US Public Sector Compliance, Security GRC

Anthropic•San Francisco, NY
•Hybrid

About The Position

Anthropic's Security Governance, Risk, and Compliance (GRC) team is responsible for ensuring the company meets its security commitments. This role specifically focuses on the Compliance and Audit Programs (CAP) within Security GRC, managing the integrated audit across frameworks and maintaining the Common Control Framework. The position involves working directly with public sector engineering pods to address US public sector compliance requirements from inception through authorization and ongoing monitoring. This is an individual contributor role for someone who works independently, writes clearly, and finds satisfaction in maintaining government authorizations as products evolve.

Requirements

  • Several years in security compliance or IT audit with hands-on US government compliance for a cloud service (FedRAMP, DoD impact levels, CMMC or NIST SP 800-171, or StateRAMP), including the ongoing compliance cycle after authorization.
  • Working command of the NIST SP 800-53 Moderate baseline and the mechanics of authorization: boundary definition, control implementation statements, assessment, continuous monitoring, POA&M, and significant change.
  • Experience writing requirements for engineering teams from a control baseline and reviewing the evidence that came back.
  • Working knowledge of how a GovCloud or Vertex style government region differs from commercial, and what changes when a model, feature, or region is added to an authorized boundary.
  • Sufficient technical fluency to read a runbook, configuration, or pipeline definition and judge whether it enforces the written control.
  • Clear writing skills, as implementation statements and status reports are used by assessors, engineers, and leadership.
  • Ability to get partner teams to prioritize and close compliance work without direct authority.

Nice To Haves

  • Taken a service through FedRAMP High or DoD IL4 or IL5, or supported a service on classified networks.
  • Worked on a FedRAMP 20x pilot or built machine-readable evidence or reporting for an assessor.
  • Applied LLMs to compliance work such as control mapping, evidence testing, or continuous evidence collection.
  • Hold or are eligible for a US security clearance.
  • Experience with state and local requirements such as StateRAMP, TX-RAMP, IRS Publication 1075, or CJIS.
  • Fluency sufficient to read, query, and challenge code.
  • Hold certifications such as CISSP, CISA, CGRC, or similar.
  • Prior AI industry experience.

Responsibilities

  • Run the recurring compliance cycles for US government authorizations, including continuous monitoring, POA&M, annual assessments, SSP updates, significant changes, and incident notifications.
  • Co-own FedRAMP 20x work for Claude Enterprise and assist in building new authorizations such as first-party FedRAMP High, DoD impact levels, StateRAMP, and TX-RAMP.
  • Support model authorizations in GovCloud and Vertex for every model launch as the GRC member of the Inference and model delivery pod.
  • Translate government obligations into partner team requirements, including vulnerability SLAs, and review evidence.
  • Answer public sector customer and deal questions regarding authorization boundaries, CUI, IRS Publication 1075, CJIS, and ITAR, and handle questionnaires and RFIs.
  • Map US government requirements onto the Common Control Framework with the Controls Assurance Lead to maintain a single source of truth for status.
  • Utilize Claude to automate mapping, evidence collection, and reporting, and verify machine-drafted language before it becomes official record.

Benefits

  • Competitive compensation
  • Optional equity donation matching
  • Generous vacation
  • Parental leave
  • Flexible working hours
  • Visa sponsorship
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service