US Public Sector Compliance, Security GRC

Anthropic · San Francisco, CA | New York City, NY · Security · listed October 5, 2026

The shape of it

Seniority
Not stated
Where
Not stated
Stated pay
$255,000 – $270,000 USD
Requirements listed
7
Length
1,464 words

In the posting’s own words

Within Security GRC, Compliance and Audit Programs (CAP) runs the integrated audit across our frameworks and maintains the Common Control Framework the program hangs off. This role sits in Compliance & Audit Programs and works one regime family, US public sector, from requirements through authorization and ongoing compliance, working alongside the public sector engineering pods rather than downstream of them.

What it asks for · 7

  • Several years in security compliance or IT audit with hands-on US government compliance for a cloud service (FedRAMP, DoD impact levels, CMMC or NIST SP 800-171, or StateRAMP), including the ongoing compliance cycle after authorization
  • Working command of the NIST SP 800-53 Moderate baseline and the mechanics of authorization: boundary definition, control implementation statements, assessment, continuous monitoring, POA&M and significant change
  • Experience writing requirements for engineering teams from a control baseline and reviewing the evidence that came back
  • Working knowledge of how a GovCloud or Vertex style government region differs from commercial, and what changes when a model, feature or region is added to an authorized boundary
  • Enough technical fluency to read a runbook, configuration or pipeline definition and judge whether it enforces the written control
  • Clear writing, because implementation statements and status reports are what assessors, engineers and leadership work from
  • Ability to get partner teams to prioritize and close compliance work without authority over them

Also a plus

  • Have taken a service through FedRAMP High or DoD IL4 or IL5, or supported a service on classified networks
  • Have worked on a FedRAMP 20x pilot or built machine-readable evidence or reporting for an assessor
  • Have applied LLMs to compliance work such as control mapping, evidence testing or continuous evidence collection
  • Hold or are eligible for a US security clearance
  • Experience with state and local requirements such as StateRAMP, TX-RAMP, IRS Publication 1075 or CJIS

What the job covers

  • Run the recurring compliance cycles for our US government authorizations (continuous monitoring, POA&M, annual assessments, SSP updates, significant changes and incident notifications), starting with C4G on Palantir FedStart and the NIST SP 800-171 assessment with Schellman
  • Co-own FedRAMP 20x work for Claude Enterprise, and help build new authorizations (first-party FedRAMP High, DoW impact levels, StateRAMP and TX-RAMP) with requirements and evidence work
  • Support model authorizations in GovCloud and Vertex for every model launch, as the GRC member of the Inference and model delivery pod
  • Translate government obligations into partner team requirements, for example vulnerability SLAs in our internal vulnerability reporting platform, and review the evidence
  • Answer public sector customer and deal questions (what a boundary allows, CUI, IRS Publication 1075, CJIS, ITAR), and handle questionnaires and RFIs until they move to Customer Trust
  • Map US government requirements onto the Common Control Framework with the Controls Assurance Lead and keep one source of truth for status
  • Build with Claude: automate mapping, evidence collection and reporting, and verify machine-drafted language before it becomes the record

Tools and skills named

Security & compliance
  • Audit5×
  • Security5×
  • Regulatory
Models & research
  • Inference
  • LLM
Ways of working
  • Testing

Words the posting leans on

  • authorizations12×
  • compliance12×
  • control12×
  • government11×
  • evidence10×
  • requirements10×
  • fedramp7×
  • audit6×
  • changes5×
  • claude5×
  • model5×
  • public sector5×
  • security5×
  • assessment4×
  • boundary4×
  • build4×

Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.

The posting, your resume, and the gaps between them. One click loads all three.

More open at Anthropic

every open role at Anthropic →

How this page was made

An automated read of a public job posting, fetched October 5, 2026 and last changed by Anthropic on October 5, 2026. Every list above is pulled from the posting’s own sentences — nothing rewritten, nothing added, no judgment about the role or the company. Counts and seniority are read off the text by rule, so they can be wrong where the posting is unusual. The original is the only thing that binds. Openings close without warning; check the source before spending an evening on it.