Security Risk Analyst, Risk Engineering

Anthropic • $270K — $345K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in security or technology risk analysis, both qualitative and quantitative.
  • Hands-on experience with FAIR-style quantification, including scenario decomposition and Monte Carlo simulation.
  • Ability to navigate ambiguity and drive decisions from complex risk questions.
  • Strong communication skills to present complex risk positions clearly to leadership.
  • Technical depth in security to engage credibly with engineers on attack paths.
  • Experience using AI tools like Claude for risk analysis and model output review.
  • Collaborative mindset with a focus on AI safety and security risk.

Responsibilities

  • Enable leadership to make informed risk decisions by documenting and communicating tradeoffs.
  • Lead quantitative analysis of top security risks using FAIR and simulation techniques.
  • Collaborate with Security Engineering to assess threat scenarios and optimize security investments.
  • Frame risk treatment decisions with clear recommendations and uncertainty assessments.
  • Shape narratives for leadership risk reviews and define organizational risk metrics.
  • Utilize AI and automation to enhance risk analysis scalability and quality.
  • Develop reusable methods and training for partner teams to improve risk analysis self-service.

Benefits

  • Visa sponsorship available for eligible candidates.
  • Hybrid work policy requiring at least 25% in-office attendance.
  • Encouragement for diverse candidates to apply, promoting representation in AI development.
Full Job Description
About the role

The Security Risk team is responsible for how Anthropic identifies, prioritizes, and drives treatment of its most important security risks. We are rebuilding risk management to operate as an engineering function, using automation, quantitative risk and AI-native platforms to enable decision making. The risks we assess span Anthropic's full security landscape, so the team needs breadth across domains and the judgment to go deep wherever a decision demands it. Security Risk, in deep partnership with Security Engineering, helps define the security program and shapes how investment and treatment decisions get made.

The conventional GRC playbook was not built for a company shipping frontier AI. You will help define what replaces it, with a direct line to CISO-level decisions. As a Security Risk Analyst you will take risk questions from leadership and partner teams and drive them to a decision. Sometimes that is a fast, structured qualitative assessment and other times it is a deep FAIR-based quantitative analysis. Either way you bring leadership a clear position, the tradeoffs, and honest uncertainty, and you defend it under challenge. In parallel, you will help turn quantitative risk into a product partner teams can leverage, and define the standards a growing risk function will run on.
Key responsibilities
  • Enable leadership and partner teams to make risk-informed decisions. Take ambiguous risk questions, drive them to a documented decision, and communicate the quantitative and qualitative tradeoffs clearly
  • Lead quantitative analysis of the company's top security risk scenarios using FAIR, calibrated estimation, and simulation, working with the engineers who own the systems and presenting results in terms leadership can act on
  • Partner with Security Engineering to assess threat scenarios and control effectiveness so security investment is right-sized to actual risk and remediation is sequenced where it buys down the most risk
  • Frame escalations and risk treatment decisions with a clear recommendation, an honest statement of uncertainty, and re-evaluation triggers, and pressure test those decisions with risk owners
  • Shape the analysis and narrative behind leadership risk reviews, and help define risk appetite and the risk metrics the organization should measure and why
  • Use AI and automation to scale risk analysis, and own the calibration and quality review that keep the outputs trustworthy
  • Turn one-off analyses into reusable methods, templates, and training so risk analysis becomes increasingly self service for partner teams, and raise the analytical quality of the risk register
You may be a good fit if you
  • Have owned security or technology risk analysis end to end, qualitative and quantitative, and can point to a decision your output changed, whether a funding call, a launch call, a remediation sequence, or a documented acceptance
  • Have hands-on FAIR-style quantification experience, including scenario decomposition, calibrated estimation, and Monte Carlo simulation in Python, R, or spreadsheet tooling, briefed to decision makers
  • Thrive in ambiguity. You frame a moving question into something analyzable, pick the depth that fits, and drive to a decision rather than a report
  • Put defensible severity and likelihood on ambiguous problems, state uncertainty honestly, and change your position when the evidence changes
  • Have enough technical security depth to decompose an attack path with security engineers and be credible in the room
  • Can compress a complex risk position into one paragraph for the CISO, make the tradeoff explicit, and defend it under pointed questions
  • Use Claude or other LLMs as daily working tools and review model output critically
  • Are low ego and collaborative, build credibility through the work, and care about AI safety and the role security risk plays in it
Strong candidates may also
  • Have applied FAIR-CAM or another structured approach to control effectiveness and attack path modeling
  • Have built or operated a cyber risk quantification program, or turned quantitative analysis into tooling, templates, or training that others ran
  • Have helped define risk appetite or tolerance thresholds an organization actually used to make decisions
  • Bring a background in security engineering, detection, threat intelligence, actuarial science, or decision science that grounds the numbers in real systems
  • Are familiar with security risks specific to AI systems, such as goal or intent modification, and how they change traditional threat models


The annual compensation range for this role is listed below.

For sales roles, the range provided is the role's On Target Earnings ("OTE") range, meaning that the range includes both the sales commissions/sales bonuses target and annual base salary for the role.

Annual Salary:

$270,000-$345,000 USD

Logistics

Minimum education: Bachelor's degree or an equivalent combination of education, training, and/or experience

Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience

Minimum years of experience: Years of experience required will correlate with the internal job level requirements for the position

Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices.

Visa sponsorship: We do sponsor visas! However, we aren't able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this.

We encourage you to apply even if you do not believe you meet every single qualification. Not all strong candidates will meet every single qualification as listed. Research shows that people who identify as being from underrepresented groups are more prone to experiencing imposter syndrome and doubting the strength of their candidacy, so we urge you not to exclude yourself prematurely and to submit an application if you're interested in this work. We think AI systems like the ones we're building have enormous social and ethical implications. We think this makes representation even more important, and we strive to include a range of diverse perspectives on our team.

About Anthropic

Anthropic is an artificial intelligence research lab that focuses on developing AI systems that are safe, reliable, and trustworthy. The company was founded in 2019 by Dr. Yoshua Bengio, a leading AI researcher and winner of the Turing Award. Anthropic's research is focused on developing AI systems that can learn from small amounts of data, reason about complex systems, and interact with humans in a natural way. The company is based in New York City and has a team of experienced AI researchers and engineers.
Learn more about Anthropic
Size
50 employees
Industry
Founded
2019

More Jobs at Anthropic

More Information Technology Jobs

Find similar Security Risk Analyst, Risk Engineering jobs: