anthropic

Third Party Risk Analyst, Security GRC

Apply Now

At a Glance

Location
Friendly (Travel Required) | San Francisco, California, United States
Work Regime
remote
Posted
2026-07-22T20:14:01-04:00

Key Requirements

Certifications

  • ISO

Domain Knowledge

  • Automation
  • Banking
  • Cloud
  • Education
  • Finance
  • Logistics
  • Regulatory

Requirements

Experience running third party or vendor risk assessments end to end at a technology company: scoping the engagement, determining inherent risk, reviewing controls and evidence, documenting residual risk, and driving findings to closure

Ability to assess a vendor across security, privacy, compliance, and operational risk domains, and to recognize which findings you can close yourself and which need a domain specialist

Experience building or tuning an LLM-backed workflow, agent, or automation in a risk, compliance, or operations context, including tuning prompts and reviewing model output for accuracy

Experience building or operating issue management workflows: logging issues with a clear owner and due date, tracking remediation, and escalating when treatment stalls

Hands-on time in a procurement or GRC platform with an understanding of how intake, tiering, and assessment routing fit together

Experience assessing cloud infrastructure, data center, or data-pipeline vendors

Responsibilities

Anthropic's Third Party Risk Management (TPRM) team sits within Security GRC and is responsible for risk management of our vendor and partner relationships, making risk visible to the people who need to act on it, and driving it down.

We're building the program for what a frontier AI lab actually has at stake: the models, the research IP, the safety commitments, and the infrastructure that keeps Claude available to customers.

The program is designed agent-first, with an AI risk agent handling intake, tiering, and evidence collection so that people spend their time on judgment, remediation, and the vendors that matter most.

You will run the Mission Critical and Highest-Risk vendor portfolios.

On the Mission Critical side that means the compute, data center, and data-pipeline vendors where a tier rating is the start of the conversation rather than the end of it: exit and failover planning, single-point-of-failure analysis and treatment, and financial and solvency screening.

On the Highest-Risk side that means the vendors with the deepest access to our data and systems, where you'll make sure assessment depth matches the exposure and drive remediation on what those assessments surface.