About the role
Anthropic is building safe and reliable AI systems that are beneficial for users and society. The company brings together researchers, engineers, policy experts, and business leaders focused on creating AI that is interpretable and steerable. As security risk and compliance continue to matter more in AI development, Anthropic is investing in governance structures that can keep pace with rapid innovation.
Anthropic's Security Governance, Risk, and Compliance team connects the company's security commitments to the teams that implement them. You would help shape how the organization governs AI agents—systems that act autonomously on behalf of users. This role sits at the intersection of policy, engineering, and regulatory compliance, where you would define standards for agent behavior, data access, and risk acceptance.
What you'll do
- Author security policies and standards that govern how AI agents are built, deployed, and operated across the company
- Define criteria for when agents can access sensitive or regulated data, and determine which agent actions require human approval under compliance frameworks
- Establish data governance requirements for agents, including least-privilege access controls, periodic access reviews, and handling procedures for regulated and sensitive information
- Work within engineering approval workflows as the GRC reviewer, ensuring controls are integrated into deployment decisions
- Monitor agent behavior over time and refine governance requirements in partnership with security, research, and engineering teams
- Map agent controls to established frameworks like ISO 27001, ISO 42001, and the EU AI Act to strengthen Anthropic's compliance certifications
- Assess agent-related security and compliance risks, document findings, and drive resolution with engineering owners
- Own the approval process for agent-related risk acceptances and exceptions, setting duration and re-review requirements
What you'll bring
- At least eight years of experience in security governance, risk, and compliance, including ownership of security policies and control standards at a technology company
- Direct experience compartmentalizing sensitive data, PII, or intellectual property, with deep understanding of how identity and access mechanisms protect or weaken data boundaries
- Ability to think about non-human identities as a distinct risk category and design least-privilege and accountability controls for systems acting on behalf of people
- Capability to reason from threat models to controls and communicate tradeoffs clearly to both engineers and auditors
- Experience defining risk-based review criteria within engineering workflows and maintaining their effectiveness as systems evolve rapidly
- Clear, precise written communication for technical and non-technical audiences
- Comfort operating in ambiguous environments where industry standards are still emerging and you help establish them
- Drive to be a security authority who educates and influences engineering outcomes, not just advises
Nice to have
- Familiarity with LLM agent security from AI labs, developer platforms, or agent tooling companies
- Knowledge of AI governance frameworks alongside traditional security frameworks
- Experience adapting controls from regulated or highly sensitive environments to open, high-trust engineering cultures
- Professional certifications such as CISSP, CISM, CRISC, CISA, CCSP, or ISO 27001/42001 Lead Implementer or Auditor credentials
What they offer
- Annual compensation of 255,000 to 345,000 USD
- Visa sponsorship available; Anthropic retains an immigration lawyer to support candidates who receive offers
- Hybrid work arrangement with expectation of in-office presence at least 25% of the time at San Francisco or New York City offices
- Bachelor's degree or equivalent combination of education, training, and professional experience required
Pay, location & hours
Salary not listed. Based in San Francisco, CA, New York City, NY.
About Anthropic
39 open roles in this building · Company page → · See it on the map