-end, reviewing evidence, verifying agent-drafted evaluations, determining inherent and residual risk, and driving findings to closure with vendors and business owners. You will also extend assurance past approval, manage contractual security terms, secure configuration baselines, continuous monitoring, and reassessment.

Key Responsibilities

  • Run supplier security assessments: review agent-prefilled outputs, evaluate vendor controls and evidence, determine residual risk, and route to domain reviewers where deeper assessment is warranted
  • Operate supplier issue management and risk treatment: document findings with severity, owner, and due date, drive remediation with vendors and business owners, record risk acceptances, and roll open issues up to the risk register
  • Run continuous monitoring after approval: reopen assessments on defined triggers, investigate SaaS configuration, data, and use case drift signals, and queue reassessments where vendor scope has moved
  • Improve the program: identify gaps in coverage, questionnaires, requirements, and tooling, propose fixes, and carry roadmap items that mature supplier security
  • Tune and maintain the Claude-powered assessment platform: prompt development, questionnaire and assessment type design, calibration against assessor decisions, and output QA
  • Contribute to KPI and KRI reporting on coverage, cycle time, residual risk, open issues, and reassessments due

Minimum Qualifications

  • Experience running supplier security assessments end-to-end at a technology company
  • Working knowledge of risk fundamentals and judgment to apply them with incomplete evidence
  • Ability to assess vendors across security domains and recognize findings requiring specialists
  • Track record of driving risk treatment to closure through influence across teams
  • Experience building or tuning LLM-backed workflows or automations in risk, compliance, or operations contexts
  • Experience building or operating issue management workflows
  • Working technical knowledge of SaaS security configuration and standard vendor security contract terms
  • Ability to read SOC 2 reports or penetration tests and turn them into findings

Preferred Qualifications

  • Experience assessing cloud infrastructure, data center, or data-pipeline vendors
  • Experience supporting SOX, SOC 2, or ISO 27001 third-party or vendor management controls
  • Experience assessing specialized vendor cohorts from a security risk perspective
  • Experience with post-approval supplier continuous monitoring

Logistics

  • Annual Salary: $255,000-$270,000 USD
This listing is enriched and indexed by YubHub. To apply, use the employer's original posting: https://job-boards.greenhouse.io/anthropic/jobs/5427893008