Security GRC Specialist, Public Sector
Listed on 2026-01-23
-
IT/Tech
Cybersecurity -
Government
Cybersecurity
About Anthropic
Anthropic’s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems.
About The TeamAs part of the Anthropic security department, the compliance team owns understanding security and AI safety expectations, as established by regulators, customers and (nascent) industry norms (which we also seek to influence). The compliance team uses this understanding to provide direction to internal partners on the priorities of security and safety requirements they must meet. The compliance team assures regulators and customers that those expectations are met by earning security credentials and responding to direct inquiry about Anthropics security program from auditors, customers and partners.
This opportunity is unique, as we work to secure today’s most novel and valuable asset types, we must build a new kind of compliance program, assuring the safety of artificial intelligence capabilities.
Responsibilities- Lead complex federal authorization efforts including FedRAMP ATOs (Low, Moderate, High), DoD Impact Level authorizations (IL4, IL5, IL6), and Intelligence Community security compliance programs
- Serve as the compliance DRI for one or more strategic public sector initiatives:
DoD/CMMC programs, National Security/IC deployments, or State & Local Government/EDU certifications - Navigate multi-stakeholder authorization processes, coordinating with Government Authorizing Officials, Third-Party Assessment Organizations (3
PAOs), and internal engineering/product teams - Translate government security frameworks (NIST 800-53, NIST 800-171, CNSSI 1253, ICD 503, FedRAMP baselines) into actionable technical requirements for cloud-native AI infrastructure
- Build and maintain authorization artifacts including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action & Milestones (POA&Ms), and continuous monitoring documentation
- Establish scalable ATO processes that can support multiple simultaneous authorizations across different classification levels and government agencies
- Collaborate with product and engineering teams to implement technical controls that satisfy government security requirements while enabling AI innovation
- Maintain authorization posture through continuous monitoring, annual assessments, and change management processes aligned with government requirements
- Have 8+ years of progressive GRC experience with at least 3+ years directly leading federal authorization efforts (FedRAMP, DoD, IC, or equivalent)
- Have hands‑on experience shepherding at least one initial ATO lifecycle from planning through authorization and subsequent continuous monitoring
- Possess deep working knowledge of NIST 800‑53 and can map controls to technical implementations in cloud environments
- Have worked with government authorization stakeholders including AOs, 3
PAOs, ISSOs, ISSMs, and understand the federal ATO ecosystem - Can translate between government compliance language and engineering requirements, making complex mandates actionable for technical teams
- Have experience with cloud‑native security architectures (e.g., AWS Gov Cloud) and understand how to achieve government compliance in modern infrastructure
- Write exceptionally clear documentation that satisfies both government auditors and technical implementers
- Thrive in high‑stakes, deadline‑driven environments where authorization timelines directly impact business outcomes
- Are energized by being the subject matter expert who guides the organization through complex government compliance landscapes
- Have active Secret or Top Secret clearance (or TS/SCI for IC‑focused roles)
- Bring multi‑domain public sector experience (e.g., both DoD and Civilian agencies, or Federal and SLED)
- Possess experience with classified system authorizations or cross‑domain solutions
- Have worked in AI/ML companies navigating novel compliance challenges for emerging technology
- Understand…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).