← Back to results

Security Risk Analyst, Risk Engineering

Join Anthropic as a Security Risk Analyst to drive risk-informed decisions in a rapidly evolving AI landscape.

Location
San Francisco, CA, United States
Compensation
$270k–$345k/yr
Level
mid
Type
full time · Hybrid

Posted by employer 1 day ago

First seen on Joblaze 4 hours ago

Last verified on the company career page 4 hours ago

Skills & Technologies

What you'll build

  • Enable leadership to make risk-informed decisions
  • Lead quantitative analysis of security risk scenarios
  • Partner with Security Engineering to assess threat scenarios
  • Frame escalations and risk treatment decisions
  • Shape analysis for leadership risk reviews

Must have

  • Owned security or technology risk analysis end to end
  • Hands-on FAIR-style quantification experience
  • Thrive in ambiguity
  • Technical security depth to decompose an attack path
  • Defensible severity and likelihood on ambiguous problems

Nice to have

  • Applied FAIR-CAM or another structured approach
  • Built or operated a cyber risk quantification program
  • Defined risk appetite or tolerance thresholds
  • Background in security engineering or decision science
  • Familiar with security risks specific to AI systems

Practical constraints

  • Currently, staff must be in the office at least 25% of the time

AI in the day-to-day

Use AI and automation to scale risk analysis.

Requirements

Education
Bachelor's degree
Visa
Sponsorship available

Not disclosed in this posting: years of experience.

Benefits

401k Match Unlimited PTO Equity/Stock Options Remote Work Health Insurance Parental Leave

Joblaze summary

In the role of Security Risk Analyst at Anthropic, the individual will focus on assessing and managing security risks through both qualitative and quantitative analyses, driving decisions that impact the company's security posture. Proficiency in FAIR methodology, along with experience in risk analysis and a solid understanding of security engineering, are essential for success in this position. This role is well-suited for candidates with a strong background in security or technology risk analysis, particularly those who thrive in ambiguous environments and can communicate complex risk scenarios effectively. Anthropic's emphasis on collaboration and AI safety underscores the importance of t

Joblaze insights

  • Listed today — first seen on Joblaze October 6, 2026. Last confirmed on Anthropic's careers page October 6, 2026.
  • Salary band is above the typical range for Security roles (median ~$170,000).
  • Starts above 94% of 49 comparable mid security roles in United States that list Python we track (median $130,000 across 21 companies). See Python salary trends
  • Python appears in 41.1% of 192 comparable mid security roles in United States; AI/ML appears in 5.2% of 192 comparable mid security roles in United States.

Quick facts

Is the Security Risk Analyst, Risk Engineering role remote?
It's hybrid — Anthropic expects some on-site time in San Francisco, CA, United States.
What's the salary range?
Anthropic lists $270,000–$345,000 for this role.
Where is the role based?
Anthropic is hiring for this position in San Francisco, CA, United States.
What's the tech stack?
Joblaze extracted these technologies from the posting: AI/ML, FAIR, Monte-Carlo simulation, Python, R.
Does Anthropic sponsor work visas for this role?
Yes — the posting indicates visa sponsorship is available for the right candidate.
What seniority level is this role?
Anthropic targets mid-level candidates for this position.
Is this full-time or contract?
Full-time for this Security Risk Analyst, Risk Engineering role at Anthropic.

From the original posting

About Anthropic

About the role

The Security Risk team is responsible for how Anthropic identifies, prioritizes, and drives treatment of its most important security risks. We are rebuilding risk management to operate as an engineering function, using automation, quantitative risk and AI-native platforms to enable decision making. The risks we assess span Anthropic's full security landscape, so the team needs breadth across domains and the judgment to go deep wherever a decision demands it. Security Risk, in deep partnership with Security Engineering, helps define the security program and shapes how investment and treatment decisions get made.

The conventional GRC playbook was not built for a company shipping frontier AI. You will help define what replaces it, with a direct line to CISO-level decisions. As a Security Risk Analyst you will take risk questions from leadership and partner teams and drive them to a decision. Sometimes that is a fast, structured qualitative assessment and other times it is a deep FAIR-based quantitative analysis. Either way you bring leadership a clear position, the tradeoffs, and honest uncertainty, and you defend it under challenge. In parallel, you will help turn quantitative risk into a product partner teams can leverage, and define the standards a growing risk function will run on.

Key responsibilities

  • Enable leadership and partner teams to make risk-informed decisions. Take ambiguous risk questions, drive them to a documented decision, and communicate the quantitative and qualitative tradeoffs clearly

  • Lead quantitative analysis of the company's top security risk scenarios using FAIR, calibrated estimation, and simulation, working with the engineers who own the systems and presenting results in terms leadership can act on

  • Partner with Security Engineering to assess threat scenarios and control effectiveness so security investment is right-sized to actual risk and remediation is sequenced where it buys down the most risk

  • Frame escalations and risk treatment decisions with a clear recommendation, an honest statement of uncertainty, and re-evaluation triggers, and pressure test those decisions with risk owners

  • Shape the analysis and narrative behind leadership risk reviews, and help define risk appetite and the risk metrics the organization should measure and why

  • Use AI and automation to scale risk analysis, and own the calibration and quality review that keep the outputs trustworthy

  • Turn one-off analyses into reusable methods, templates, and training so risk analysis becomes increasingly self service for partner teams, and raise the analytical quality of the risk register

You may be a good fit if you

  • Have owned security or technology risk analysis end to end, qualitative and quantitative, and can point to a decision your output changed, whether a funding call, a launch call, a remediation sequence, or a documented acceptance

  • Have hands-on FAIR-style quantification experience, including scenario decomposition, calibrated estimation, and Monte Carlo simulation in Python, R, or spreadsheet tooling, briefed to decision makers

  • Thrive in ambiguity. You frame a moving question into something analyzable, pick the depth that fits, and drive to a decision rather than a report

  • Put defensible severity and likelihood on ambiguous problems, state uncertainty honestly, and change your position when the evidence changes

  • Have enough technical security depth to decompose an attack path with security engineers and be credible in the room

  • Can compress a complex risk position into one paragraph for the CISO, make the tradeoff explicit, and defend it under pointed questions

  • Use Claude or other LLMs as daily working tools and review model output critically

  • Are low ego and collaborative, build credibility through the work, and care about AI safety and the role security risk plays in it

Strong candidates may also

  • Have applied FAIR-CAM or another structured approach to control effectiveness and attack path modeling

  • Have built or operated a cyber risk quantification program, or turned quantitative analysis into tooling, templates, or training that others ran

  • Have helped define risk appetite or tolerance thresholds an organization actually used to make decisions

  • Bring a background in security engineering, detection, threat intelligence, actuarial science, or decision science that grounds the numbers in real systems

  • Are familiar with security risks specific to AI systems, such as goal or intent modification, and how they change traditional threat models

The annual compensation range for this role is listed below.

Annual Salary:
$270,000—$345,000 USD

Logistics

Standard company text repeated across Anthropic's postings is omitted here.

Similar positions

Anthropic
Staff Security Engineer, Risk Engineering
Anthropic · San Francisco, CA | New York City, NY | Seattle, WA
Anthropic
Staff+ Application Security Engineer
Anthropic · Remote-Friendly (Travel-Required) | San Francisco, CA | Seattle, WA | New York City, NY
Anthropic
Technical Program Manager, Security
Anthropic · San Francisco, CA | New York City, NY | Seattle, WA
Anthropic
Security Risk & Compliance, Data Centers & Compute
Anthropic · San Francisco, CA | Seattle, WA | New York City, NY | Washington, DC
Anthropic
Security Risk & Compliance, Agent Security
Anthropic · San Francisco, CA, United States