Supplier Security & Assurance (Security GRC)
Anthropic · San Francisco
Job description
About the role
Anthropic’s Supplier Security & Assurance (SSA) team within Security GRC assesses the security of the company’s suppliers, ensuring they meet security requirements and providing clear approval decisions. The role involves end‑to‑end supplier assessments, continuous monitoring, and shaping the tooling and requirements for the program.
Key responsibilities
- Run supplier security assessments: review agent‑prefilled outputs, evaluate vendor controls and evidence, determine residual risk, and route to domain reviewers when deeper assessment is needed.
- Operate supplier issue management and risk treatment: document findings with severity, owner and due date, drive remediation with vendors and business owners, and record risk acceptances.
- Run continuous monitoring after approval: reopen assessments on triggers such as data‑classification changes, new SOC 2 reports, or vendor incidents, and queue reassessments when scope changes.
- Improve the program: identify gaps in coverage, questionnaires, requirements, and tooling, propose fixes, and carry roadmap items to mature supplier security.
- Tune and maintain the Claude‑powered assessment platform: develop prompts, design questionnaires, calibrate against assessor decisions, and ensure output quality.
Required profile
- Experience running supplier security assessments end‑to‑end at a technology company.
- Working knowledge of risk fundamentals (inherent and residual risk, control effectiveness, compensating controls, risk acceptance).
- Ability to assess vendors across security domains and know when to involve domain specialists.
- Track record of driving risk treatment to closure through influence across teams.
- Experience building or tuning LLM‑backed workflows or agents in a risk/compliance context.
- Experience operating issue‑management workflows with clear owners, due dates and escalation paths.
- Technical knowledge of SaaS security configuration (SSO, SCIM, admin scoping, sharing defaults, audit‑log export) and standard vendor contract terms (DPA, incident notification, subprocessors, audit rights).
- Ability to read SOC 2 reports or penetration tests and translate them into actionable findings.
Required skills
- LLM‑backed workflow development and prompt tuning
- Claude‑powered assessment platform configuration
- SaaS security configuration (SSO, SCIM, admin scoping, audit‑log export)
- SOC 2 report analysis and control mapping
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in the United States.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 1 day ago
Expires 1 month from now
4 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
Anthropic
San Francisco