Lead, Security Controls Assurance - SOX

EngineersOfAI

San Francisco, Northern (CA, KY)

Hybrid

USD 180,000 - 240,000

Full time

12 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Anthropic is seeking a Security GRC leader to own the IT general controls (ITGC) program and continuous control monitoring in a SOX 404 readiness context. You will partner with Internal Audit and engineering to define requirements, drive evidence collection, and remediate deficiencies.

As the role grows, you will expand control coverage to other security/compliance areas, ensuring auditability and alignment across frameworks while supporting life as a public company.

Qualifications

  • Experience leading ITGC programs for SOX 404 readiness, ideally at a public company.
  • Strong understanding of external auditor scope, testing, and deficiency remediation.

Responsibilities

  • Define control requirements and acceptance criteria for ITGC domains (access, change, ops, dev) for SOX-in-scope systems.
  • Set go-live control expectations (auditability, duties segregation, logging, evidence retention).
  • Review infrastructure changes for SOX impact and map to control population.
  • Operate second-line control monitoring and automated evidence collection for ITGCs.
  • Drive remediation with cross-functional partners and verify closure before re-testing.
  • Assess scope changes through a SOX lens and ensure alignment with other frameworks.

Skills

SOX compliance
IT controls
GRC program management
Audit readiness
Regulatory reporting

Education

Bachelor's degree in IT/CS or Accounting

Tools

PCAOB AS 2201
COSO 2013
SOC 2
ISO 27001/42001

Job description

About Anthropic

Anthropic’s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems.

About the role

Anthropic's Security Governance, Risk, and Compliance (GRC) team is the connective tissue that holds the company accountable to its security and control commitments. We translate regulatory, customer, and voluntary obligations into controls that teams act on, and give leadership a bird's-eye view of how well we're meeting them. We're building toward continuous assurance, to challenge and evidence the performance of controls continuously rather than through periodic audits.

As Anthropic prepares for life as a public company, the Sarbanes-Oxley (SOX) control environment over our technology stack is one of the most consequential things this team owns. As part of Security GRC's technical controls assurance function, you will be the voice on what the IT general controls must achieve to support SOX 404 compliance. In partnership with Internal Audit, you will define control requirements and acceptance criteria for the in-scope engineering systems and infrastructure that underpin financial reporting. You will pair with engineering as they design and implement against those requirements, and validate that what ships actually meets the bar before Internal Audit and our external auditors test it. You are the product owner for control design methodology and continuous control monitoring, initially around ITGCs, but extending into other areas of security and compliance to drive visibility where and when we need it.

Key responsibilities
  • Define control requirements and acceptance criteria across the core ITGC domains of logical access, change management, computer operations, and program development for SOX in-scope systems, including home-built platforms where the control has to be designed into the system rather than bolted on.

  • Set the bar for in-scope systems from day one. As financially significant systems are built, migrated, or replaced, define what the system must provide (auditability, segregation of duties, change control, immutable logging, evidence retention) before go-live, so controls are not retrofitted after the fact.

  • Pressure-test changes for SOX impact during design. Review major infrastructure, system, and agent framework changes for control impact while decisions are still cheap, and maintain a clear view of which changes alter the SOX scope, key control population, or evidence requirements.

  • Own second-line control monitoring and evidence readiness. Stand up continuous controls monitoring and automated evidence collection for ITGCs (control testing, walkthrough preparation, population and completeness validation, and mapping to the common controls framework). Materially raise automated evidence coverage and cut audit prep time.

  • Drive control deficiency remediation with cross functional partners. Track and root-cause ITGC deficiencies surfaced by monitoring, Internal Audit, or external audit; partner with engineering owners on remediation design; and assess whether remediation actually closes the gap before re-testing.

  • Assess scope changes through a SOX lens. When new products, entities, systems, or integrations come into scope, provide technical and compliance assessment of their impact on control design, evidence requirements, and engineering effort before commitments are made.

  • Maintain alignment with the broader compliance portfolio. Where SOX ITGCs overlap with SOC 2, ISO 27001/42001, or other frameworks, ensure controls are designed once and evidenced once, and that changes made for one framework do not silently break another.

Minimum qualifications
  • Thrive at the pace of a hypergrowth company. You're comfortable making calls with incomplete information and reprioritizing as scope shifts.

  • Have led or been a senior contributor to an ITGC program through SOX 404 readiness and/or at a public company, with a working command of PCAOB AS 2201, COSO 2013, and how external auditors scope, test, and evaluate technology controls and deficiencie

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Manager, IT SOX
Senior Manager, IT SOX

EngineersOfAI • San Francisco (CA), Northern (KY)

Hybrid
USD 180,000 - 240,000
SOX ITGC & Security Controls Lead
SOX ITGC & Security Controls Lead

Anthropic • Washington

Hybrid
USD 410,000 - 510,000
Equity donation matching
Generous vacation & parental leave
Flexible working hours
+1
SOX ITGC Controls Assurance Lead
SOX ITGC Controls Assurance Lead

Halbarad Risk Intelligence, Inc. • Northern (KY), New York (NY)

Hybrid
USD 306,000 - 510,000
SOX ITGC Controls Lead for Secure Engineering
SOX ITGC Controls Lead for Secure Engineering

Anthropic • Seattle (WA)

Hybrid
USD 410,000 - 510,000
Senior IT SOX Compliance Lead
Senior IT SOX Compliance Lead

EngineersOfAI • San Francisco (CA), Northern (KY)

Hybrid
USD 180,000 - 240,000
SOX ITGC Control Lead: Assurance & Monitoring
SOX ITGC Control Lead: Assurance & Monitoring

EngineersOfAI • San Francisco (CA), Northern (KY)

Hybrid
USD 180,000 - 240,000
Lead, Security Controls Assurance - SOX
Lead, Security Controls Assurance - SOX

Anthropic • Washington

Hybrid
USD 410,000 - 510,000
Equity donation matching
Generous vacation & parental leave
Flexible working hours
+1
Senior ITGC Controls Lead (SOX)
Senior ITGC Controls Lead (SOX)

Anthropic • New York (NY)

Hybrid
USD 410,000 - 510,000
Lead, Security Controls Assurance - SOX
Lead, Security Controls Assurance - SOX

Anthropic • Seattle (WA)

Hybrid
USD 410,000 - 510,000
Lead, Security Controls Assurance - SOX
Lead, Security Controls Assurance - SOX

Anthropic • New York (NY)

Hybrid
USD 410,000 - 510,000