← Back to job listings
AN
Third Party Risk Analyst (Security GRC)
Anthropic · San Francisco, United States
About The Role
Join Anthropic, a leading frontier AI lab, as a Third Party Risk Analyst. In this role, you will be responsible for managing the risk associated with our vendor and partner relationships. You will oversee the Mission Critical and Highest-Risk vendor portfolios, ensuring that risk assessments and remediation efforts are aligned with business impact and exposure. You will also support vendor incident response and contribute to KPI/KRI reporting. This position offers a comprehensive benefits package, including health insurance, paid parental leave, and retirement plans.
- Assumer la responsabilité de la gestion des portefeuilles de fournisseurs critiques et à haut risque, en veillant à ce que les évaluations de sécurité, de confidentialité et de conformité soient alignées sur l'exposition active des fournisseurs.
- Diriger le processus d'évaluation des risques inhérents, en examinant le classement pré-rempli par l'agent, en évaluant les contrôles et les preuves des fournisseurs, et en déterminant le risque résiduel.
- Contribuer à l'amélioration continue du programme de gestion des risques des tiers, en développant des prompts, en calibrant les tests, en analysant les erreurs et en garantissant la qualité des résultats.
- Experience building or tuning an LLM-backed workflow, agent, or automation in a risk, compliance, or operations context, including tuning prompts and reviewing model output for accuracy
- Experience running third party or vendor risk assessments end to end at a technology company: scoping the engagement, determining inherent risk, reviewing controls and evidence, documenting residual risk, and driving findings to closure
- Working knowledge of business continuity, disaster recovery, and concentration risk concepts, with the ability to apply them to a vendor portfolio
- Ability to assess a vendor across security, privacy, compliance, and operational risk domains, and to recognize which findings you can close yourself and which need a domain specialist
- Track record of driving risk treatment to closure through influence across teams with competing priorities
- Working knowledge of risk fundamentals (inherent and residual risk, control effectiveness, compensating controls, risk acceptance) and the judgment to apply them when the evidence is incomplete or the answer isn't in a framework
- Hands-on time in a procurement or GRC platform with an understanding of how intake, tiering, and assessment routing fit together
- Experience building or operating issue management workflows: logging issues with a clear owner and due date, tracking remediation, and escalating when treatment stalls
- Experience assessing cloud infrastructure, data center, or data-pipeline vendors
- Exposure to exit planning, contract termination provisions, or supplier failover testing
- Experience with vendor financial health or solvency screening (credit models, financial statement review, or tools such as RapidRatings, CreditSafe, or LSEG)
- Experience supporting SOX, SOC 2, or ISO 27001 third party or vendor management controls
- We encourage you to apply even if you do not believe you meet every single qualification
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring