SlipstreamJobsFresh Startup & VC-Backed Jobs

Supplier Security & Assurance, Security GRC

Anthropic - San Francisco, CA, United States - Hybrid - posted 2026-09-18

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 255,000 - 270,000 / annual

Anthropic is seeking a Supplier Security & Assurance (SSA) specialist to join the Security GRC team. This role is responsible for assessing the security posture of Anthropic's vendor ecosystem—including SaaS providers, data operations vendors, compute and data center providers, hardware suppliers, and services firms—to ensure they meet security requirements and organizational risk tolerance. You will run supplier security assessments end-to-end: reviewing evidence, verifying AI-assisted evaluations, determining inherent and residual risk, and driving findings to closure with vendors and business owners. The program is designed agent-first, allowing you to focus your judgment on high-impact decisions, remediation, and the vendors that matter most. Key responsibilities include: - Conducting comprehensive supplier security assessments: reviewing agent-prefilled outputs, evaluating vendor controls and evidence, determining residual risk, and routing to domain specialists where deeper assessment is needed - Operating supplier issue management and risk treatment: documenting findings with severity, owner, and due date; driving remediation with vendors and business owners; recording risk acceptances; and escalating open issues to the risk register - Running continuous monitoring post-approval: reopening assessments on defined triggers (data classification changes, new SOC 2 reports, new subprocessors, vendor incidents); investigating SaaS configuration, data, and use case drift; and queuing reassessments when vendor scope changes - Improving the program: identifying gaps in coverage, questionnaires, requirements, and tooling; proposing fixes; and carrying roadmap items that mature the supplier security program - Tuning and maintaining the Claude-powered assessment platform: prompt development, questionnaire and assessment type design, calibration against assessor decisions, and output QA - Contributing to KPI and KRI reporting on coverage, cycle time, residual risk, open issues, and reassessments due Anthropics's mission is to create reliable, interpretable, and steerable AI systems. The company is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems. REQUIREMENTS: Minimum qualifications: - End-to-end supplier security assessment experience at a technology company: scoping engagements, determining inherent risk, reviewing controls and evidence, documenting residual risk, and driving findings to closure - Working knowledge of risk fundamentals (inherent and residual risk, control effectiveness, compensating controls, risk acceptance) and judgment to apply them when evidence is incomplete or answers aren't in a framework - Ability to assess vendors across security domains and recognize which findings you can close yourself versus which need a security domain specialist - Track record of driving risk treatment to closure through influence across teams with competing priorities - Experience building or tuning an LLM-backed workflow, agent, or automation in a risk, compliance, or operations context, including prompt tuning and reviewing model output for accuracy - Experience building or operating issue management workflows: logging issues with clear owner and due date, tracking remediation, and escalating when treatment stalls - Working technical knowledge of SaaS security configuration (SSO and SCIM, admin scoping, sharing defaults, audit log export) and standard vendor security contract terms (DPA, incident notification, subprocessors, audit and testing rights) - Ability to read SOC 2 reports or penetration tests and turn them into findings: identify control exceptions and carve-outs, map complementary user entity controls, and judge what evidence does and does not prove Preferred qualifications: - Experience assessing cloud infrastructure, data center, or data-pipeline vendors - Experience supporting SOX, SOC 2, or ISO 27001 third-party or vendor management controls - Experience assessing specialized vendor cohorts from a security risk perspective: human data operations or data labeling vendors, hardware suppliers, compute providers and neoclouds - Experience with post-approval supplier continuous monitoring: configuration, data, and use case drift detection, shadow IT & SaaS detection, vendor incident management, or evidence-based vendor audits/site visits Minimum education: Bachelor's degree or equivalent combination of education, training, and/or experience in a field relevant to the role.

Similar roles