Engineering Manager, GRC Platform

Anthropic · San Francisco, CA | New York City, NY | Seattle, WA · Security · listed November 19, 2025

The shape of it

Seniority
Manager
Experience asked
3–12 years
Where
Not stated
Stated pay
$320,000 – $405,000 USD
Requirements listed
7
Length
1,548 words

In the posting’s own words

We are seeking an Engineering Manager, GRC to join our GRC organization and build the technical foundation for how we scale our risk and compliance programs. In this role, you will lead the team that designs and implements automated workflows, data pipelines, and integrations that transform manual compliance processes into scalable engineering systems.

What it asks for · 7

  • Are a systems thinker first. You understand how complex environments work: how data flows between systems, where integration points exist, what breaks when systems don't talk to each other. You can both design the right architecture and environment for an enterprise-grade internal tool, as well as implement and iterate on that architecture as the organization and priorities evolve.
  • Have a relentless focus on data integration: you understand how to pull data from multiple sources, normalize it, join it meaningfully, and surface insights. You're comfortable reasoning about messy, inconsistent data and designing systems that handle edge cases gracefully.
  • Understand APIs and integration patterns: REST APIs, webhooks, authentication flows, polling vs. push architectures, and can evaluate systems based on how well they expose data and support automation.
  • Can work independently with minimal guidance, taking ownership of complex problems from design through implementation while managing ambiguity inherent in early-stage programs.
  • Have strong analytical and problem-solving skills with attention to detail necessary for compliance work, balanced with pragmatism about risk-based prioritization in fast-paced environments.
  • Familiarity with cloud platforms (AWS, GCP, Azure) and an understanding of how compliance-relevant data can be extracted from their APIs and logging systems.
  • Familiarity with Infrastructure as Code tools (Terraform, CloudFormation, Ansible) and DevSecOps practices including CI/CD pipeline integration and policy-as-code implementations.

Also a plus

  • Have 12+ years of total experience and 3-4+ years of experience managing technical individual contributors or systems-focused teams, with a proven track record of building or scaling small teams (2-5 people) in security, compliance, automation, or operations functions.
  • Have 5+ years of experience designing, building, and scaling automated workflows, data pipelines, or system integrations.
  • Balance strategic thinking with hands-on technical leadership: bring a full-stack mindset and do what it takes to solve problems end-to-end — building pipelines and integrations yourself while the team is small, and going deep on code and design reviews as it scales.
  • Have a strong technical foundation with proficiency in Python (or a similar language) for automation, API integration, and data transformation — you're comfortable writing, reviewing, and shipping production code alongside your team, and expect to stay close to the code as the team grows.
  • Experience designing or implementing AI-powered automation, agentic workflows, or LLM-based tooling in operational contexts.
  • Experience with GRC platforms such as ServiceNow GRC, Vanta, Drata, OneTrust, RSA Archer, or similar tools including configuration, customization, and integration capabilities.
  • Prior experience in high-growth startup environments demonstrating ability to build scalable processes and adapt quickly to changing requirements and priorities

What the job covers

  • Lead the team that establishes foundational GRC processes and architecture. Design and build automated workflows for risk management and compliance, creating scalable systems that enable continuous monitoring as Anthropic grows.
  • Build data pipelines that aggregate risk, control, and asset information from across our technology stack. This means solving hard data integration problems: mapping disparate schemas, handling inconsistent data quality, and creating unified views of compliance posture through dashboards and reporting tools.
  • Inform GRC platform strategy and implementation: in partnership with other programs, plan for and build tooling that meets our compliance requirements.
  • Translate written policies and compliance requirements into policy-as-code—working with Engineering and Security teams to express requirements as enforceable rules, automated checks, and continuous validation rather than static documents.
  • Establish feedback loops between policy and implementation: surface where technical controls diverge from written requirements, identify where policies need to evolve based on infrastructure realities, and ensure that compliance requirements are expressed in terms engineers can act on.
  • Design and deploy agentic AI workflows that extend team capacity, using Claude to serve as a virtual GRC analyst to automate evidence analysis, monitor control effectiveness, draft audit responses, interpret policy documents, and handle other tasks that require reasoning over unstructured information.
  • Design and maintain integrations connecting GRC tooling with cloud infrastructure, identity management systems, HRIS platforms, ticketing systems, version control, and CI/CD pipelines—working with engineers to implement integrations that enable automated evidence collection and continuous compliance validation.
  • Build and lead an AI-forward GRC engineering function as we scale: hiring team members, establishing practices, and defining the technical roadmap for governance and compliance automation at Anthropic.

Tools and skills named

Security & compliance
  • Security3×
  • Audit2×
  • HIPAA
  • Regulatory
  • Risk management
  • SOC 2
Cloud & infra
  • CI/CD2×
  • Ansible
  • AWS
  • Azure
  • GCP
  • Terraform
Data
  • Data pipelines3×
Frameworks
  • REST2×
Product & design
  • Design systems
  • Roadmap
Languages
  • Python
Models & research
  • LLM

Words the posting leans on

  • compliance15×
  • data15×
  • systems15×
  • integration13×
  • design9×
  • grc9×
  • requirements7×
  • automation6×
  • build6×
  • experience6×
  • pipelines6×
  • technical6×
  • workflows6×
  • architecture5×
  • code5×
  • engineering5×

Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.

The posting, your resume, and the gaps between them. One click loads all three.

More open at Anthropic

every open role at Anthropic

How this page was made

An automated read of a public job posting, fetched August 24, 2026 and last changed by Anthropic on August 21, 2026. Every list above is pulled from the posting’s own sentences — nothing rewritten, nothing added, no judgment about the role or the company. Counts and seniority are read off the text by rule, so they can be wrong where the posting is unusual. The original is the only thing that binds. Openings close without warning; check the source before spending an evening on it.