Назад
2 часа назад

US Public Sector Compliance, Security GRC

255 000 - 270 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
US Public Sector Compliance, Security GRC (AI security compliance): Running US government authorization and ongoing compliance programs for Anthropic's AI services with an accent on FedRAMP, DoD, CMMC, NIST, StateRAMP, and evidence-based controls. Focus on translating government requirements into engineering requirements, reviewing control evidence, maintaining authorization boundaries, and automating compliance mapping and reporting with Claude.

Location: San Francisco, CA or New York City, NY; hybrid attendance in an Anthropic office at least 25% of the time

Annual salary: $255,000–$270,000 USD

Company

Anthropic builds reliable, interpretable, and steerable AI systems intended to be safe and beneficial for users and society.

What you will do

  • Run recurring compliance cycles for US government authorizations, including continuous monitoring, POA&M, annual assessments, SSP updates, significant changes, and incident notifications.
  • Co-own FedRAMP 20x work for Claude Enterprise and support new FedRAMP High, DoD, StateRAMP, and TX-RAMP authorizations.
  • Support model authorizations in GovCloud and Vertex for model launches and work with inference and model delivery engineering pods.
  • Translate government obligations into specific engineering requirements, review evidence, and determine whether launches are ready for government boundaries.
  • Answer public-sector customer questions and handle questionnaires and RFIs involving CUI, IRS Publication 1075, CJIS, and ITAR.
  • Map government requirements to the Common Control Framework and automate compliance mapping, evidence collection, and reporting with Claude.

Requirements

  • Several years of security compliance or IT audit experience involving US government compliance for a cloud service and post-authorization cycles.
  • Working command of the NIST SP 800-53 Moderate baseline, authorization boundaries, control implementation statements, assessments, continuous monitoring, POA&M, and significant changes.
  • Experience writing requirements for engineering teams and reviewing evidence returned by those teams.
  • Knowledge of how GovCloud- or Vertex-style government regions differ from commercial environments and how model, feature, or region changes affect an authorized boundary.
  • Technical fluency sufficient to read runbooks, configurations, or pipeline definitions and assess whether they enforce controls.
  • Clear writing and the ability to drive partner teams to complete compliance work without direct authority.

Nice to have

  • Experience taking a service through FedRAMP High, DoD IL4 or IL5, or classified networks.
  • Experience with FedRAMP 20x pilots, machine-readable evidence, or assessor reporting.
  • Experience applying LLMs to control mapping, evidence testing, or continuous evidence collection.
  • US security clearance or eligibility for one.
  • Experience with StateRAMP, TX-RAMP, IRS Publication 1075, or CJIS.

Culture & Benefits

  • Hybrid work with staff expected to work from an Anthropic office at least 25% of the time.
  • Visa sponsorship is available, with reasonable efforts and immigration-lawyer support for successful candidates.
  • Competitive compensation, optional equity donation matching, generous vacation and parental leave, and flexible working hours.
  • Collaborative environment focused on trustworthy AI, communication, and high-impact research.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →