Supply Chain Security & Assurance Lead

Anthropic Anthropic · AI Frontier · United States · Remote · Security

This role focuses on supply chain security and assurance for data center infrastructure, ensuring hardware is trustworthy from procurement through operation. It involves building systems for supplier assessment, component integrity, and risk management, partnering with legal and vendors, and driving industry standards. The goal is to establish a robust security posture for Anthropic's growing compute footprint.

What you'd actually do

  1. Own supply chain risk management and media protection end to end as the subject matter expert: policy and plan, supplier assessment and tiering, contract security requirements, component integrity and disposal standards
  2. Partner with Legal Security on contract terms and risk acceptance: translate what Anthropic needs into terms vendors can actually meet, find the position that protects us without killing the deal, and own the documented trade when we accept less than the ideal
  3. Design and build the supplier-risk and hardware approval systems in our data platform: the data model, the scoring logic, and the evidence pipeline that turns vendor assessments and component verdicts into queryable, auditable state that deal-gating and audit consumers depend on
  4. Lead partner security engagement across the compute portfolio: own the security exhibits, the questionnaire and assessment cycle, and the cadence with neocloud and silicon vendors so platform engineers stay focused on technical vetting rather than vendor meetings
  5. Drive industry participation that compounds: shepherd hardware vendors through third-party hardware security certification, author and land Anthropic's secure-DC and platform-security requirements with silicon and OEM partners (NVIDIA and others), and represent us in OCP and equivalent forums so the ecosystem does our vetting for us

Skills

Required

  • Data center hardware operations
  • Supply chain security
  • Hardware security
  • Hyperscaler scale experience
  • Data-bearing-device program management
  • Media protection program management
  • Component traceability program management
  • Tooling and data systems development
  • Supply chain risk management frameworks (NIST 800-161, NIST 800-53)
  • Evidence model for auditors
  • Authoring security requirements for contracts
  • Vendor and partner contract negotiation
  • Industry standards bodies participation (OCP or equivalent)
  • Data model design
  • Evidence pipeline design
  • Engineering implementation review
  • Written and verbal communication
  • Cross-functional collaboration (engineering, operations, legal, executive)

Nice to have

  • Directing supply chain security or risk management at a major cloud provider
  • Running security workstream for multi-party hardware programs
  • Building supplier risk tiering systems
  • Building hardware approval systems
  • Hands-on DC site operations
  • Hands-on hardware operations

What the JD emphasized

  • Built and run a data-bearing-device, media protection, or component traceability program from inception, including the tooling and data systems behind it, not just the policy
  • Deep, practitioner-level command of supply chain risk management frameworks (NIST 800-161, NIST 800-53 supply chain and media protection control families, or equivalent) and the evidence model auditors expect for them
  • A track record of authoring security requirements that landed in vendor and partner contracts and held through delivery
  • Experience representing an operator in standards bodies or industry working groups (OCP or equivalent) and changing what those bodies ship
  • Enough engineering depth to design data models and evidence pipelines and review the implementations critically, even when you're not writing every line