SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 270,000 - 345,000 / annual
Anthropic is seeking a Security Risk & Compliance Manager to join its security department. This role is responsible for understanding and implementing security and AI safety expectations established by regulators, customers, and industry norms. You will provide direction to internal partners on security and safety requirements, earn security credentials, and respond to inquiries from auditors, customers, and partners.
Key responsibilities include:
- Understanding how Anthropic's security and privacy capabilities across major cloud platforms implement common frameworks such as NIST 800-53, NIST 800-171, ISO 27001, ISO 27701, CSA CCM, and SOC 2
- Building scalable data center and hyperscaler processes and documentation systems to support future expansion to additional geographies and compliance frameworks
- Assessing and mitigating security and operational risks, implementing corrective actions, and managing vendor compliance
- Coordinating engagements with independent assessors to earn security and privacy certifications and attestations important to customers and enterprise partnerships, and to meet regulatory obligations
- Writing, updating, and enacting policies capturing security, privacy, and AI safety requirements
- Maintaining and enhancing Anthropic's system of security controls through audit readiness, recordkeeping, and cross-functional communication
This is a unique opportunity to build a new kind of compliance program focused on securing novel and valuable AI capabilities. You will work in a fast-paced, high-growth environment at a leading AI safety company.
ANTHROPIC CONTEXT: Anthropic is a public benefit corporation headquartered in San Francisco with a mission to create reliable, interpretable, and steerable AI systems. The company offers competitive compensation, optional equity donation matching, generous vacation and parental leave, flexible working hours, and collaborative office space. Hybrid policy requires at least 25% in-office time, though some roles may require more.
REQUIREMENTS:
Minimum qualifications:
- 8+ years of progressive experience in audit and compliance roles, with direct ownership of certification/attestation or security compliance implementation projects
- Experience working in cloud-native environments with understanding of security and privacy considerations for multi-cloud and hybrid architectures
- Ability to translate complex compliance requirements into actionable workstreams for technical and non-technical stakeholders
- Experience integrating with common controls frameworks or GRC systems that scaled with organizational growth
- Strong written communication skills for security and privacy documentation for both external and internal audiences
- Ability to thrive in ambiguous, fast-paced environments where processes must be built from scratch
- Comfort organizing time-bounded task management of delegated work streams across a diverse organization
- Enthusiasm for being the subject matter expert who educates the organization on new compliance requirements and auditors on current security practices
Preferred qualifications:
- Experience in AI/ML companies with understanding of unique security considerations for model development and deployment
- Experience with cloud companies and understanding of cloud security controls and physical security requirements
- Background from high-growth technology companies managing rapid compliance expansion
- Experience implementing automated enforcement of security controls (compliance as code)
- Relevant certifications: CISA, CRISC, CISM, CISSP, or ISO 27001 Lead Auditor/Implementer
Minimum education: Bachelor's degree or equivalent combination of education, training, and/or experience in a field relevant to the role.