Senior Manager, IT SOX

Anthropic · San Francisco, CA · Finance · listed September 1, 2026

The shape of it

Seniority
Manager
Experience asked
8+ years
Where
Hybrid
Stated pay
$230,000 – $300,000 USD
Requirements listed
9
Length
1,298 words

In the posting’s own words

We are looking for a Senior Manager, IT SOX to join the Internal Audit team at Anthropic. In this role, you will be a hands-on technical contributor and key executor of our IT SOX compliance program, with deep focus on our IT General Controls, IT Application Controls, and system risk assessments.

What it asks for · 9

  • Hands-on IT audit or IT SOX compliance experience, ideally in a fast-paced technology environment
  • Deep working knowledge of ITGCs, ITACs, and IT risk assessment methodologies
  • Experience auditing highly automated DevOps environments (CI/CD pipelines, infrastructure-as-code, automated deployments) and adapting traditional change-management and access controls to them
  • Experience designing, testing, and documenting controls across access management, change management, and computer operations
  • Demonstrated comfort with ambiguity and the ability to operate effectively in a high-pace, rapidly changing environment
  • Ability to effectively guide and direct the work of internal team members and/or co-sourced partners
  • Ability to work independently on complex, ambiguous workstreams while communicating proactively with senior stakeholders
  • Strong project management and organizational skills with close attention to detail
  • Clear, effective communicator — able to work across technical and non-technical audiences

Also a plus

  • 8+ years of hands-on IT audit and SOX compliance experience, including time in a Big 4 or comparable environment
  • Hands-on experience with cloud environments (GCP, AWS, and/or Azure)
  • Experience at a pre-IPO or newly public technology company
  • Track record of scaling an audit or SOX program through periods of rapid growth
  • Familiarity with enterprise systems such as Workday, Salesforce, or GitHub
  • Experience evaluating SDLC controls in modern software development environments
  • CISA, CIA, CISSP, CPA, or equivalent certification
  • Genuine enthusiasm for working in an AI-first environment — applying AI to audit work itself and rethinking assumptions about how controls operate when AI is embedded in the processes being audited

What the job covers

  • Advise on the design of a control environment fit for an AI-first company, including controls over highly automated DevOps pipelines and emerging agentic identity models
  • Partner with Engineering, Security, IT, and DevOps teams to assess the design and implementation of scalable and sustainable controls
  • Assess new system implementations and changes
  • Identify automation and tooling opportunities to improve control efficiency and monitoring, and contribute to the development of continuous monitoring capabilities
  • Assist in scoping and planning for annual SOX IT assessments
  • Execute IT SOX testing across IT General Controls and IT Application Controls, including access management, change management, and computer operations
  • Perform system and process risk assessments to identify control gaps and recommend remediation
  • Own control documentation and ensure audit-ready evidence is current and complete
  • Evaluate IT automated controls and support the shift from manual to automated control reliance
  • Scale the IT SOX program as the company grows — rationalizing scope, standardizing testing approaches, and building repeatable processes that keep pace with new systems and entities
  • Guide and direct the day-to-day work of internal team members and co-sourced partners: setting priorities, reviewing workpapers, and ensuring quality and consistency across the testing program
  • Build strong working relationships with process and control owners across the organization

Tools and skills named

Security & compliance
  • Audit8×
  • Security2×
Ways of working
  • Testing5×
  • Technical writing
Cloud & infra
  • AWS
  • Azure
  • CI/CD
  • GCP
Go to market
  • Salesforce
Operations & finance
  • Project management

Words the posting leans on

  • controls20×
  • sox11×
  • experience7×
  • audit6×
  • automated5×
  • management5×
  • system5×
  • technical5×
  • testing5×
  • assessments4×
  • hands-on4×
  • partner4×
  • program4×
  • risk4×
  • ai-first3×
  • effectively3×

Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.

The posting, your resume, and the gaps between them. One click loads all three.

More open at Anthropic

every open role at Anthropic

How this page was made

An automated read of a public job posting, fetched September 2, 2026 and last changed by Anthropic on September 1, 2026. Every list above is pulled from the posting’s own sentences — nothing rewritten, nothing added, no judgment about the role or the company. Counts and seniority are read off the text by rule, so they can be wrong where the posting is unusual. The original is the only thing that binds. Openings close without warning; check the source before spending an evening on it.