FREE ACCESS
5,000–10,000 jobs/day
See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Third Party Risk Analyst, Security GRC
AnthropicThird Party Risk Analyst managing vendor portfolios for AI systems at Anthropic. Ensuring risk assessment and remediation for critical vendor relationships.
Posted 7/23/2026full-timeSan Francisco • California • 🇺🇸 United StatesMid-LevelSenior💰 $255,000 - $270,000 per yearWebsite
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in managing vendor risk assessments, including evaluating security, privacy, compliance, and operational risks. Proficient in driving risk treatment to closure and operating issue management workflows within procurement or GRC platforms.
Highest-signal resume keywords
Vendor Risk AssessmentRisk Treatment ManagementGRC Platform ExperienceIssue Management WorkflowBusiness Continuity Knowledge
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Risk FundamentalsControl EffectivenessResidual Risk DocumentationLLM-Backed Workflow TuningVendor Impact Assessment
Soft Skills
Influence Across TeamsCross-Functional Coordination
Tools & Technologies
TPRM Risk AgentProcurement PlatformGRC Platform
Industry Keywords
Third Party Risk ManagementCompliance AssessmentDisaster RecoveryConcentration Risk
About the role
Key responsibilities & impact- Own the Mission Critical vendor portfolio: maintain the tiered list, validate it against business impact analysis findings, support exit and failover planning, and drive risk treatment for single points of failure with Procurement, Business Continuity, and business owners
- Manage the Highest-Risk vendor portfolio: keep security, privacy, and compliance assessment depth aligned to active vendor exposure, and drive remediation with the relevant domain teams
- Support vendor incident response: vendor-side impact assessment, business-owner coordination, and post-incident risk treatment
- Run inherent risk assessments through the intake workflow: review agent-prefilled tiering, evaluate vendor controls and evidence across security, privacy, compliance, and operational risk, determine residual risk, and route to domain reviewers where deeper assessment is warranted
- Operate the TPRM issue management workflow: document findings with clear risk statements, assign owners, track treatment to closure
- Tune and maintain the TPRM Risk Agent alongside the team through prompt development, backtest calibration, error analysis, and output QA
- Contribute to KPI/KRI reporting on portfolio coverage and cycle time
Requirements
What you’ll need- Experience running third party or vendor risk assessments end to end at a technology company: scoping the engagement, determining inherent risk, reviewing controls and evidence, documenting residual risk, and driving findings to closure
- Working knowledge of risk fundamentals (inherent and residual risk, control effectiveness, compensating controls, risk acceptance) and the judgment to apply them when the evidence is incomplete or the answer isn't in a framework
- Ability to assess a vendor across security, privacy, compliance, and operational risk domains, and to recognize which findings you can close yourself and which need a domain specialist
- Track record of driving risk treatment to closure through influence across teams with competing priorities
- Experience building or tuning an LLM-backed workflow, agent, or automation in a risk, compliance, or operations context, including tuning prompts and reviewing model output for accuracy
- Experience building or operating issue management workflows: logging issues with a clear owner and due date, tracking remediation, and escalating when treatment stalls
- Hands-on time in a procurement or GRC platform with an understanding of how intake, tiering, and assessment routing fit together
- Working knowledge of business continuity, disaster recovery, and concentration risk concepts, with the ability to apply them to a vendor portfolio
Benefits
Comp & perks- Competitive compensation and benefits
- Optional equity donation matching
- Generous vacation and parental leave
- Flexible working hours
- Lovely office space in which to collaborate with colleagues