Third Party Risk Analyst, Security GRC na Anthropic

Remoto - San Francisco, CA, United States

Candidatar-se
Ver mais vagas na Anthropic

The Third Party Risk Analyst, Security GRC, will own the top of Anthropic's risk stack, managing Mission Critical and Highest‑Risk vendor portfolios, driving risk treatment, operating the TPRM issue management workflow, and contributing to KPI/KRI reporting. This remote‑friendly role requires deep expertise in vendor risk, security, privacy, compliance, and operational risk, and experience building or tuning LLM‑backed workflows.

Salary

USD 255,000 - 270,000

Requirements

Skills

  • Experience running third party or vendor risk assessments end to end at a technology company
  • Working knowledge of risk fundamentals (inherent and residual risk, control effectiveness, compensating controls, risk acceptance)
  • Ability to assess a vendor across security, privacy, compliance, and operational risk domains
  • Track record of driving risk treatment to closure through influence across teams with competing priorities
  • Experience building or tuning an LLM‑backed workflow, agent, or automation in a risk, compliance, or operations context, including tuning prompts and reviewing model output for accuracy
  • Experience building or operating issue management workflows: logging issues with a clear owner and due date, tracking remediation, and escalating when treatment stalls
  • Hands‑on time in a procurement or GRC platform with an understanding of how intake, tiering, and assessment routing fit together
  • Working knowledge of business continuity, disaster recovery, and concentration risk concepts

Responsibilities

  • Own the Mission Critical vendor portfolio: maintain the tiered list, validate it against business impact analysis findings, support exit and failover planning, and drive risk treatment for single points of failure with Procurement, Business Continuity, and business owners
  • Manage the Highest‑Risk vendor portfolio: keep security, privacy, and compliance assessment depth aligned to active vendor exposure, and drive remediation with the relevant domain teams
  • Support vendor incident response: vendor‑side impact assessment, business‑owner coordination, and post‑incident risk treatment
  • Run inherent risk assessments through the intake workflow: review agent‑prefilled tiering, evaluate vendor controls and evidence across security, privacy, compliance, and operational risk, determine residual risk, and route to domain reviewers where deeper assessment is warranted
  • Operate the TPRM issue management workflow: document findings with clear risk statements, assign owners, track treatment to closure
  • Tune and maintain the TPRM Risk Agent alongside the team through prompt development, backtest calibration, error analysis, and output QA
  • Contribute to KPI/KRI reporting on portfolio coverage and cycle time

Technologies

LLM‑backed workflowautomationGRC platformRisk assessmentRapidRatingsCreditSafeLSEGSOXSOC 2ISO 27001

Compartilhar vaga

Descubra se seu currículo está pronto para esta vaga

Veja como nossa IA pode otimizar seu currículo e aumentar suas chances de conseguir esta posição.