SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 230,000 - 300,000 / annual
Anthropic is seeking a Senior Manager, IT SOX to join the Internal Audit team and lead the company's IT SOX compliance program. This is a hands-on technical role reporting to the Head of IT SOX, combining individual contributor expertise with team leadership responsibilities.
You will serve as a key executor and trusted advisor for IT General Controls (ITGCs), IT Application Controls (ITACs), and system risk assessments. The role is well-suited for someone comfortable with ambiguity in a high-pace environment, particularly one who enjoys solving novel compliance problems in an AI-first organization.
Key responsibilities include:
- Advising on control environment design tailored to an AI-first company, including controls over automated DevOps pipelines and emerging agentic identity models
- Partnering with Engineering, Security, IT, and DevOps teams to assess design and implementation of scalable controls
- Assessing new system implementations and changes
- Identifying automation and tooling opportunities to improve control efficiency and continuous monitoring
- Scoping and planning annual SOX IT assessments
- Executing IT SOX testing across ITGCs and ITACs, including access management, change management, and computer operations
- Performing system and process risk assessments to identify control gaps and recommend remediation
- Owning control documentation and ensuring audit-ready evidence is current and complete
- Evaluating IT automated controls and supporting the shift from manual to automated control reliance
- Scaling the IT SOX program as the company grows, rationalizing scope, standardizing testing approaches, and building repeatable processes
- Guiding and directing day-to-day work of internal team members and co-sourced partners, setting priorities, reviewing workpapers, and ensuring quality
- Building strong working relationships with process and control owners across the organization
- Translating technical control requirements for non-technical stakeholders and vice versa
- Supporting SEC cybersecurity disclosure requirements and related risk monitoring
- Coordinating with external auditors on IT SOX matters, including evidence requests, walkthroughs, and testing schedules
- Tracking and assisting with remediation of audit findings
You will bring technical depth, a bias toward automation, and the ability to partner effectively with both technical teams and external auditors as the organization scales to public-company standards.
Minimum qualifications:
- Hands-on IT audit or IT SOX compliance experience, ideally in a fast-paced technology environment
- Deep working knowledge of ITGCs, ITACs, and IT risk assessment methodologies
- Experience auditing highly automated DevOps environments (CI/CD pipelines, infrastructure-as-code, automated deployments) and adapting traditional change-management and access controls to them
- Experience designing, testing, and documenting controls across access management, change management, and computer operations
- Demonstrated comfort with ambiguity and ability to operate effectively in a high-pace, rapidly changing environment
- Ability to effectively guide and direct the work of internal team members and/or co-sourced partners
- Ability to work independently on complex, ambiguous workstreams while communicating proactively with senior stakeholders
- Strong project management and organizational skills with close attention to detail
- Clear, effective communicator able to work across technical and non-technical audiences
- Bachelor's degree or equivalent combination of education, training, and/or experience
- Field of study relevant to the role as demonstrated through coursework, training, or professional experience
Preferred qualifications:
- 8+ years of hands-on IT audit and SOX compliance experience, including time in a Big 4 or comparable environment
- Hands-on experience with cloud environments (GCP, AWS, and/or Azure)
- Experience scaling a compliance program to public-company standards
- Track record of scaling an audit or SOX program through periods of rapid growth
- Familiarity with enterprise systems such as Workday, Salesforce, or GitHub
- Experience evaluating SDLC controls in modern software development environments
- CISA, CIA, CISSP, CPA, or equivalent certification
- Genuine enthusiasm for working in an AI-first environment, applying AI to audit work itself and rethinking assumptions about how controls operate when AI is embedded in the processes being audited