SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Anthropic is seeking a Senior Manager, IT SOX to join the Internal Audit team and lead the company's IT SOX compliance program. This is a hands-on technical role reporting to the Head of IT SOX, combining individual contributor expertise with team leadership responsibilities.
You will design and execute IT General Controls (ITGCs), IT Application Controls (ITACs), and system risk assessments tailored to an AI-first, rapidly scaling organization. Key responsibilities include advising on control environments for highly automated DevOps pipelines and emerging agentic identity models; partnering with Engineering, Security, IT, and DevOps teams to assess control design and implementation; performing IT SOX testing across access management, change management, and computer operations; and identifying automation opportunities to improve control efficiency and monitoring.
You will guide and direct internal team members and co-sourced partners, setting priorities and ensuring quality across the testing program. Additional duties include scoping and planning annual SOX IT assessments, performing system and process risk assessments, owning control documentation, evaluating automated controls, and scaling the IT SOX program as the company grows. You'll act as a trusted advisor translating technical control requirements for non-technical stakeholders, support SEC cybersecurity disclosure requirements, coordinate with external auditors, and track remediation of audit findings.
The ideal candidate has 8+ years of hands-on IT audit and SOX compliance experience, ideally from a Big 4 firm or comparable environment. You must have deep working knowledge of ITGCs, ITACs, and IT risk assessment methodologies, with demonstrated experience auditing highly automated DevOps environments (CI/CD pipelines, infrastructure-as-code, automated deployments). Experience designing, testing, and documenting controls across access management, change management, and computer operations is essential. You should be comfortable with ambiguity, thrive in high-pace environments, and have proven ability to guide and direct team members independently on complex workstreams while communicating proactively with senior stakeholders.
Preferred qualifications include hands-on experience with cloud environments (GCP, AWS, Azure), experience at pre-IPO or newly public technology companies, track record of scaling audit or SOX programs through rapid growth, familiarity with enterprise systems (Workday, Salesforce, GitHub), experience evaluating SDLC controls in modern software development environments, and certifications such as CISA, CIA, CISSP, or CPA.