仕事内容
<div class="content-intro"><h2><strong>About Anthropic</strong></h2>
<p>Anthropic’s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems.</p></div><h2><strong>About the team</strong></h2>
<p>Anthropic's Security Governance, Risk, and Compliance (GRC) team is the connective tissue that holds the company accountable to its security commitments. We translate regulatory, customer, and voluntary obligations into controls that teams act on, and give leadership a bird's-eye view of how well we're meeting them. We're building toward a fundamentally different kind of GRC: one that directs Claude, with the right humans in the loop, to challenge and evidence the performance of controls continuously rather than through periodic audits.</p>
<p>Within Security GRC, Compliance & Audit Programs runs the integrated audit across our frameworks and maintains the Common Control Framework, the single set of controls that the whole program is built on. This role sits in Audit & Assurance and owns the framework and the assurance view across every control domain.</p>
<h2><strong>About the role</strong></h2>
<p>As part of the Security Audit & Controls team, you will own the CCF across every control domain, from access and change management to logging, encryption, and people controls: which controls we have, what each one says, how each maps to the frameworks and commitments we hold, and whether each one is actually working. You'll work with control owners and GRC Partners to draft and validate control descriptions and activities that describe reality rather than policy intent, build the monitoring that shows operating effectiveness continuously instead of once a year, and drive what monitoring finds to closure with contro