GSOC Response & Policy Program Specialist

Anthropic · San Francisco, CA · Other

Posted 2026-08-08

Apply for this role →

About the Role

We are seeking a GSOC Response & Policy Program Specialist to define how Anthropic's Global Security Operations Center detects, responds to, and recovers from incidents affecting our people, facilities, and operations.

You will write the GSOC plan and policy: the functions, the severity matrix, the communication templates, and the service levels. You will build global incident-specific response protocols, covering incidents that arise across different regions and countries, and turn each one into two playbooks, one that is built on actionability for the operator on the floor and one for the business facing for the partner receiving the call. You will design a simple, scalable on-call rotation and call tree so Incident Commander coverage never depends on any one person. You will take this body of work through Legal, HR, and Communications, secure signoff from senior leadership, and then train and roll it out.

You will assist in responding to incidents. This role will also coordinate the handoff to the appropriate Incident Commander as an incident escalates, and acts as the standing liaison between GSOC and Crisis Management. Your job is to turn all of this into a written, approved, and actionable standard that the GSOC and the business both run on, and to keep it current as the program matures.

This is a builder's role in a program that is scaling globally. The scope covers incidents on site, off site, and during travel, including natural disasters, across every region Anthropic operates in.

Important Note: In this position, you may be exposed to graphic and explicit content, including material of a violent or psychologically disturbing nature.

This role carries an on-call requirement and after-hours availability. The GSOC Response & Policy Specialist is expected to respond to threats as they arise, including evenings, weekends, and holidays.

Responsibilities

Author the GSOC plan and policy, including the documented set of GSOC functions, the incident severity matrix, communication templates, and service level agreements for response timing

Design global incident- and event-specific response protocols, and produce the corresponding GSOC operator playbooks and business-facing playbooks

Define and obtain approval for the tooling and channels used for incident response and management, and for the distinct path used for information-only employee advisories

Partner with Legal, Communications, HR, and Employee Relations to align on notification thresholds and obligations before an incident occurs, not during one

Design and formalize a simple, scalable on-call rotation and call tree for GSOC incident response personnel, so Incident Commander coverage does not depend on any single person's availability

Drive policy socialization and secure approval from senior leadership

Build and deliver the training and rollout that puts the policy into practice

You will assist in responding to incidents. This role will also coordinate the handoff to the appropriate Incident Commander as an incident escalates, and acts as the standing liaison between GSOC and Crisis Management.

Act as the standing liaison between GSOC and Crisis Management, and partner with Crisis Management on GSOC service design

Run after-action reviews and tabletop exercises, and fold what they surface back into the policy

Measure whether the standard is being met, and report on it

You may be a good fit if you:

Have 8+ years of professional experience in GSOCs, security operations, emergency or crisis management, business continuity, incident command, or a closely related discipline

Hold a bachelor's degree or higher in a relevant field

Have authored security, safety, or emergency response policy that was formally approved and adopted by an organization

Have served as Incident Commander, or in an equivalent command role, during live incidents

Have working knowledge of ISO 22320:2018 (or an equivalent incident command system such as ICS/NIMS) and of severity or tiering frameworks, and can speak to adapting one to a specific organization

Write clearly and concisely for non-specialist audiences, and can tailor the same underlying content for an operator, a business partner, and an executive

Can manage a document-heavy program on a deadline while remaining available for live incident response

Have a strong drive for continuous process improvement and thrive in highly collaborative environments

Are comfortable with a flexible schedule, including 24/7 on-call rotation and after-hours response

Strong candidates may also have:

Experience standing up a security operations center or an incident response program from an undocumented state

Familiarity with mass notification, critical communications and incident management platforms

Experience with travel risk management and duty-of-care programs covering travelers and employees affected by natural disasters

Professional certifications such as CEM, CBCP, PSP, or FEMA ICS credentials

Specialized knowledge of risks unique to the AI sector

Deadline to apply: None. Applications will be received on a rolling basis.

The annual compensation range for this role is listed below.

For sales roles, the range provided is the role’s On Target Earnings ("OTE") range, meaning that the range includes both the sales commissions/sales bonuses target and annual base salary for the role.

Annual Salary:

$180,000—$230,000 USD

Apply for this role →

← Back to all jobs