
Anthropic · Remote-Friendly (Travel Required) | San Francisco, CA
ABOUT ANTHROPIC Anthropic’s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for ...
Anthropic’s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our
users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and
business leaders working together to build beneficial AI systems.
Anthropic's Third Party Risk Management (TPRM) team sits within Security GRC and is responsible for risk management of our vendor
and partner relationships, making risk visible to the people who need to act on it, and driving it down. We're building the
program for what a frontier AI lab actually has at stake: the models, the research IP, the safety commitments, and the
infrastructure that keeps Claude available to customers. The program is designed agent-first, with an AI risk agent handling
intake, tiering, and evidence collection so that people spend their time on judgment, remediation, and the vendors that matter
most.
This role owns the top of that risk stack. You will run the Mission Critical and Highest-Risk vendor portfolios. On the Mission
Critical side that means the compute, data center, and data-pipeline vendors where a tier rating is the start of the conversation
rather than the end of it: exit and failover planning, single-point-of-failure analysis and treatment, and financial and solvency
screening. On the Highest-Risk side that means the vendors with the deepest access to our data and systems, where you'll make sure
assessment depth matches the exposure and drive remediation on what those assessments surface. You'll also carry the operational
baseline the whole team shares (intake reviews, QA on agent output, escalations, reporting) so the program keeps moving while the
portfolio work is underway.
support exit and failover planning, and drive risk treatment for single points of failure with Procurement, Business
Continuity, and business owners
exposure, and drive remediation with the relevant domain teams
evidence across security, privacy, compliance, and operational risk, determine residual risk, and route to domain reviewers
where deeper assessment is warranted
closure
output QA
determining inherent risk, reviewing controls and evidence, documenting residual risk, and driving findings to closure
acceptance) and the judgment to apply them when the evidence is incomplete or the answer isn't in a framework
you can close yourself and which need a domain specialist
including tuning prompts and reviewing model output for accuracy
remediation, and escalating when treatment stalls
together
a vendor portfolio
RapidRatings, CreditSafe, or LSEG)
The annual compensation range for this role is listed below.
For sales roles, the range provided is the role’s On Target Earnings ("OTE") range, meaning that the range includes both the sales
commissions/sales bonuses target and annual base salary for the role.
Minimum education: Bachelor’s degree or an equivalent combination of education, training, and/or experience
Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience
Minimum years of experience: Years of experience required will correlate with the internal job level requirements for the position
Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some
roles may require more time in our offices.
Visa sponsorship: We do sponsor visas! However, we aren't able to successfully sponsor visas for every role and every candidate.
But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help
with this.
We encourage you to apply even if you do not believe you meet every single qualification. Not all strong candidates will meet
every single qualification as listed. Research shows that people who identify as being from underrepresented groups are more
prone to experiencing imposter syndrome and doubting the strength of their candidacy, so we urge you not to exclude yourself
prematurely and to submit an application if you're interested in this work. We think AI systems like the ones we're building have
enormous social and ethical implications. We think this makes representation even more important, and we strive to include a range
of diverse perspectives on our team.
Your safety matters to us. To protect yourself from potential scams, remember that Anthropic recruiters only contact you
from @anthropic.com email addresses. In some cases, we may partner with vetted recruiting agencies who will identify themselves as
working on behalf of Anthropic. Be cautious of emails from other domains. Legitimate Anthropic recruiters will never ask for
money, fees, or banking information before your first day. If you're ever unsure about a communication, don't click any
links—visit anthropic.com/careers [http://anthropic.com/careers] directly for confirmed position openings.
We believe that the highest-impact AI research will be big science. At Anthropic we work as a single cohesive team on just a few
large-scale research efforts. And we value impact — advancing our long-term goals of steerable, trustworthy AI — rather than work
on smaller and more specific puzzles. We view AI research as an empirical science, which has as much in common with physics and
biology as with traditional efforts in computer science. We're an extremely collaborative group, and we host frequent research
discussions to ensure that we are pursuing the highest-impact work at any given time. As such, we greatly value communication
skills.
The easiest way to understand our research directions is to read our recent research. This research continues many of the
directions our team worked on prior to Anthropic, including: GPT-3, Circuit-Based Interpretability, Multimodal Neurons, Scaling
Laws, AI & Compute, Concrete Problems in AI Safety, and Learning from Human Preferences.
Anthropic is a public benefit corporation headquartered in San Francisco. We offer competitive compensation and benefits, optional
equity donation matching, generous vacation and parental leave, flexible working hours, and a lovely office space in which to
collaborate with colleagues. Guidance on Candidates' AI Usage: Learn about our policy
[https://www.anthropic.com/candidate-ai-guidance] for using AI in our application process.
Third Party Risk Analyst - London, 12 Months FTC Pay.UK maintains and develops the UK retail payment systems and standards that are core to the economy. From Bacs to Faster Payments and cheques, we act as the single operator for UK retail payments, working in the public interest to ensure safe, open, innovative and resilient systems. Pay.UK maintains and develops the UK retail payment systems and standards that keep the economy moving, processing over 11 billion transactions worth more than £10 trillion each year. In this role, you will build practical third party risk experience by working end to end on supplier assurance across systems that millions of people and businesses rely on every day. We are seeking a Third Party Risk Analyst to join our Procurement team on a 12 month fixed term basis, reporting to the Senior Third Party Risk Manager and supporting effective risk oversight across critical supplier relationships. ACCOUNTABILITIES The role incorporates the following key responsibilities. * Support end to end execution of supplier assurance reviews, including criticality assessment, supplier tiering and gap analysis. * Issue, manage and assess Third Party Assurance Questionnaires across key risk domains including cyber security, data protection, operational resilience and business continuity. * Evaluate supplier responses and evidence to assess control design and effectiveness, documenting findings and residual risk. * Produce clear Third Party Assurance Reports, including issues, remediation actions and timelines. * Act as Pay.UK’s operational point of contact with suppliers during assurance activity, including evidence collection and scheduling. * Engage internal subject matter experts to validate evidence, challenge responses and escalate issues where required. * Maintain accurate supplier and risk data within the GRC tool and provide first line support to suppliers. * Monitor the supplier threat landscape using external intelligence and data sources. * Support commercial managers by ensuring identified risks are addressed, tracked and closed. * Prepare regular functional risk reports that summarise supplier assurance results, key risk themes, and remediation progress, and present clear insights to governance forums to support informed decisions. QUALIFICATIONS, SKILLS AND EXPERIENCE To perform well in this role you will demonstrate the following experience and capabilities. * Degree or equivalent experience in a relevant field such as risk management, business, information security, procurement or law. * Understanding of third party risk management and UK regulatory expectations relating to outsourcing and supplier assurance. * Solid analytical skills with experience performing gap analysis and interpreting technical risk information. * Experience working in a controls driven environment with governance, audit and evidence based assessments. * Professional certifications are beneficial but not mandatory, including CTPRP, IRM, CRISC, CISSP, ISO 27001, CIPP/E or CIPS. PAY.UK BEHAVIOURS At Pay.UK, our behaviours are central to who we are and how we operate. They bring our values to life, shape our culture, and guide how we make decisions, collaborate, and respond to challenges across the payments ecosystem. All interview processes will assess the following behaviours: * Listen to Find Win-Wins - Empathy, Listening and Understanding * Influence with Courage - Influence, Courage * Go Horizontal First - Cross Boundary Collaboration * Take Ownership - Self Development * Opportunity Mindset - Initiative * Simplify - Achievement Orientation ---------------------------------------------------------------------------------------------------------------------------------- INCLUSIVITY At Pay.UK, we value diversity and inclusivity. Research has shown that candidates from underrepresented groups may hesitate to apply unless they meet all the requirements listed. We encourage all qualified candidates to apply, regardless of how closely their skills and experience match the requirements. We are committed to supporting accessibility needs and creating a welcoming environment for all employees. Become part of our team and contribute to the creation of an inclusive work environment that values everyone's unique input. ---------------------------------------------------------------------------------------------------------------------------------- WHO WE ARE Pay.UK maintains and develops the UK retail payment systems and standards that are core to the economy being able to function on a day-to-day basis. From Bacs to Faster Payments and cheques – we act as the single operator for all UK retail payments. We put the needs of consumers and businesses at the heart of everything we do, working in the public interest to ensure that the systems the country relies on for its banking transactions are safe, open, innovative and resilient. Our payment systems underpin the services that enable funds to be transferred between people and institutions. In 2024, the UK's retail payment systems processed 11 billion transactions worth over £10 trillion through Bacs Direct Credit, Direct Debit, Faster Payments, and cheques, and our Current Account Switch Service has facilitated over 9 million switches since it’s launch in 2013. Every day, individuals and businesses use the services we provide to get their salaries, pay their bills and make online and mobile banking payments. Our vision for the future is to enable a vibrant economy, with Pay.UK delivering robust payment infrastructure and standards for the benefit of consumers and businesses nationwide. Learn more about life at Pay.UK by hearing what employees have to say, click here to view videos. ---------------------------------------------------------------------------------------------------------------------------------- BENEFITS & ADDITIONAL INFORMATION * 12% Non-contributory pension * Discretionary annual bonus * 30 days annual leave (excluding bank holidays) * Private medical insurance, life assurance, income protection, health cash plan, dental insurance, Bupa medicals etc * Employee assistance programme * Cycle to Work Scheme * Season ticket loan * Annual fitness subsidy of up to £500 per annum * Working from home policy - minimum 40% in the office (eg. 2 days in the office over a 5 day working week) Please note: * Some of our benefits are only available to colleagues after meeting the requirements of the probationary period. * Pay.UK employee benefits are not available to contractors and are only available to permanent and fixed-term employees.
ABOUT LENDABLE Lendable is on a mission to build the world's best technology to help people get credit and save money. We're building one of the world’s leading fintech companies and are off to a strong start: * One of the UK’s newest unicorns with a team of just over 700 people * Among the fastest-growing tech companies in the UK * Profitable since 2017 * Backed by top investors including Balderton Capital and Goldman Sachs * Loved by customers with the best reviews in the market (4.9 across 10,000s of reviews on Trustpilot) So far, we’ve rebuilt the Big Three consumer finance products from scratch: loans, credit cards and car finance. We get money into our customers’ hands in minutes instead of days. We’re growing fast, and there’s a lot more to do: we’re going after the two biggest Western markets (UK and US) where trillions worth of financial products are held by big banks with dated systems and painful processes. JOIN US IF YOU WANT TO 1. Take ownership across a broad remit. You are trusted to make decisions that drive a material impact on the direction and success of Lendable from day 1 2. Work in small teams of exceptional people, who are relentlessly resourceful to solve problems and find smarter solutions than the status quo 3. Build the best technology in-house, using new data sources, machine learning and AI to make machines do the heavy lifting ABOUT THE ROLE We are looking for a proactive Security GRC Analyst to join our Information Security team. You will play a pivotal role in scaling our security posture in a fast-paced, AI driven, cloud-native environment. You will be part of a growing team, where your voice will be heard, and your ability to take ownership and drive initiative will directly shape our security culture and operational resilience. Your approach to GRC starts with the risk, not the checklist. Rather than chasing compliance for its own sake, you will identify and assess the risks first, then collaborate with stakeholders to design pragmatic mitigations. You understand that compliance doesn't drive the business; rather, it is the natural outcome of a mature security posture that actively works for the organisation. WHAT YOU’LL BE DOING * Framework & Regulatory Alignment: Help maintain, improve, and scale our security compliance programmes, ensuring ongoing alignment with standards such as SOC 2, ISO 27001, and PCI-DSS, as well as regulator expectations and UK GDPR. * Risk & Mitigation: Collaborate on identifying security risks across the business - including emerging risks from AI-driven and agentic threats - and support the team in driving practical, risk-first mitigation strategies. * Compliance Automation: Utilise our security compliance platform (e.g., Vanta/Drata) to orchestrate automated evidence collection, reducing manual overhead and moving the company toward a state of continuous audit readiness. * Third-Party Risk Management (TPRM): Conduct vendor and third-party security risk assessments to evaluate the security posture of partners and critical outsourced service providers. * Translating Risk & Governance: Work with the team to bridge the gap between engineering and business governance by turning technical security metrics into clear, risk-based narratives for internal stakeholders and external auditors. * Security Culture & Awareness: Support the delivery and promotion of security awareness initiatives to help drive a strong culture of shared security responsibility across the organisation. * Technical Collaboration: Actively engage in conversations with engineers, developers, and IT teams - understanding their technical language and workflows to help align security controls with engineering realities. * Audit & Assessment Support: Participate in external audits and assessments by gathering evidence, preparing documentation, and helping to ensure a smooth, successful audit cycle. WHAT YOU WILL BRING Essential: * Experience: 5+ years of experience in a related role (ideally within a regulated, cloud-native business or FinTech). * Compliance & Risk Expertise: A strong, foundational understanding of security risk management principles and hands-on experience working with compliance frameworks (e.g. ISO 27001, PCI-DSS, or SOC 2). * Risk-First & Pragmatic Mindset: A natural tendency to start with the "why" (the risk) rather than the checklist. You possess the ability to balance strict financial regulations with the operational agility of a fast-paced FinTech, ensuring security controls protect the business without slowing it down. * Communication & Collaboration: Outstanding communication skills with a proven ability to comfortably converse with technical stakeholders, understand their challenges, and translate them into business risks. * Drive & Initiative: A highly proactive and self-motivated mindset - someone who actively looks for ways to improve our security posture and drive change. Deisrable: * Tooling: Direct, practical experience working with modern security compliance and automation platforms (such as Vanta or Drata). * Programming and automation: Experience with Python or a similar programming/scripting language, and/or using AI to improve productivity through automation. INTERVIEW PROCESS 1. Initial Chat all with a Recruiter 2. 15 minute Cognitive Assessment 3. 30 minute Hiring Manager call 4. 60 minute Technical Interview 5. 60 Culture-Add Interview LIFE AT LENDABLE * Winning team: the opportunity to scale up one of the world’s most successful fintech companies * Flexible working: flexible approach tailored to each role. Hybrid roles require three days in-office weekly; fully remote roles include regular opportunities for in-person connection through socials and off-sites * Socials & connection: opportunities and events to come together, socialise, and get to know each other beyond the office walls * Health coverage: support for your physical and mental wellbeing, including private health cover * Retirement & savings: long-term financial wellbeing through retirement savings plans * Employee referral programme: earn a competitive bonus when you refer successful new team members * Office meals & snacks: enjoy a fully stocked kitchen, plus complimentary lunches prepared by in-house chefs on in-office days at select locations * Sustainable commuting: cycle-to-work and electric vehicle salary sacrifice schemes available in select locations Please note: The availability and details of specific benefits vary by location and role. For more information, please speak to your Talent Partner. Check out our blog!
Senior Security Analyst - GRC (Massy - France) Founded in 2000, Ivalua is a leading global provider of cloud-based procurement solutions. COMPANY OVERVIEW At Ivalua we are a global community of exceptional professionals, who believe that digital transformation revolutionizes supply chain sustainability and resiliency to unlock the power of supplier collaboration. We achieve this through our leading cloud-based spend management platform that empowers hundreds of the world's most admired brands to effectively manage all categories of spend and all suppliers to increase profitability, improve ESG (environmental, social, and corporate governance) performance, lower risk, and improve productivity. Driven by our passions and fueled by our shared ambitions, we empower and challenge each other to create meaningful experiences for our colleagues, customers, partners, and communities. Learn more at www.ivalua.com. Follow us on LinkedIn THE OPPORTUNITY CONTEXT: You will be part of the InfoSec team with a mission to build, maintain, and continuously improve our Information Security program, providing peace of mind and assurance of protection and safety to our customers. Our team is hands-on, with a strong problem-solving mindset, capable of thinking holistically about implementation and providing solutions to address our customers' long-term challenges. We work hard and play hard, enjoying various indoor and outdoor activities organized by the company, allowing you to focus, collaborate, and unleash your creativity. ROLE: We are looking for a Senior Security Analyst to join our InfoSec team. This role will help drive various GRC activities which include supporting prospect and customer security questions, maintaining security policies, supporting security audits and assessments and driving new security certifications/compliance initiatives. WHAT YOU WILL DO WITH US * Lead and support compliance initiatives across global and regional frameworks including SOC 1/SOC 2, ISO 27001, IRAP, PCI-DSS, SecNumCloud, Cyber Essentials Plus (CE+), BSI C5, NIST 800-53 * Evaluate technical controls across the technology stack, including all layers of the TCP/IP model (e.g. network segmentation, firewall rulesets, TLS/SSL configuration, IDS/IPS, access controls, application security, encryption in transit/at rest, cloud security configurations), and translate security requirements into actionable guidance for engineering and infrastructure teams. * Drive and manage customer security audits, security questionnaires, and contract reviews with a primary focus on the EMEA region. Participate in the negotiation and review of French contracts to ensure alignment with security and compliance obligations. * Attend prospect and customer meetings and effectively present Ivalua’s security architecture and control information to them. * Lead or support internal and third party security risk management processes, including risk identification, analysis, scoring, treatment planning, and ongoing monitoring. * Support continuous compliance monitoring activities using manual and automation and GRC tooling to maintain control effectiveness, generate evidence, and ensure audit readiness. * Own execution and coordination of key security and availability controls such as Business Impact Analysis (BIA), Disaster Recovery testing, security incident response exercises, access reviews, etc. YOUR PROFILE If you have the below experience and strengths this role could be for you: Skills and Experience: * At least 4 years of experience as Security Analyst GRC * Strong working knowledge of security, risk, and compliance frameworks (e.g. NIST CSF & 800-53, ISO 27001, SOC, HITRUST, HIPAA, PCI-DSS, GDPR) * Direct experience managing audits, self-assessments, or risk assessments against one or more InfoSec frameworks listed above * Experience performing or supporting security risk management processes (risk assessments, risk registers, business impact analysis) * Familiarity with continuous compliance and monitoring platforms * Good understanding of cloud platforms (Azure, AWS, GCP) and ability to discuss security architecture and control implementation with technical teams * Knowledge and experience working with IT and security personnel as well as security concepts across all layers of technology (network, infrastructure, web applications, cloud environments) * Knowledge of risk and security industry literature and knowledge bases (e.g. OWASP, MITRE ATT&CK, NIST 800-39) * Relevant audit and/or Information Security certifications (e.g. CISSP, CISA, CISM, Azure Cloud Security) are desired * Prior experience at a Big 4 firm or in a security/compliance function in a cloud/SaaS environment is a plus Soft Skills: * Excellent interpersonal, communication, and organizational skills. Ability to communicate efficiently and professionally in both French and English, including in contractual, regulatory, and technical contexts * Demonstrated ability to work across geographically distributed teams and with external vendors, auditors, or regulators. * Strong organizational skills and attention to detail; able to manage multiple competing priorities in a fast-paced environment * High degree of initiative, self-motivation, and ability to work independently with limited supervision WHAT HAPPENS NEXT If your application fits this specific position’s needs, our skilled Talent team will reach out to schedule an initial screening call. Get one step closer to achieving your goals – apply today! Our Talent team will guide you through every step of the interview process - from preparation to completion. They're here to support you! Our recruitment process is designed to assess your competencies through a series of personalized interviews with internal stakeholders relevant to the role. Interviews will be conducted virtually via video or on-site with face-to-face meetings. LIFE AT IVALUA * Hybrid working model (3 days in the office per week) * We're a team dedicated to pushing the boundaries of product innovation and technology * Sustainable Growth, Privately Held * A stable and cash-flow positive Company since 10 years * Snacks and weekly lunches in the office * Feel empowered to pursue your goals with improved team collaboration and increased creativity/productivity * Unlock and unleash your full professional potential with our exceptional training and career development program * Join a dynamic and international team of top-notch professionals who are experts in their respective fields * Collaborate with like-minded individuals who are deeply passionate and highly motivated about their work * Experience a truly diverse and inclusive work environment where your unique contributions are highly valued * Regular social events, competitive outings, team running events, and musical activities * Comparably recognized Ivalua for the following (https://www.comparably.com/companies/ivalua): Powered by People - Powered by You! United by our values we embrace diversity and equity in the broadest possible sense to create an inclusive workplace. To help our customers make supply chains more efficient, sustainable and resilient, we rely on a global team with a variety of backgrounds, skills and views. We believe in equal opportunity and in diversity as a driver of innovation that cultivates a spirit of inclusiveness, creates a productive and fun place to work, and provides fulfilling career opportunities for all Ivaluans. https://www.linkedin.com/company/ivalua/about/ Experience life at Ivalua - check out our captivating video! Gain insight into our unique company culture and get a glimpse of what it's like to work with us. #LI-MV1 #LI-HYBRID