Lead, Security Controls Assurance - SOX
Anthropic · San Francisco, CA | Seattle, WA | New York City, NY | Washington, DC · Security · listed September 8, 2026
The shape of it
Seniority
Senior
Where
Not stated
Stated pay
$410,000 – $510,000 USD
Requirements listed
10
Length
2,106 words
In the posting’s own words
As Anthropic prepares for life as a public company, the Sarbanes-Oxley (SOX) control environment over our technology stack is one of the most consequential things this team owns. As part of Security GRC's technical controls assurance function, you will be the voice on what the IT general controls must achieve to support SOX 404 compliance. In partnership with Internal Audit, you will define control requirements and acceptance criteria for the in-scope engineering systems and infrastructure that underpin financial reporting. You will pair with engineering as they design and implement against those requirements, and validate that what ships actually meets the bar before Internal Audit and our external auditors test it. You are the product owner for control design methodology and continuous control monitoring, initially around ITGCs, but extending into other areas of security and compliance to drive visibility where and when we need it.
What it asks for · 10
- Thrive at the pace of a hypergrowth company. You're comfortable making calls with incomplete information and reprioritizing as scope shifts.
- Have led or been a senior contributor to an ITGC program through SOX 404 readiness and/or at a public company, with a working command of PCAOB AS 2201, COSO 2013, and how external auditors scope, test, and evaluate technology controls and deficiencies.
- Have genuine engineering fluency, possibly from an earlier engineering career: you can read code and Terraform, follow a CI/CD pipeline end to end, and challenge a design on its technical merits.
- Have programming skills in Python or at least one systems language such as Go, Rust, or C/C++.
- Have deep familiarity with developer platform, release engineering, cloud infrastructure, or ERP/financial systems control domains.
- Understand the role of the second line: you can advise and challenge engineering without taking ownership of their controls, and you know where the line sits between your monitoring and Internal Audit's independent testing.
- Are a strong collaborator and communicator across Finance, Engineering, Internal Audit, and external auditors.
- Use Claude and other LLMs as daily working tools, and have grounded, specific views on which SOX assurance workflows AI can run today and which it can't yet.
- Translate SOX and framework language into acceptance criteria engineers can build against, and translate engineering reality back into assurance language auditors and leadership can rely on.
- Default to getting the requirement designed into the system rather than papering over the gap with procedure.
Also a plus
- A combination of audit or advisory experience (Big 4 or equivalent, ideally IT audit) with in-house experience at an AI-forward tech company, in either order.
- Taken a company through a first-year SOX 404(a) and 404(b) assessment, including a first external ITGC audit.
- Defined or assessed controls over home-built financially significant systems, usage-based billing, or revenue metering pipelines.
- Defined or assessed controls for AI/ML systems or agents acting in production environments.
- Stood up continuous controls monitoring or automated evidence programs.
- Experience with SOC 1 reliance, service organization control mapping, and complementary user entity controls.
- CISSP, CISA, CPA, or equivalent certification.
What the job covers
- Define control requirements and acceptance criteria across the core ITGC domains of logical access, change management, computer operations, and program development for SOX in-scope systems, including home-built platforms where the control has to be designed into the system rather than bolted on.
- Set the bar for in-scope systems from day one. As financially significant systems are built, migrated, or replaced, define what the system must provide (auditability, segregation of duties, change control, immutable logging, evidence retention) before go-live, so controls are not retrofitted after the fact.
- Pressure-test changes for SOX impact during design. Review major infrastructure, system, and agent framework changes for control impact while decisions are still cheap, and maintain a clear view of which changes alter the SOX scope, key control population, or evidence requirements.
- Own second-line control monitoring and evidence readiness. Stand up continuous controls monitoring and automated evidence collection for ITGCs (control testing, walkthrough preparation, population and completeness validation, and mapping to the common controls framework). Materially raise automated evidence coverage and cut audit prep time.
- Drive control deficiency remediation with cross functional partners. Track and root-cause ITGC deficiencies surfaced by monitoring, Internal Audit, or external audit; partner with engineering owners on remediation design; and assess whether remediation actually closes the gap before re-testing.
- Assess scope changes through a SOX lens. When new products, entities, systems, or integrations come into scope, provide technical and compliance assessment of their impact on control design, evidence requirements, and engineering effort before commitments are made.
- Maintain alignment with the broader compliance portfolio. Where SOX ITGCs overlap with SOC 2, ISO 27001/42001, or other frameworks, ensure controls are designed once and evidenced once, and that changes made for one framework do not silently break another.
Tools and skills named
Security & compliance
- Audit18×
- Security4×
- SOC 22×
- Regulatory
Languages
- C++2×
- Go2×
- Python2×
- Rust2×
Ways of working
- Testing6×
- Cross-functional2×
Cloud & infra
- CI/CD2×
- Terraform2×
Models & research
- LLM2×
- Machine learning2×
Words the posting leans on
- control51×
- systems25×
- sox20×
- audit19×
- engineering18×
- evidence15×
- changes14×
- itgc13×
- monitoring11×
- design10×
- framework10×
- requirements10×
- scope10×
- external9×
- internal audit8×
- compliance7×
Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.
The posting, your resume, and the gaps between them. One click loads all three.
More open at Anthropic
- Account Executive, AI NativeNew York City, NY; San Francisco, CA | New York City, NY
- Account Executive - DNBSingapore
- Account Executive - Public Sector (ASEAN)Singapore
- Account Executive, StartupsSan Francisco, CA | New York City, NY
- Account Executive, StartupsDublin, IE
- Accounting, Revenue Internal ControlsSan Francisco, CA | Seattle, WA