Security Risk Analyst, Risk Engineering

Anthropic · San Francisco, CA | New York City, NY · Security · listed October 5, 2026

The shape of it

Seniority
Not stated
Where
Hybrid
Stated pay
$270,000 – $345,000 USD
Requirements listed
8
Length
1,777 words

In the posting’s own words

The conventional GRC playbook was not built for a company shipping frontier AI. You will help define what replaces it, with a direct line to CISO-level decisions. As a Security Risk Analyst you will take risk questions from leadership and partner teams and drive them to a decision. Sometimes that is a fast, structured qualitative assessment and other times it is a deep FAIR-based quantitative analysis. Either way you bring leadership a clear position, the tradeoffs, and honest uncertainty, and you defend it under challenge. In parallel, you will help turn quantitative risk into a product partner teams can leverage, and define the standards a growing risk function will run on.

What it asks for · 8

  • Have owned security or technology risk analysis end to end, qualitative and quantitative, and can point to a decision your output changed, whether a funding call, a launch call, a remediation sequence, or a documented acceptance
  • Have hands-on FAIR-style quantification experience, including scenario decomposition, calibrated estimation, and Monte Carlo simulation in Python, R, or spreadsheet tooling, briefed to decision makers
  • Thrive in ambiguity. You frame a moving question into something analyzable, pick the depth that fits, and drive to a decision rather than a report
  • Put defensible severity and likelihood on ambiguous problems, state uncertainty honestly, and change your position when the evidence changes
  • Have enough technical security depth to decompose an attack path with security engineers and be credible in the room
  • Can compress a complex risk position into one paragraph for the CISO, make the tradeoff explicit, and defend it under pointed questions
  • Use Claude or other LLMs as daily working tools and review model output critically
  • Are low ego and collaborative, build credibility through the work, and care about AI safety and the role security risk plays in it

Also a plus

  • Have applied FAIR-CAM or another structured approach to control effectiveness and attack path modeling
  • Have built or operated a cyber risk quantification program, or turned quantitative analysis into tooling, templates, or training that others ran
  • Have helped define risk appetite or tolerance thresholds an organization actually used to make decisions
  • Bring a background in security engineering, detection, threat intelligence, actuarial science, or decision science that grounds the numbers in real systems
  • Are familiar with security risks specific to AI systems, such as goal or intent modification, and how they change traditional threat models

What the job covers

  • Enable leadership and partner teams to make risk-informed decisions. Take ambiguous risk questions, drive them to a documented decision, and communicate the quantitative and qualitative tradeoffs clearly
  • Lead quantitative analysis of the company's top security risk scenarios using FAIR, calibrated estimation, and simulation, working with the engineers who own the systems and presenting results in terms leadership can act on
  • Partner with Security Engineering to assess threat scenarios and control effectiveness so security investment is right-sized to actual risk and remediation is sequenced where it buys down the most risk
  • Frame escalations and risk treatment decisions with a clear recommendation, an honest statement of uncertainty, and re-evaluation triggers, and pressure test those decisions with risk owners
  • Shape the analysis and narrative behind leadership risk reviews, and help define risk appetite and the risk metrics the organization should measure and why
  • Use AI and automation to scale risk analysis, and own the calibration and quality review that keep the outputs trustworthy
  • Turn one-off analyses into reusable methods, templates, and training so risk analysis becomes increasingly self service for partner teams, and raise the analytical quality of the risk register

Tools and skills named

Security & compliance
  • Security25×
  • Risk management
Languages
  • Python2×
Models & research
  • LLM2×

Words the posting leans on

  • risk46×
  • security25×
  • decision23×
  • analysis13×
  • quantitative11×
  • leadership8×
  • partner8×
  • define7×
  • questions7×
  • security risk7×
  • change6×
  • drive6×
  • output6×
  • review6×
  • risk analysis6×
  • scenarios6×

Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.

The posting, your resume, and the gaps between them. One click loads all three.

More open at Anthropic

every open role at Anthropic →

How this page was made

An automated read of a public job posting, fetched October 5, 2026 and last changed by Anthropic on October 5, 2026. Every list above is pulled from the posting’s own sentences — nothing rewritten, nothing added, no judgment about the role or the company. Counts and seniority are read off the text by rule, so they can be wrong where the posting is unusual. The original is the only thing that binds. Openings close without warning; check the source before spending an evening on it.