Anthropic is seeking a Lead for Security Controls Assurance focused on SOX compliance. The role is part of the Security Governance, Risk, and Compliance team and involves defining IT general control requirements, monitoring continuous assurance, and collaborating with engineering, internal audit, and external auditors to ensure SOX 404 readiness across multiple locations in the United States.
Lead, Security Controls Assurance - SOX na Anthropic
Presencial - San Francisco, CA; Seattle, WA; New York City, NY; Washington, DC
Ver mais vagas na AnthropicRequirements
Skills
- Thriving in a hypergrowth environment and making decisions with incomplete information
- Lead or senior contributor to an ITGC program through SOX 404 readiness at a public company, with knowledge of PCAOB AS 2201, COSO 2013
- Engineering fluency: reading code and Terraform, following a CI/CD pipeline end‑to‑end
- Programming skills in Python or one of Go, Rust, or C/C++
- Deep familiarity with developer platform, release engineering, cloud infrastructure, or ERP/financial systems control domains
- Understanding of the second line: advising and challenging engineering without owning controls
- Strong collaboration and communication across Finance, Engineering, Internal Audit, and external auditors
- Daily use of Claude and other LLMs, with clear views on what SOX assurance workflows AI can and cannot perform
- Translating SOX and framework language into acceptance criteria for engineers and converting engineering reality back into assurance language
- Designing requirements into the system rather than covering gaps with procedures
- Audit or advisory experience (Big 4 or equivalent, ideally IT audit) combined with in‑house experience at an AI‑forward tech company
- Experience taking a company through first‑year SOX 404(a) and 404(b) assessments, including an external ITGC audit
- Defined or assessed controls over home‑built financially significant systems, usage‑based billing, or revenue metering pipelines
- Defined or assessed controls for AI/ML systems or agents in production
- Stood up continuous controls monitoring or automated evidence programs
- Experience with SOC 1 reliance, service organization control mapping, and complementary user entity controls
- Certifications such as CISSP, CISA
Responsibilities
- Define control requirements and acceptance criteria across core ITGC domains of logical access, change management, computer operations, and program development for SOX in‑scope systems
- Set the bar for in‑scope systems from day one, defining auditability, segregation of duties, change control, immutable logging, and evidence retention before go‑live
- Pressure‑test changes for SOX impact during design and maintain a clear view of scope changes, key control populations, and evidence requirements
- Own second‑line control monitoring and evidence readiness by standing up continuous controls monitoring and automated evidence collection for ITGCs
- Drive control deficiency remediation with cross‑functional partners, tracking and root‑causing ITGC deficiencies and assessing remediation effectiveness
- Assess scope changes through a SOX lens for new products, entities, systems, or integrations before commitments are made
- Maintain alignment with the broader compliance portfolio, ensuring controls designed once and evidenced once across frameworks such as SOC 2 and ISO 27001/42001
Technologies
TerraformCI/CD pipelinePythonGoRustC/C++ClaudeAI/ML systemsCloud infrastructure
Descubra se seu currículo está pronto para esta vaga
Veja como nossa IA pode otimizar seu currículo e aumentar suas chances de conseguir esta posição.