InterviewHack.ai
Empezar gratis
Vacantes / Anthropic

Lead, Security Controls Assurance - SOX

Anthropic · San Francisco, CA | Seattle, WA | New York City, NY | Washington, DClead

En corto

  • ▸Líder técnico en cumplimiento SOX para controles de seguridad de sistemas de tecnología.
  • ▸Diseñas y validas controles de ITGC (acceso lógico, cambios, operaciones, desarrollo) desde el inicio de los sistemas.
  • ▸Eres el enlace clave entre ingeniería, auditoría interna y auditores externos para asegurar evidencia continua y automatizada.

Proficiency in English is required.

Postularme en la empresa ↗Compartir por WhatsApp

En ~1 minuto te damos: quién te entrevista, las preguntas probables con respuestas desde tu CV, y tu CV adaptado a esta vacante. Gratis, sin tarjeta.

🎧¿Llegás a la entrevista? Llevá el copiloto. Nuestra extensión escucha la entrevista en vivo y te muestra anclas de 3-4 palabras desde tu CV y tu preparación — mirás, conectás, hablás. Gratis. Ver la extensión →

¿Qué piden?

  • ✓Experiencia comprobada en SOX 404 y controles ITGC (acceso lógico, gestión de cambios, operaciones, desarrollo).
  • ✓Capacidad para definir requisitos de control desde el diseño inicial de sistemas.
  • ✓Experiencia en colaboración con equipos de ingeniería para implementar controles en plataformas propias.
  • ✓Habilidad para evaluar impacto de cambios en sistemas sobre el alcance SOX.
  • ✓Conocimiento de marcos de control como COSO, COBIT o NIST.
  • ✓Experiencia en automatización de evidencia y monitoreo continuo de controles.

¿No cumplís todo? Es lo normal — tu dossier gratis te dice qué gaps tenés y cómo cubrirlos en la entrevista.

SOX 404ITGCLogical Access ControlsChange Management ControlsComputer Operations ControlsProgram Development ControlsAuditabilitySegregation of DutiesImmutable LoggingEvidence Retention

¿A quién escribirle en Anthropic?

Tu dossier gratis identifica a las personas que te entrevistarían — con su background, qué valoran y cómo escribirles para destacar antes de aplicar.

About Anthropic Anthropic’s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems. About the role Anthropic's Security Governance, Risk, and Compliance (GRC) team is the connective tissue that holds the company accountable to its security and control commitments. We translate regulatory, customer, and voluntary obligations into controls that teams act on, and give leadership a bird's-eye view of how well we're meeting them. We're building toward continuous assurance, to challenge and evidence the performance of controls continuously rather than through periodic audits. As Anthropic prepares for life as a public company, the Sarbanes-Oxley (SOX) control environment over our technology stack is one of the most consequential things this team owns. As part of Security GRC's technical controls assurance function, you will be the voice on what the IT general controls must achieve to support SOX 404 compliance. In partnership with Internal Audit, you will define control requirements and acceptance criteria for the in-scope engineering systems and infrastructure that underpin financial reporting. You will pair with engineering as they design and implement against those requirements, and validate that what ships actually meets the bar before Internal Audit and our external auditors test it. You are the product owner for control design methodology and continuous control monitoring, initially around ITGCs, but extending into other areas of security and compliance to drive visibility where and when we need it. Key responsibilities • Define control requirements and acceptance criteria across the core ITGC domains of logical access, change management, computer operations, and program development for SOX in-scope systems, including home-built platforms where the control has to be designed into the system rather than bolted on. • Set the bar for in-scope systems from day one. As financially significant systems are built, migrated, or replaced, define what the system must provide (auditability, segregation of duties, change control, immutable logging, evidence retention) before go-live, so controls are not retrofitted after the fact. • Pressure-test changes for SOX impact during design. Review major infrastructure, system, and agent framework changes for control impact while decisions are still cheap, and maintain a clear view of which changes alter the SOX scope, key control population, or evidence requirements. • Own second-line control monitoring and evidence readiness. Stand up continuous controls monitoring and automated evidence collection for ITGCs (control testing, walkthrough preparation, population and completeness validation, and mapping to the common controls framework). Materially raise automated evidence coverage and cut audit prep time. • Drive control deficiency remediation with cross functional partners. Track and root-cause ITGC deficiencies surfaced by monitoring, Internal Audit, or external audit; partner with engineering owners on remediation design; and assess whether remediation actually closes the gap before re-testing. • Assess scope changes through a SOX lens. When new products, entities, systems, or integrations come into scope, provide technical and compliance assessment of their impact on control design, evidence requirements, and engineering effort before commitments are made. • Maintain alignment with the broader compliance portfolio. Where SOX ITGCs overlap with SOC 2, ISO 27001/42001, or other frameworks, ensure controls

No apliques sin prepararte

Investigamos quién te entrevista, adaptamos tu CV y te ensayamos en vivo — gratis la primera.

InterviewHack.ai

Preparate para la entrevista exacta: quién te entrevista, tu CV a medida y coach real.

Producto

VacantesRevisar CV (ATS) gratis¿Cómo suena tu inglés?¿Te pagan bien?Reporte de sueldos LATAMCursos gratisBlogCV a medidaPráctica habladaEs gratis

Empleos remotos

ReactPythonFull-StackLATAMArgentinaMéxicoVer todas →

Preparate

Práctica habladaFrontendBackendAI EngineerPor empresaVendete con tu CV

Empresa

Buscás talentoAcerca deContactoPrivacidadTérminos

© 2026 InterviewHack.ai · Tu CV es tuyo. Nunca se usa para entrenar nada. · Un producto de IA-PTY

Vacantes similares activas

User Experience Researcher, Platform

Anthropic · San Francisco, CA | New York City, NY | Seattle, WA

→

Strategic Account Executive, Tech

Anthropic · San Francisco, CA

→

Staff+ Software Engineer, ML Inference Path

Anthropic · San Francisco, CA

→

Staff+ Software Engineer, ML Sampling Path

Anthropic · San Francisco, CA

→