Commercial Counsel, Infrastructure Security
📍 New York City, United States
📍 San Francisco, United States
📍 Seattle, United States
Used Tools & Technologies
Not specified
Required Skills & Competences
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Security @ 3
Hiring @ 3
Leadership @ 3
Communication @ 3
Reporting @ 3
Audit @ 6
Compliance @ 3
AI @ 3
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Anthropic is hiring a Commercial Counsel to support infrastructure-security for Compute and Infrastructure. You will be the day-to-day legal partner to the Chief Security Officer’s infrastructure-security and Governance, Risk & Compliance teams, owning the contractual and regulatory layer of physical and facility security, hardware and supply-chain security, network security, vendor personnel and insider-risk flow-downs, and security regulatory and assurance. You will partner closely with internal teams (Frontier, Product, Litigation, Employment, Commercial Legal) and specialized outside counsel to ensure security requirements are in contracts and external work product aligns with Anthropic’s security posture and commercial objectives.
Responsibilities
- Draft and negotiate security design-basis and site-hardening specifications in build-to-suit, lease, and colocation agreements (perimeter, access control, CCTV, intrusion detection).
- Draft and negotiate guard-force statements of work, post orders, KPI regimes, visitor/contractor/badging policy, and security clauses for shared-campus and multi-tenant arrangements.
- Own provenance, anti-tamper, and chain-of-custody warranties in silicon, ODM, and OEM agreements; trusted-supplier and country-of-origin restrictions; NDAA §889/§5949 and CHIPS-Act guardrail flow-downs; BIS/EAR export-control flow-downs and end-use/end-user certifications.
- Draft terms related to firmware integrity, secure-boot, golden-image escrow, secure logistics, counterfeit-part and grey-market controls, secure decommissioning, and certified media-destruction.
- Draft security schedules in carrier and fiber agreements (encryption-in-transit, route integrity, lawful-intercept handling) and security obligations in peering agreements.
- Set background-screening, training, and badge-revocation requirements for vendor and contractor personnel with site or hardware access, and flow Anthropic personnel-security standards into guard-force, security-integrator, and EPC vendor MSAs.
- Support CFIUS and outbound-investment screening on infrastructure vendors and sites; provide NIST/ISO/SOC 2 physical-control evidence for customer and auditor assurance; support security representations in customer contracts that reference physical infrastructure.
- Work with specialized outside counsel and ensure their work product aligns with Anthropic’s security and commercial objectives.
- Build the function: develop and maintain security-schedule library, design-basis templates, vendor security questionnaire templates, negotiation playbooks; train Procurement, Datacenter, and Network teams to apply them at scale.
- Serve as direct counsel to the CSO’s infrastructure-security organization; coordinate with Product Legal and Litigation on incident response, threat intelligence, law-enforcement and intelligence-community engagement, insider-threat governance, and model-weight security policy under Anthropic’s Responsible Scaling Policy.
- Escalate novel structures or terms that create downstream risk; ensure security requirements accommodate AI-specific threats including hardware tamper, supply-chain interdiction, and high-value-target facility risk.
- Monitor and assess the evolving regulatory landscape affecting security and data protection; identify higher-risk obligations and partner with security to operationalize them through policies, controls, and compliance programs.
- Advise on risk assessments, risk acceptance decisions, reporting to leadership and the board; review remediation commitments from assessments, customer audits, and regulator inquiries.
Requirements
- JD and active membership in at least one U.S. state bar.
- Fluency in security design-basis specifications, guard-force and access-control contracting, and how security schedules interact with build-to-suit, colocation, procurement, and carrier agreements.
- Experience with NDAA §889/§5949, CHIPS-Act guardrails, CFIUS/outbound-investment screening, and trusted-supplier or country-of-origin programs.
- Comfort with NIST, ISO 27001, and SOC 2 physical-control frameworks and the evidence/attestation processes that support customer and auditor assurance.
- Ability to coordinate effectively with multiple internal legal teams and specialized outside counsel while maintaining strategic direction.
- Strong judgment about when contractual security terms create downstream risk for Anthropic’s security posture, audit position, or operational flexibility.
- Effective collaboration skills for working with the CSO’s organization, procurement, datacenter, and network teams.
- Communication skills that translate security and supply-chain-integrity concepts into clear risk assessments for business stakeholders.
- Genuine interest in infrastructure security and appreciation for why physical, hardware, and network security is mission-critical for frontier AI.
Preferred qualifications
- 10–12+ years of relevant legal experience with exposure to physical/facility security contracting, hardware and supply-chain security, network security schedules, or security regulatory and assurance work for critical infrastructure.
- In-house experience at cloud service providers, hyperscalers, defense and aerospace primes, telecom carriers, utilities, semiconductor companies, or datacenter operators; or U.S. government experience (DoD, DHS/CISA, BIS, CFIUS).
- Experience at large technology companies with first-party datacenter or hardware programs supporting security contracting from the buy side.
- Law firm experience in national-security, supply-chain, or critical-infrastructure practices, particularly on NDAA §889, CFIUS, or trusted-supplier matters.
- Prior involvement in transactions requiring secure logistics, chain-of-custody, firmware integrity, and certified media destruction.
- Familiarity with CCTV/biometrics privacy regimes, executive-protection contracting, and contractual insider-risk program elements.
- Ability to obtain and maintain a U.S. security clearance.
Compensation
- Annual Salary: $320,000 - $385,000 USD
Logistics & Other Details
- Location: San Francisco; Seattle; Washington, D.C.; New York City (role-specific policy expects staff to be able to work from these offices at least 3 days a week).
- Minimum education: Bachelor’s degree or equivalent combination of education/training/experience.
- Visa sponsorship: Anthropic states they sponsor visas and will make reasonable efforts to obtain a visa for candidates they hire; immigration counsel is retained.
- Location-based hybrid policy: currently expect staff to be in one of Anthropic’s offices at least 25% of the time; some roles may require more time in offices.
Benefits
- Competitive compensation and benefits, optional equity donation matching, generous vacation and parental leave, flexible working hours, and an office space for collaboration.