About the role
Anthropic is building safe, reliable, and steerable AI systems for the world. The company brings together researchers, engineers, policy experts, and business leaders focused on ensuring AI remains beneficial to society. Anthropic's approach emphasizes transparency and human oversight in every major decision about its technology.
Anthropic's Security GRC team operates as the backbone of the company's commitment to security and regulatory excellence. Rather than relying on periodic audits alone, the team is pioneering a new model where AI assists in continuous control verification while keeping humans central to decisions that matter. The team translates complex regulatory and customer requirements into actionable controls and gives leadership real-time visibility into compliance health.
You'll join Compliance and Audit Programs as the individual contributor leading Anthropic's US public sector compliance work. You'll own the full lifecycle of the company's government authorizations—from FedRAMP and DoD impact levels through StateRAMP and TX-RAMP—handling everything from initial requirements through continuous monitoring and recurring authorization cycles. This position works directly alongside engineering teams building government-authorized solutions, not downstream of them, giving you real influence over how Anthropic serves the public sector.
What you'll do
- Manage recurring compliance cycles for all US government authorizations including continuous monitoring, plans of action and milestones, annual assessments, and incident notifications across FedRAMP, DoD, and state programs
- Co-own FedRAMP 20x authorization work for Claude Enterprise and build new government authorizations by translating requirements into engineering work and verifying evidence
- Support model authorizations for government cloud regions as the compliance lead within infrastructure delivery teams, ensuring every model launch meets boundary requirements
- Convert government regulatory obligations into specific, testable requirements for partner teams, then review the evidence they deliver and make launch decisions based on control readiness
- Field public sector customer and deal questions around authorization boundaries, data handling regulations like CUI and CJIS, and complete RFI and questionnaire cycles
- Maintain a single source of truth by mapping US government requirements onto Anthropic's Common Control Framework with the Controls Assurance Lead
- Use Claude to automate mapping, evidence collection, and report generation, with you retaining final judgment on what becomes the official record
What you'll bring
- Multiple years running security compliance or IT audit programs, with direct hands-on experience managing the full post-authorization cycle for a cloud service under FedRAMP, DoD impact levels, CMMC, NIST SP 800-171, or StateRAMP
- Deep fluency with NIST SP 800-53 Moderate baseline and authorization mechanics including boundary definition, control statements, assessment methodology, continuous monitoring, and POA&M
- Track record writing requirements from control baselines for engineering teams and evaluating whether delivered evidence actually demonstrates control performance
- Technical literacy sufficient to read infrastructure runbooks, configuration files, and deployment pipelines to assess whether they enforce written controls
- Clear technical writing, because your control statements and status reports become the reference material for assessors, engineers, and leadership
- Demonstrated ability to influence partner teams to prioritize compliance work and close findings without direct authority over them
- Working knowledge of how government cloud regions like GovCloud or Vertex differ from commercial infrastructure and what compliance changes when adding models or features to authorized boundaries
Nice to have
- Experience taking a service through FedRAMP High or DoD IL4/IL5 authorization, or supporting classified network deployments
- Hands-on work with FedRAMP 20x pilots or building machine-readable evidence and automated reporting for assessors
- Applied LLMs to compliance problems such as control mapping or continuous evidence collection
- Eligibility for or current US security clearance
- Experience with state and local programs including StateRAMP, TX-RAMP, IRS Publication 1075, or CJIS
What they offer
- Full-time employment in San Francisco, CA or New York City, NY
Pay, location & hours
Salary not listed. Based in San Francisco, CA, New York City, NY.
About Anthropic
39 open roles in this building · Company page → · See it on the map