Engineering Manager, GRC Platform
Job description
About the role
You will build and lead a new engineering team focused on automating risk and compliance workflows. This role is centered on creating the technical infrastructure required to normalize data across disparate systems and implementing agentic AI workflows to scale our GRC programs effectively. The position demands ownership of end-to-end solution design, ensuring that automated processes align with strict regulatory standards and business objectives. You will be responsible for establishing the architectural foundation that allows compliance operations to run with increased speed and accuracy. The role involves close collaboration with cross-functional stakeholders to translate complex requirements into robust technical implementations. Success in this position will be measured by the stability, scalability, and adoption of the automation platform you create. You will play a critical part in shaping how Anthropic manages and executes its governance, risk, and compliance initiatives globally.
Key facts
What you'll do
Lead the design and implementation of automated GRC architecture and data pipelines to ensure system integrity and reliability.
Aggregate risk and asset information from cloud infrastructure, identity providers, HRIS, and CI/CD tools to create a unified source of truth.
Develop agentic AI workflows using Claude to automate evidence collection, audit responses, and policy interpretation with minimal manual intervention.
Translate regulatory requirements into policy-as-code and automated validation checks to enforce compliance programmatically.
Hire and mentor team members while defining the technical roadmap for compliance automation and driving execution against it.
Partner with Security, IT, and Engineering teams to ensure compliance with SOC 2, ISO, HIPAA, and FedRAMP frameworks and controls.
Implement monitoring and alerting mechanisms to detect anomalies, failures, or deviations in automated compliance processes.
Collaborate with product and legal stakeholders to iterate on compliance workflows and adapt to evolving regulations and standards.
Optimize existing pipelines and infrastructure to improve performance, reduce latency, and lower operational overhead.
Document architectural decisions, processes, and procedures to ensure clarity, maintainability, and knowledge transfer across the team.
Contribute to code reviews and technical discussions to uphold engineering best practices and high standards of quality.
Support incident response and troubleshooting efforts to resolve issues in automated workflows promptly and effectively.
Identify opportunities for process improvement and propose solutions that enhance efficiency and scalability of GRC operations.
Act as a technical leader in scoping, planning, and delivering key initiatives within the compliance automation domain.
Represent the team in cross-company meetings and discussions to ensure alignment between technical capabilities and business needs.
Requirements
- 12+ years of total professional experience with a strong track record of delivering complex technical projects.
- 3 to 4+ years of experience managing technical individual contributors or systems-focused teams in a professional environment.
- 5+ years of experience building automated workflows, data pipelines, or system integrations across distributed systems.
- Proficiency in Python for automation, scripting, and API integration to develop scalable and maintainable solutions.
- Strong understanding of REST APIs, webhooks, and authentication flows including OAuth, API keys, and certificate-based auth.
- Experience with cloud platforms such as AWS, GCP, or Azure and their core services for building resilient architectures.
- Familiarity with Infrastructure as Code tools such as Terraform, CloudFormation, or Ansible for provisioning and managing resources.
- Bachelor's degree or equivalent combination of education and experience that demonstrates relevant knowledge and skills.
- Ability to work independently and collaboratively in a fast-paced, dynamic, and evolving organizational environment.
- Willingness to engage in continuous learning and adapt to new technologies, frameworks, and compliance requirements as they emerge.
- Strong written and verbal communication skills to articulate technical concepts to both technical and non-technical audiences.
- Commitment to maintaining high standards of security, privacy, and regulatory compliance in all aspects of the role.
- Willingness to travel occasionally for team meetings, client discussions, or company events as determined by business needs.
- Availability to work from an office location at least 25% of the time as required for collaboration and oversight.
Nice to have
- Experience with GRC platforms including ServiceNow GRC, Vanta, Drata, OneTrust, or RSA Archer and understanding of their capabilities and limitations.
- Background in designing AI-powered automation or LLM-based tools and integrating them into operational workflows.
- Experience working in high-growth startup environments where agility, ownership, and rapid iteration are valued.
- Familiarity with compliance frameworks such as NIST, ISO 27001, SOC 2, HIPAA, and FedRAMP and their practical application.
- Knowledge of security tooling and processes such as vulnerability management, identity governance, and access control.
- Demonstrated ability to mentor and develop engineers, fostering a culture of learning, inclusivity, and accountability.
- Experience with observability and monitoring tools such as Datadog, New Relic, or similar platforms for system insights.
- Understanding of data modeling and schema design for storing and querying complex relational and hierarchical information.
- Willingness to engage in hands-on technical work, including writing code or debugging issues, to support the team when necessary.
Practical notes
We offer visa sponsorship and retain immigration counsel to assist with the process.
Employees are expected to work from an office at least 25% of the time.
We encourage applications even if you do not meet every listed qualification.
Protect yourself from recruitment scams by only communicating via @anthropic.com email addresses.