Own and manage Anthropic's highest-risk and mission-critical third-party vendor portfolios within Security GRC. Conduct risk assessments, drive remediation and treatment plans, tune an LLM-based risk agent, and ensure business continuity for critical compute and data vendors.
255k – 270k/yr
Hybrid5+ YOESecurity Engineering
About the role
Key Responsibilities
Own the Mission Critical vendor portfolio: maintain the tiered list, validate it against business impact analysis findings, support exit and failover planning, and drive risk treatment for single points of failure with Procurement, Business Continuity, and business owners.
Manage the Highest-Risk vendor portfolio: keep security, privacy, and compliance assessment depth aligned to active vendor exposure, and drive remediation with the relevant domain teams.
Support vendor incident response: vendor-side impact assessment, business-owner coordination, and post-incident risk treatment.
Run inherent risk assessments through the intake workflow: review agent-prefilled tiering, evaluate vendor controls and evidence across security, privacy, compliance, and operational risk, determine residual risk, and route to domain reviewers where deeper assessment is warranted.
Operate the TPRM issue management workflow: document findings with clear risk statements, assign owners, track treatment to closure.
Tune and maintain the TPRM Risk Agent alongside the team through prompt development, backtest calibration, error analysis, and output QA.
Contribute to KPI/KRI reporting on portfolio coverage and cycle time.
Minimum Qualifications
Experience running third party or vendor risk assessments end to end at a technology company: scoping the engagement, determining inherent risk, reviewing controls and evidence, documenting residual risk, and driving findings to closure.
Working knowledge of risk fundamentals (inherent and residual risk, control effectiveness, compensating controls, risk acceptance) and the judgment to apply them when the evidence is incomplete or the answer isn't in a framework.
Ability to assess a vendor across security, privacy, compliance, and operational risk domains, and to recognize which findings you can close yourself and which need a domain specialist.
Track record of driving risk treatment to closure through influence across teams with competing priorities.
Experience building or tuning an LLM-backed workflow, agent, or automation in a risk, compliance, or operations context, including tuning prompts and reviewing model output for accuracy.
Experience building or operating issue management workflows: logging issues with a clear owner and due date, tracking remediation, and escalating when treatment stalls.
Hands-on time in a procurement or GRC platform with an understanding of how intake, tiering, and assessment routing fit together.
Working knowledge of business continuity, disaster recovery, and concentration risk concepts, with the ability to apply them to a vendor portfolio.
Preferred Qualifications
Experience assessing cloud infrastructure, data center, or data-pipeline vendors.
Experience with vendor financial health or solvency screening (credit models, financial statement review, or tools such as RapidRatings, CreditSafe, or LSEG).
Experience supporting SOX, SOC 2, or ISO 27001 third party or vendor management controls.
Exposure to exit planning, contract termination provisions, or supplier failover testing.
Compensation
Annual Salary: $255,000–$270,000 USD
Skills
third party risk managementvendor risk assessmentGRCrisk fundamentalsissue managementllm tuningPrompt Engineeringbusiness continuityprocurement platformssoxSOC 2ISO 27001
Builds security primitives, platform mitigations, and leads vulnerability remediation for Ramp's financial platform. Partners with engineers for secure-by-design solutions. Requires 5+ years software experience, 2+ years in security/infrastructure.
258k – 355k/yr
Hybrid5+ YOESecurity Engineering
Offensive Security Engineer
PerplexitySan Francisco, CA +1
Offensive Security Engineer conducts red team operations, penetration testing, and AI/ML attack simulations on cloud infrastructure, applications, and pipelines. Requires 5+ years experience in offensive security, expertise in cloud/web/K8s security, and custom tooling in Python/Go.
250k – 350k/yr
Hybrid5+ YOESecurity Engineering
Security Engineer, Application Security
OpenAISan Francisco, CA +2
Identifies and mitigates application security vulnerabilities through code reviews, penetration testing, and security assessments. Collaborates with development teams to integrate secure coding practices and provides guidance on threats and remediation.
Safeguards Enforcement Analyst focused on account takeover and credential abuse. Investigate compromise incidents, design remediation workflows, partner with engineering on detection, enforce AI usage policies, and develop scalable enforcement programs for platform safety.
245k – 285k/yr
HybridSecurity Engineering
Security Engineer, Detection & Response
Scale AINew York, NY +3
Senior Security Engineer focused on building detection systems, incident response automation, and maturing telemetry pipelines across cloud environments. Requires 5+ years in detection engineering or security operations and production-grade coding skills.