US Public Sector Compliance, Security GRC
$171k - $800k • Remote • San Francisco, CA | New York City, NY
Posted 9h ago
About the job
Anthropic is seeking a US Public Sector Compliance, Security GRC professional to join our Security Governance, Risk, and Compliance (GRC) team. This role focuses on maintaining Anthropic's US government authorizations, including FedRAMP, DoD impact levels, CMMC, NIST SP 800-171, and state and local requirements like StateRAMP and TX-RAMP. You will manage recurring authorization cycles, assist in building new authorizations, and ensure frontier models remain compliant. This individual contributor role involves translating government requirements into actionable engineering tasks, reviewing evidence, and ensuring product readiness for government boundaries. You will also map US government requirements to our Common Control Framework and leverage Claude for tasks like mapping, evidence collection, and reporting, with a focus on human oversight where critical.
Responsibilities
- Manage recurring compliance cycles for US government authorizations, including continuous monitoring, POA&M, annual assessments, SSP updates, significant changes, and incident notifications.
- Co-own FedRAMP 20x for Claude Enterprise and contribute to new authorizations (FedRAMP High, DoD impact levels, StateRAMP, TX-RAMP).
- Support model authorizations in GovCloud and Vertex for all model launches as part of the Inference and model delivery pod.
- Translate government obligations into partner team requirements and review evidence, such as vulnerability SLAs.
- Address public sector customer and deal inquiries regarding boundaries, CUI, IRS Publication 1075, CJIS, and ITAR, and manage questionnaires and RFIs.
- Map US government requirements to the Common Control Framework to maintain a single source of truth for status.
- Utilize Claude to automate mapping, evidence collection, and reporting, verifying machine-drafted content before finalization.
Requirements
- Several years of experience in security compliance or IT audit with hands-on US government compliance for cloud services (FedRAMP, DoD impact levels, CMMC, NIST SP 800-171, or StateRAMP).
- Experience with the ongoing compliance cycle post-authorization.
- Working command of NIST SP 800-53 Moderate baseline and authorization mechanics (boundary definition, control implementation, assessment, continuous monitoring, POA&M, significant change).
- Experience writing requirements for engineering teams based on control baselines and reviewing submitted evidence.
- Working knowledge of differences between GovCloud/Vertex government regions and commercial environments, and changes associated with adding models, features, or regions to authorized boundaries.
- Sufficient technical fluency to interpret runbooks, configurations, or pipeline definitions and assess control enforcement.
- Clear writing skills for implementation statements and status reports.
- Ability to influence partner teams to prioritize and complete compliance work without direct authority.