GRC Security Auditor: Common Controls & Monitoring

Anthropic

San Francisco (CA)

Hybrid

USD 270,000 - 345,000

Full time

5 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Equity donation matching
Vacation & parental leave
Flexible hours
Office in SF

Job summary

Anthropic in San Francisco seeks a Security Audit & Controls specialist to own the CCF across control domains, implementing monitoring and evidence collection.

You will work with control owners and GRC partners to ensure evidence is reliable, and drive remediation to closure, while mapping new frameworks and supporting external audits.

This role emphasizes independent work, clear writing, and the ability to influence controls with auditors and engineers.

Qualifications

  • Several years in IT audit, security compliance, or controls assurance across more than one framework (e.g., SOC 2, ISO 27001, FedRAMP, HIPAA).
  • Hands-on ownership of a control framework or control library across multiple frameworks (e.g., SOC 2, ISO 27001, FedRAMP, HIPAA).
  • Experience writing control descriptions, control activities, and test procedures relied on by auditors.
  • Experience with continuous controls monitoring or automated evidence collection.
  • Enough technical fluency to read a runbook, a configuration, or a pipeline definition and assess enforcement of the written control claims.
  • Clear writing, because control language and status reports are used by auditors, engineers, and leadership.
  • Ability to collaborate with control owners and partner teams to prioritize and close work.

Responsibilities

  • Own the Common Control Framework and its mappings to SOC 2, ISO 27001/42001, HIPAA, FedRAMP, and change processes for controls.
  • Draft and validate control descriptions and activities with owners, detailing who, how often, in which system, and what evidence proves it.
  • Design and run continuous monitoring of control efficacy: define metrics and automated tests, tune false positives, surface failures to owners.
  • Verify remediation and carry it into steady state with GRC Partners and control owners.
  • Map new frameworks onto the CCF and write requirements for deltas.
  • Support integrated audits and customer audits: readiness checks and evidence requests.
  • Evaluate evidence reliability, including AI-generated evidence, and set audit-ready standards.
  • Build with Claude: automate control mapping, testing, and monitoring.

Skills

IT audit
security compliance
controls assurance
framework ownership
writing control descriptions
continuous controls monitoring
data-driven testing
communication

Education

Bachelor’s degree in a relevant field

Job description

Anthropic in San Francisco seeks a Security Audit & Controls specialist to own the CCF across control domains, implementing monitoring and evidence collection.

You will work with control owners and GRC partners to ensure evidence is reliable, and drive remediation to closure, while mapping new frameworks and supporting external audits.

This role emphasizes independent work, clear writing, and the ability to influence controls with auditors and engineers.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Continuous Controls Auditor & GRC Lead
Continuous Controls Auditor & GRC Lead

Alex Loftus • New York (NY)

Hybrid
USD 140,000 - 230,000
Security GRC & Controls Auditor
Security GRC & Controls Auditor

Anthropic Limited • San Francisco (CA)

Hybrid
USD 150,000 - 210,000
Equity donation matching
Generous vacation
Parental leave
+2
Security GRC & Controls Auditor with Continuous Monitoring
Security GRC & Controls Auditor with Continuous Monitoring

United States Digital Space LLC • San Francisco (CA)

Hybrid
USD 150,000 - 190,000
GRC Program Manager, Audit & Controls
GRC Program Manager, Audit & Controls

OpenAI • United States

Remote
USD 130,000 - 170,000
GRC Lead: AI Compliance Certifications (SOC 2, ISO 27001)
GRC Lead: AI Compliance Certifications (SOC 2, ISO 27001)

Thinking Machines Lab Inc. • San Francisco (CA), Northern (KY)

Hybrid
USD 225,000 - 350,000
Health, dental, and vision benefits
Unlimited PTO
Paid parental leave
+1
Senior GRC Analyst for Common Controls Framework
Senior GRC Analyst for Common Controls Framework

salesforce.com, inc. • San Francisco (CA)

On-site
USD 117,000 - 177,000
GRC Program Lead: Audit & Controls Architect
GRC Program Lead: Audit & Controls Architect

OpenAI • San Francisco (CA)

On-site
USD 180,000 - 240,000
Senior GRC Analyst — Common Controls Lead
Senior GRC Analyst — Common Controls Lead

Own Company • San Francisco (CA)

On-site
USD 120,000 - 170,000
Health insurance
401(k) matching
Employee stock purchase program
+5
SOX ITGC & Security Controls Lead
SOX ITGC & Security Controls Lead

Anthropic • Washington

Hybrid
USD 410,000 - 510,000
Equity donation matching
Generous vacation & parental leave
Flexible working hours
+1
Security GRC Lead: Compliance-as-Code & Automation
Security GRC Lead: Compliance-as-Code & Automation

Candid Health • United States

On-site
USD 120,000 - 160,000