Security Risk & Compliance, Agent Security at Anthropic

Hybrid - San Francisco, CA

Apply
More jobs at Anthropic

Anthropic, a public benefit corporation headquartered in San Francisco, is hiring a security risk and compliance professional to lead the governance, risk, and compliance (GRC) of AI agents. The role involves creating and enforcing policies, defining review criteria, and monitoring agent behavior to ensure compliance with industry standards and regulations. Candidates will collaborate across engineering, research, and security teams to shape policies for agent security, data governance, and risk acceptance, while advocating for best practices in a rapidly evolving AI landscape.

Salary

USD 255,000 - 345,000

Requirements

Skills

  • 8+ years in security governance, risk, and compliance at a technology company
  • Experience owning or supporting efforts to compartmentalize sensitive data, PII, or intellectual property
  • Understanding of identity and access mechanisms that implement or undermine protection boundaries
  • Design of least-privilege access and accountability controls for systems acting on a person's behalf
  • Ability to reason from a threat model to a control and explain tradeoffs to engineers and auditors
  • Defined risk‑based review or approval criteria within engineering workflows that remain effective under high change velocity
  • Clear, precise written communication for both technical and non‑technical audiences
  • Comfortable in ambiguous environments and able to propose standards rather than wait for them
  • Motivation to act as the security and risk authority who educates and influences outcomes
  • Understanding of the security properties of LLM agents (optional)
  • Familiarity with AI governance frameworks alongside traditional security frameworks (optional)
  • Experience adapting controls from regulated or highly sensitive environments to an open, high‑trust engineering culture (optional)
  • Relevant certifications such as CISSP, CISM, CRISC, CISA, CCSP, ISO 27001 or ISO 42001 Lead Implementer/Auditor (optional)

Responsibilities

  • Serve as the security policy partner for AI agent governance, authoring policies and standards for how agents are built, deployed, and operated
  • Define review and approval criteria for when an agent may interact with sensitive or regulated data and which actions require human approval within compliance frameworks
  • Serve as the GRC reviewer within existing engineering approval workflows
  • Define data governance requirements for agents, including least‑privilege access, access reviews, and handling of regulated and sensitive data
  • Monitor agent behavior over time and adapt governance requirements in partnership with cross‑functional security, research, and engineering teams
  • Map agent security and data controls to AI governance frameworks (e.g., ISO 27001, ISO 42001, EU AI Act) and strengthen Anthropic's certification efforts ensuring agent security is auditable
  • Assess and document agent‑related security and compliance risks, driving them to resolution with engineering owners
  • Own the policy for agent‑related risk acceptances and exceptions, including approval authority, duration and re‑review

Technologies

ISO 27001ISO 42001EU AI ActAI governance frameworksLLM agents

See if your resume is ready for this job

See how our AI can optimize your resume and improve your chances for this role.