Impress employers and recruiters.
Choose from hundreds of resume examples.

Impress employers and recruiters.
Choose from hundreds of resume examples.
Tailor your resume to this Supplier Security & Assurance, Security GRC role.
Rezi rewrites your resume against Anthropic's job description. Free.

Tailor your resume to this Supplier Security & Assurance, Security GRC role.
Rezi rewrites your resume against Anthropic's job description. Free.
Don't guess if your resume is good enough.
See how it scores against the Supplier Security & Assurance, Security GRC posting at Anthropic — free, in seconds.

Don't guess if your resume is good enough.
See how it scores against the Supplier Security & Assurance, Security GRC posting at Anthropic — free, in seconds.
About the Role
The Supplier Security & Assurance (SSA) team, within Security GRC, is responsible for assessing supplier security. This involves evaluating vendor security requirements, identifying deviations, and providing clear approval decisions. The program is designed to be agent-first, allowing human focus on judgment, remediation, and critical vendors. As a team member, you will manage supplier security assessments from end-to-end, including evidence review, agent-drafted evaluation verification, risk determination, and driving findings to closure. You will also handle aspects beyond approval, such as contractual terms, secure configurations, continuous monitoring, and reassessments, while contributing to the program's tooling and requirements.
Responsibilities
- Run supplier security assessments: review agent-prefilled outputs, evaluate vendor controls and evidence, determine residual risk, and route to domain reviewers where deeper assessment is warranted.
- Operate supplier issue management and risk treatment: document findings with severity, owner, and due date; drive remediation with vendors and business owners; record risk acceptances; and roll open issues into the risk register.
- Run continuous monitoring after approval: reopen assessments on defined triggers, investigate SaaS configuration, data, and use case drift signals, and queue reassessments when vendor scope changes.
- Improve the program by identifying gaps in coverage, questionnaires, requirements, and tooling, proposing fixes, and advancing roadmap items.
- Tune and maintain the Claude-powered assessment platform, including prompt development, questionnaire and assessment type design, calibration, and output QA.
- Contribute to KPI and KRI reporting on coverage, cycle time, residual risk, open issues, and reassessments due.
Requirements
- Experience running supplier security assessments end-to-end at a technology company, including scoping, inherent risk determination, controls and evidence review, residual risk documentation, and findings closure.
- Working knowledge of risk fundamentals (inherent and residual risk, control effectiveness, compensating controls, risk acceptance) and the judgment to apply them with incomplete evidence.
- Ability to assess vendors across security domains and identify findings manageable independently versus those requiring a security domain specialist.
- Track record of driving risk treatment to closure through influence across teams with competing priorities.
- Experience building or tuning an LLM-backed workflow, agent, or automation in a risk, compliance, or operations context, including prompt tuning and output review.
- Experience building or operating issue management workflows, including logging issues, tracking remediation, and escalating stalled treatment.
- Working technical knowledge of SaaS security configuration (SSO and SCIM, admin scoping, sharing defaults, audit log export).
- Working technical knowledge of standard vendor security contract terms (DPA, incident notification, subprocessors, audit and testing rights).
- Ability to read a SOC 2 report or penetration test and translate it into findings, including identifying control exceptions, mapping user entity controls, and judging evidence limitations.
Skills
- LLM-backed workflow development
- Prompt development
- Questionnaire design
- Assessment type design
- Risk assessment
- Issue management
- SaaS security configuration
- Vendor security contract review
- SOC 2 report analysis
- Penetration test analysis
Location
- San Francisco
Work Type
- Hybrid
Experience Level
- Minimum years of experience required will correlate with the internal job level requirements for the position
Education Level
- Bachelor’s degree or an equivalent combination of education, training, and/or experience
- A field relevant to the role as demonstrated through coursework, training, or professional experience
Salary/Compensations
- $255,000—$270,000 USD
Benefits
- Competitive compensation
- Benefits
- Optional equity donation matching
- Generous vacation
- Parental leave
- Flexible working hours
- Lovely office space
About the Company
- Anthropic's mission is to create reliable, interpretable, and steerable AI systems that are safe and beneficial for users and society.
- The team is a growing group of researchers, engineers, policy experts, and business leaders.
- The company believes that high-impact AI research is big science, working as a single cohesive team on large-scale research efforts.
- Anthropic values impact and advancing long-term goals of steerable, trustworthy AI.
- AI research is viewed as an empirical science with ties to physics, biology, and computer science.
- The company is a collaborative group that hosts frequent research discussions.
- Research directions include GPT-3, Circuit-Based Interpretability, Multimodal Neurons, Scaling Laws, AI & Compute, Concrete Problems in AI Safety, and Learning from Human Preferences.
- Anthropic is a public benefit corporation headquartered in San Francisco.
Equal Opportunity
- We encourage you to apply even if you do not believe you meet every single qualification.
- Research shows that people who identify as being from underrepresented groups are more prone to experiencing imposter syndrome and doubting the strength of their candidacy, so we urge you not to exclude yourself prematurely and to submit an application if you're interested in this work.
- We think AI systems like the ones we're building have enormous social and ethical implications. We think this makes representation even more important, and we strive to include a range of diverse perspectives on our team.
- Anthropic recruiters only contact you from @anthropic.com email addresses.
- Be cautious of emails from other domains. Legitimate Anthropic recruiters will never ask for money, fees, or banking information before your first day.
- If you're ever unsure about a communication, don't click any links—visit anthropic.com/careers directly for confirmed position openings.