Security Risk & Compliance, Agent Security
Anthropic · San Francisco, CA | New York City, NY · Security · listed October 5, 2026
The shape of it
Seniority
Not stated
Where
Hybrid
Stated pay
$255,000 – $345,000 USD
Requirements listed
9
Length
1,184 words
In the posting’s own words
Done everything on this list before. Very few people have governed AI agents at scale — we care more about how you reason about access, accountability, and blast radius than about a prior title.
What it asks for · 9
- Have 8+ years in security governance, risk, and compliance, including ownership of security policies and control standards at a technology company
- Have owned or meaningfully supported efforts to compartmentalize sensitive data, PII, or intellectual property, and understand how identity and access mechanisms implement or undermine protection boundaries
- Think about non-human identities as a distinct risk and control category, and can design least-privilege access and accountability controls for systems acting on a person's behalf
- Can reason from a threat model to a control and explain the tradeoff to both an engineer and an auditor
- Have defined risk-based review or approval criteria within engineering workflows and kept them effective under high change velocity
- Deliver clear, precise written work for both technical and non-technical audiences
- Thrive in ambiguous environments with no settled industry playbook, where you're expected to propose the standard rather than wait for one
- Are energized by being the security and risk authority who educates and influences outcomes rather than only advises
- Done everything on this list before. Very few people have governed AI agents at scale — we care more about how you reason about access, accountability, and blast radius than about a prior title.
Also a plus
- Understand the security properties of LLM agents, whether from an AI, developer-platform, or agent-tooling company, or through comparable experience
- Bring familiarity with AI governance frameworks alongside traditional security frameworks
- Have adapted controls from regulated or highly sensitive environments to an open, high-trust engineering culture
- Possess relevant certifications (CISSP, CISM, CRISC, CISA, CCSP, ISO 27001 or ISO 42001 Lead Implementer/Auditor)
What the job covers
- Serve as the security policy partner for AI agent governance, authoring the policies and standards for how agents are built, deployed, operated
- Define review and approval criteria when an agent may interact with sensitive or regulated data, and which actions require human approval as it relates to compliance frameworks
- Serve as the GRC reviewer within existing engineering approval workflows
- Define data governance requirements for agents, including least-privilege access, access reviews, and handling of regulated and sensitive data
- Monitor agent behavior over time and adapt governance requirements in partnership with cross-functional security, research and engineering teams
- Map agent security and data controls to AI governance frameworks (e.g., ISO 27001, ISO 42001, EU AI Act), strengthening Anthropic's certification efforts ensuring agent security is auditable
- Assess and document agent-related security and compliance risks, driving them to resolution with engineering owners
- Own the policy for agent-related risk acceptances and exceptions, including approval authority, duration and re-review
Tools and skills named
Security & compliance
- Security12×
- Regulatory
Models & research
- LLM
Ways of working
- Cross-functional
Words the posting leans on
- security12×
- agent10×
- controls8×
- governance7×
- access6×
- risk6×
- approval5×
- data5×
- engineering5×
- compliance4×
- frameworks4×
- iso4×
- sensitive4×
- grc3×
- rather3×
- reason3×
Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.
The posting, your resume, and the gaps between them. One click loads all three.
More open at Anthropic
- Account Executive, AI NativeNew York City, NY; San Francisco, CA | New York City, NY
- Account Executive - DNBSingapore
- Account Executive - Public Sector (ASEAN)Singapore
- Account Executive, StartupsDublin, IE
- Account Executive, StartupsSan Francisco, CA | New York City, NY
- AI Deployment Specialist, Beneficial DeploymentsSan Francisco, CA | New York City, NY