Commercial Counsel, Infrastructure Security

Anthropic Anthropic · AI Frontier · San Francisco, CA · Legal

Commercial Counsel, Infrastructure Security for Compute and Infrastructure at Anthropic. This role partners with the Chief Security Officer's infrastructure-security and GRC teams, owning the contractual and regulatory aspects of physical and facility security, hardware and supply-chain security, network security, vendor personnel and insider-risk, and security regulatory and assurance. Responsibilities include drafting and negotiating security specifications, owning provenance and anti-tamper warranties, setting background-screening requirements, supporting CFIUS and outbound-investment screening, and advising on risk assessments and the evolving regulatory landscape.

What you'd actually do

  1. Draft and negotiate security design-basis and site-hardening specifications in build-to-suit, lease, and colo agreements (perimeter, access control, CCTV, intrusion detection); guard-force statements of work, post orders, and KPI regimes; visitor, contractor, and badging policy; and security clauses in shared-campus and multi-tenant arrangements
  2. Own provenance, anti-tamper, and chain-of-custody warranties in silicon, ODM, and OEM paper; trusted-supplier and country-of-origin restrictions; NDAA §889/§5949 and CHIPS-Act guardrail flow-downs; BIS/EAR advanced-computing and semiconductor export-control flow-downs and end-use/end-user certifications; firmware integrity, secure-boot, and golden-image escrow terms; secure logistics; counterfeit-part and grey-market controls; and secure decommissioning and certified media-destruction terms
  3. Draft security schedules in carrier and fiber agreements (encryption-in-transit, route integrity, lawful-intercept handling), and security obligations in peering agreements
  4. Set background-screening, training, and badge-revocation requirements for vendor and contractor personnel with site or hardware access, and flow Anthropic personnel-security standards into guard-force, security-integrator, and EPC vendor MSAs
  5. Support CFIUS and outbound-investment screening on infrastructure vendors and sites, provide NIST/ISO/SOC 2 physical-control evidence for customer and auditor assurance in partnership with security teams; and support security representations in customer contracts that reference physical infrastructure with Commercial Legal

Skills

Required

  • JD and active membership in at least one U.S. state bar
  • Fluency in security design-basis specifications, guard-force and access-control contracting, and how security schedules interact with build-to-suit, colo, procurement, and carrier agreements
  • Experience with NDAA §889/§5949, CHIPS-Act guardrails, CFIUS/outbound-investment screening, and trusted-supplier or country-of-origin programs
  • Comfort with NIST, ISO 27001, and SOC 2 physical-control frameworks and the evidence and attestation process that supports customer and auditor assurance
  • Ability to coordinate effectively with multiple internal legal teams, and specialized outside counsel while maintaining strategic direction
  • Strong judgment about when contractual security terms create downstream risk for Anthropic’s security posture, audit position, or operational flexibility
  • Effective collaboration skills for working with the CSO’s organization, procurement, datacenter, and network teams
  • Communication skills that translate security and supply-chain-integrity concepts into clear risk assessments for business stakeholders
  • Genuine interest in infrastructure security and appreciation for why physical, hardware, and network security is mission-critical for frontier AI

Nice to have

  • At least 10-12 years of relevant legal experience with meaningful exposure to physical and facility security contracting, hardware and supply-chain

What the JD emphasized

  • security design-basis
  • guard-force
  • NDAA §889/§5949
  • CHIPS-Act guardrail flow-downs
  • CFIUS
  • NIST/ISO/SOC 2 physical-control