Lead, Security Controls Assurance - SOX

Showcify

Bogotá ciudad

Híbrido

COP 1.273.371.000 - 1.583.949.000

Jornada completa

Hace 13 días
Generador de candidaturas

Transforma esta oferta en una entrevista: un currículum y una carta de presentación creados pensando en lo que quiere el empleador.

Supera los filtros ATS

Descripción de la vacante

Anthropic is seeking a Security GRC professional to own IT general controls design and continuous control monitoring in support of SOX 404 readiness. You will partner with Internal Audit and engineering to ensure controls are deeply embedded in systems.

You will define requirements, supervise monitoring programs, and drive remediation with cross-functional teams. A strong background in Python/Go/C++ and Terraform will be valuable in this role.

Formación

  • Thrive at the pace of a hypergrowth company. You're comfortable making calls with incomplete information and reprioritizing as scope shifts.
  • Have led or been a senior contributor to an ITGC program through SOX 404 readiness and/or at a public company, with a working command of PCAOB AS 2201, COSO 2013, and how external auditors scope, test, and evaluate technology controls and deficiencies.
  • Have genuine engineering fluency, possibly from an earlier engineering career: you can read code and Terraform, follow a CI/CD pipeline end to end, and challenge a design on its technical merits.
  • Have programming skills in Python or at least one systems language such as Go, Rust, or C/C++.
  • Have deep familiarity with developer platform, release engineering, cloud infrastructure, or ERP/financial systems control domains.
  • Understand the role of the second line: you can advise and challenge engineering without taking ownership of their controls, and you know where the line sits between your monitoring and Internal Audit's independent testing.
  • Are a strong collaborator and communicator across Finance, Engineering, Internal Audit, and external auditors.
  • Use Claude and other LLMs as daily working tools, and have grounded, specific views on which SOX assurance workflows AI can run today and which it can't yet.
  • Translate SOX and framework language into acceptance criteria engineers can build against, and translate engineering reality back into assurance language auditors and leadership can rely on.
  • Default to getting the requirement designed into the system rather than papering over the gap with procedure.

Responsabilidades

  • Define control requirements and acceptance criteria across the core ITGC domains of logical access, change management, computer operations, and program development for SOX in-scope systems, including home-built platforms where the control has to be designed into the system rather than bolted on.
  • Set the bar for in-scope systems from day one. As financially significant systems are built, migrated, or replaced, define what the system must provide (auditability, segregation of duties, change control, immutable logging, evidence retention) before go-live, so controls are not retrofitted after the fact.
  • Pressure-test changes for SOX impact during design. Review major infrastructure, system, and agent framework changes for control impact while decisions are still cheap, and maintain a clear view of which changes alter the SOX scope, key control population, or evidence requirements.
  • Own second-line control monitoring and evidence readiness. Stand up continuous controls monitoring and automated evidence collection for ITGCs (control testing, walkthrough preparation, population and completeness validation, and mapping to the common controls framework). Materially raise automated evidence coverage and cut audit prep time.
  • Drive control deficiency remediation with cross functional partners. Track and root-cause ITGC deficiencies surfaced by monitoring, Internal Audit, or external audit; partner with engineering owners on remediation design; and assess whether remediation actually closes the gap before re-testing.
  • Assess scope changes through a SOX lens. When new products, entities, systems, or integrations come into scope, provide technical and compliance assessment of their impact on control design, evidence requirements, and engineering effort before commitments are made.
  • Maintain alignment with the broader compliance portfolio. Where SOX ITGCs overlap with SOC 2, ISO 27001/42001, or other frameworks, ensure controls are designed once and evidences are provided once.

Conocimientos

Python
Go
Rust
C/C++
CI/CD
Cloud infra
SOX ITGC
Auditing
Communication

Educación

Bachelor's degree in a relevant field

Herramientas

Terraform
Cloud platforms (AWS/Azure)

Descripción del empleo

About Anthropic

Anthropic’s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems.

About the role

Anthropic's Security Governance, Risk, and Compliance (GRC) team is the connective tissue that holds the company accountable to its security and control commitments. We translate regulatory, customer, and voluntary obligations into controls that teams act on, and give leadership a bird's-eye view of how well we're meeting them. We're building toward continuous assurance, to challenge and evidence the performance of controls continuously rather than through periodic audits.

As Anthropic prepares for life as a public company, the Sarbanes-Oxley (SOX) control environment over our technology stack is one of the most consequential things this team owns. As part of Security GRC's technical controls assurance function, you will be the voice on what the IT general controls must achieve to support SOX 404 compliance. In partnership with Internal Audit, you will define control requirements and acceptance criteria for the in-scope engineering systems and infrastructure that underpin financial reporting. You will pair with engineering as they design and implement against those requirements, and validate that what ships actually meets the bar before Internal Audit and our external auditors test it. You are the product owner for control design methodology and continuous control monitoring, initially around ITGCs, but extending into other areas of security and compliance to drive visibility where and when we need it.

Key responsibilities
  • Define control requirements and acceptance criteria across the core ITGC domains of logical access, change management, computer operations, and program development for SOX in-scope systems, including home-built platforms where the control has to be designed into the system rather than bolted on.

  • Set the bar for in-scope systems from day one. As financially significant systems are built, migrated, or replaced, define what the system must provide (auditability, segregation of duties, change control, immutable logging, evidence retention) before go-live, so controls are not retrofitted after the fact.

  • Pressure-test changes for SOX impact during design. Review major infrastructure, system, and agent framework changes for control impact while decisions are still cheap, and maintain a clear view of which changes alter the SOX scope, key control population, or evidence requirements.

  • Own second-line control monitoring and evidence readiness. Stand up continuous controls monitoring and automated evidence collection for ITGCs (control testing, walkthrough preparation, population and completeness validation, and mapping to the common controls framework). Materially raise automated evidence coverage and cut audit prep time.

  • Drive control deficiency remediation with cross functional partners. Track and root-cause ITGC deficiencies surfaced by monitoring, Internal Audit, or external audit; partner with engineering owners on remediation design; and assess whether remediation actually closes the gap before re-testing.

  • Assess scope changes through a SOX lens. When new products, entities, systems, or integrations come into scope, provide technical and compliance assessment of their impact on control design, evidence requirements, and engineering effort before commitments are made.

  • Maintain alignment with the broader compliance portfolio. Where SOX ITGCs overlap with SOC 2, ISO 27001/42001, or other frameworks, ensure controls are designed once and evidenced once, and that changes made for one framework do not silently break another.

Minimum qualifications
  • Thrive at the pace of a hypergrowth company. You're comfortable making calls with incomplete information and reprioritizing as scope shifts.

  • Have led or been a senior contributor to an ITGC program through SOX 404 readiness and/or at a public company, with a working command of PCAOB AS 2201, COSO 2013, and how external auditors scope, test, and evaluate technology controls and deficiencies.

  • Have genuine engineering fluency, possibly from an earlier engineering career: you can read code and Terraform, follow a CI/CD pipeline end to end, and challenge a design on its technical merits.

  • Have programming skills in Python or at least one systems language such as Go, Rust, or C/C++.

  • Have deep familiarity with developer platform, release engineering, cloud infrastructure, or ERP/financial systems control domains.

  • Understand the role of the second line: you can advise and challenge engineering without taking ownership of their controls, and you know where the line sits between your monitoring and Internal Audit's independent testing.

  • Are a strong collaborator and communicator across Finance, Engineering, Internal Audit, and external auditors.

  • Use Claude and other LLMs as daily working tools, and have grounded, specific views on which SOX assurance workflows AI can run today and which it can't yet.

  • Translate SOX and framework language into acceptance criteria engineers can build against, and translate engineering reality back into assurance language auditors and leadership can rely on.

  • Default to getting the requirement designed into the system rather than papering over the gap with procedure.

Preferred qualifications
  • A combination of audit or advisory experience (Big 4 or equivalent, ideally IT audit) with in-house experience at an AI-forward tech company, in either order.

  • Taken a company through a first-year SOX 404(a) and 404(b) assessment, including a first external ITGC audit.

  • Defined or assessed controls over home-built financially significant systems, usage-based billing, or revenue metering pipelines.

  • Defined or assessed controls for AI/ML systems or agents acting in production environments.

  • Stood up continuous controls monitoring or automated evidence programs.

  • Experience with SOC 1 reliance, service organization control mapping, and complementary user entity controls.

  • CISSP, CISA, CPA, or equivalent certification.

The annual compensation range for this role is listed below.

For sales roles, the range provided is the role’s On Target Earnings ("OTE") range, meaning that the range includes both the sales commissions/sales bonuses target and annual base salary for the role.

Annual Salary:

$410,000 — $510,000 USD

Logistics

Minimum education: Bachelor’s degree or an equivalent combination of education, training, and/or experience

Required field of study:A field relevant to the role as demonstrated through coursework, training, or professional experience

Minimum years of experience: Years of experience required will correlate with the internal job level requirements for the position

Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices.

Visa sponsorship:We do sponsor visas! However, we aren't able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this.

Not all strong candidates will meet every single qualification as listed. Research shows that people who identify as being from underrepresented groups are more prone to experiencing imposter syndrome and doubting the strength of their candidacy, so we urge you not to exclude yourself prematurely and to submit an application if you're interested in this work. We think AI systems like the ones we're building have enormous social and ethical implications. We think this makes representation even more important, and we strive to include a range of diverse perspectives on our team. Your safety matters to us. To protect yourself from potential scams, remember that Anthropic recruiters only contact you from@anthropic.comemail addresses. In some cases, we may partner with vetted recruiting agencies who will identify themselves as working on behalf of Anthropic. Be cautious of emails from other domains. Legitimate Anthropic recruiters will never ask for money, fees, or banking information before your first day. If you're ever unsure about a communication, don't click any links—visitdirectly for confirmed position openings.

How we’re different

We believe that the highest-impact AI research will be big science. At Anthropic we work as a single cohesive team on just a few large-scale research efforts. And we value impact — advancing our long-term goals of steerable, trustworthy AI — rather than work on smaller and more specific puzzles. We view AI research as an empirical science, which has as much in common with physics and biology as with traditional efforts in computer science. We're an extremely collaborative group, and we host frequent research discussions to ensure that we are pursuing the highest-impact work at any given time. As such, we greatly value communication skills.

The easiest way to understand our research directions is to read our recent research. This research continues many of the directions our team worked on prior to Anthropic, including: GPT-3, Circuit-Based Interpretability, Multimodal Neurons, Scaling Laws, AI & Compute, Concrete Problems in AI Safety, and Learning from Human Preferences.

Anthropic is a public benefit corporation headquartered in San Francisco. We offer competitive compensation and benefits, optional equity donation matching, generous vacation and parental leave, flexible working hours, and a lovely office space in which to collaborate with colleagues. Guidance on Candidates' AI Usage:Learn about our policy for using AI in our application process.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Manager, Customer Success – Strategic Consumer Tech
Manager, Customer Success – Strategic Consumer Tech

United States Digital Space LLC • Bogotá ciudad

Híbrido
COP 822.547.000 - 993.264.000
Hybrid work flexibility
Senior AI Engineer — Remote, Build Trusted AI for Web3
Senior AI Engineer — Remote, Build Trusted AI for Web3

ChainGPT • Colombia

A distancia
COP 402.738.622 - 536.984.830
Flexible hours
Competitive compensation
Remote-first environment
Senior AI Platform Engineer
Senior AI Platform Engineer

Caseware • Colombia

Presencial
COP 186.840.000 - 280.260.000
Global Marketing Lead — AI Infrastructure & Consumer Growth
Global Marketing Lead — AI Infrastructure & Consumer Growth

ChainGPT • Colombia

Presencial
COP 288.683.603 - 416.987.426
Flexible PTO
Remote Work
Schedule That Matches You
+6
Senior Forward Deployed AI Architect (GenAI, AWS)
Senior Forward Deployed AI Architect (GenAI, AWS)

Provectus • Bogotá

Híbrido
COP 374.895.000 - 562.342.000
Remote-friendly culture
Education budget
Medical insurance coverage
+1
Senior AI Engineer
Senior AI Engineer

Athenaworks • Bogotá

Presencial
COP 388.878.000 - 583.318.000
Payment in USD
Flexible work schedule
Non-working pay days
+1
Senior AI Engineer | Colombia | English C1
Senior AI Engineer | Colombia | English C1

Cadre AI • Colombia

Presencial
COP 150.000.000 - 230.000.000
AI-DNA Software Engineering Superbuilder
AI-DNA Software Engineering Superbuilder

IgniteTech • Colombia

A distancia
COP 640.123.000
Senior Forward Deployed AI Architect (GenAI, AWS)
Senior Forward Deployed AI Architect (GenAI, AWS)

Provectus • Perímetro Urbano Barranquilla

Presencial
COP 374.895.000 - 562.342.000
Remote-friendly culture
PTO policy, local public holidays
Medical insurance coverage
+1
Senior Forward Deployed AI Engineer / Solutions Architect (GenAI, AWS)
Senior Forward Deployed AI Engineer / Solutions Architect (GenAI, AWS)

Provectus • Sur

Presencial
COP 120.000.000 - 180.000.000