anthropic
Third Party Risk Analyst, Security GRC
At a Glance
- Location
- Friendly (Travel Required) | San Francisco, California, United States
- Work Regime
- remote
- Posted
- 2026-07-22T20:14:01-04:00
Key Requirements
Certifications
- ISO
Domain Knowledge
- Automation
- Banking
- Cloud
- Education
- Finance
- Logistics
- Regulatory
Requirements
Experience running third party or vendor risk assessments end to end at a technology company: scoping the engagement, determining inherent risk, reviewing controls and evidence, documenting residual risk, and driving findings to closure
Ability to assess a vendor across security, privacy, compliance, and operational risk domains, and to recognize which findings you can close yourself and which need a domain specialist
Experience building or tuning an LLM-backed workflow, agent, or automation in a risk, compliance, or operations context, including tuning prompts and reviewing model output for accuracy
Experience building or operating issue management workflows: logging issues with a clear owner and due date, tracking remediation, and escalating when treatment stalls
Hands-on time in a procurement or GRC platform with an understanding of how intake, tiering, and assessment routing fit together
Experience assessing cloud infrastructure, data center, or data-pipeline vendors
Responsibilities
Anthropic's Third Party Risk Management (TPRM) team sits within Security GRC and is responsible for risk management of our vendor and partner relationships, making risk visible to the people who need to act on it, and driving it down.
We're building the program for what a frontier AI lab actually has at stake: the models, the research IP, the safety commitments, and the infrastructure that keeps Claude available to customers.
The program is designed agent-first, with an AI risk agent handling intake, tiering, and evidence collection so that people spend their time on judgment, remediation, and the vendors that matter most.
You will run the Mission Critical and Highest-Risk vendor portfolios.
On the Mission Critical side that means the compute, data center, and data-pipeline vendors where a tier rating is the start of the conversation rather than the end of it: exit and failover planning, single-point-of-failure analysis and treatment, and financial and solvency screening.
On the Highest-Risk side that means the vendors with the deepest access to our data and systems, where you'll make sure assessment depth matches the exposure and drive remediation on what those assessments surface.