US Public Sector Compliance, Security GRC

USD 255,000-270,000 per year
MIDDLE
✅ Hybrid
✅ Visa Sponsorship

Tech Stack

Audit @ 3 Compliance @ 3 LLM Leadership @ 3 Reporting @ 3 Security @ 3

Details

Anthropic's Security Governance, Risk, and Compliance (GRC) team translates regulatory, customer, and voluntary obligations into controls and provides visibility into the company's security commitments. The Compliance and Audit Programs team runs integrated audits across frameworks and maintains the Common Control Framework.

This role focuses on US public sector compliance, including federal civilian requirements, Department of War impact levels, CMMC, NIST SP 800-171, StateRAMP, TX-RAMP, and agency requirements. The role supports authorizations from requirements through authorization and ongoing compliance, working alongside public sector engineering teams.

Responsibilities

  • Run recurring compliance cycles for US government authorizations, including continuous monitoring, POA&M, annual assessments, SSP updates, significant changes, and incident notifications.
  • Start with C4G on Palantir FedStart and the NIST SP 800-171 assessment with Schellman.
  • Co-own FedRAMP 20x work for Claude Enterprise.
  • Help build new authorizations, including first-party FedRAMP High, Department of War impact levels, StateRAMP, and TX-RAMP, through requirements and evidence work.
  • Support model authorizations in GovCloud and Vertex for every model launch as the GRC member of the inference and model delivery pod.
  • Translate government obligations into requirements for partner teams, such as vulnerability service-level agreements in the internal vulnerability reporting platform, and review the resulting evidence.
  • Answer public sector customer and deal questions concerning authorization boundaries, CUI, IRS Publication 1075, CJIS, and ITAR.
  • Handle questionnaires and requests for information until they move to Customer Trust.
  • Map US government requirements onto the Common Control Framework with the Controls Assurance Lead and maintain a single source of truth for status.
  • Use Claude to automate mapping, evidence collection, and reporting, while verifying machine-drafted language before it becomes part of the record.

Requirements

  • Several years of experience in security compliance or IT audit, including hands-on US government compliance for a cloud service through the ongoing compliance cycle after authorization. Relevant frameworks include FedRAMP, Department of War impact levels, CMMC, NIST SP 800-171, and StateRAMP.
  • Working knowledge of the NIST SP 800-53 Moderate baseline and authorization mechanics, including boundary definition, control implementation statements, assessment, continuous monitoring, POA&M, and significant change.
  • Experience writing requirements for engineering teams from a control baseline and reviewing the resulting evidence.
  • Working knowledge of how GovCloud- or Vertex-style government regions differ from commercial environments, and how adding a model, feature, or region affects an authorized boundary.
  • Technical fluency sufficient to read a runbook, configuration, or pipeline definition and assess whether it enforces the written control.
  • Clear writing skills for implementation statements and status reports used by assessors, engineers, and leadership.
  • Ability to help partner teams prioritize and close compliance work without direct authority over them.
  • A bachelor's degree or equivalent combination of education, training, and experience. The field of study must be relevant to the role through coursework, training, or professional experience.

Preferred Qualifications

  • Experience taking a service through FedRAMP High or Department of War IL4 or IL5, or supporting a service on classified networks.
  • Experience with a FedRAMP 20x pilot or with machine-readable evidence or reporting for an assessor.
  • Experience applying LLMs to compliance work, such as control mapping, evidence testing, or continuous evidence collection.
  • A US security clearance or eligibility to obtain one.
  • Experience with state and local requirements such as StateRAMP, TX-RAMP, IRS Publication 1075, or CJIS.
  • CISSP, CISA, CGRC, or a similar certification is welcome but not required.

Compensation and Logistics

  • Annual salary: $255,000–$270,000 USD.
  • The role follows a location-based hybrid policy, with staff expected to work from one of the company's offices at least 25% of the time. Some roles may require more office time.
  • Anthropic sponsors visas and will make reasonable efforts to obtain a visa for successful candidates, although sponsorship is not guaranteed for every role or candidate.
  • Applications are accepted on a rolling basis with no stated deadline.

More jobs at Anthropic

Similar jobs