Supply Chain Security & Assurance Lead
About the role
About Anthropic
Anthropic’s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems.
About the team
The Data Center Security Engineering team owns the security posture of Anthropic-operated data center infrastructure, from the physical facility up to the booted node. As Anthropic moves from cloud tenant to operating our own compute footprint at scale, this team provides the same security interface a hyperscaler would: a fleet of trustworthy, attestable machines with a stated posture per environment.
This role sits in the Security Lifecycle Engineering pillar and owns the supply chain and assurance side of that interface: making sure the hardware that enters the fleet is trustworthy before it arrives, building the systems that prove it continuously, and pushing that bar upstream into the vendor and standards ecosystem so we aren't re-vetting every SKU forever.
About the role
You'll independently scope and lead Anthropic's data center supply chain security function on a 6-12 month horizon, with substantial independence on direction and approach. The footprint is expanding fast across owned facilities, neocloud partners, and international sites; this function does not exist today and you will build both the program and the engineering that backs it.
- Own supply chain risk management and media protection end to end as the subject matter expert: policy and plan, supplier assessment and tiering, contract security requirements, component integrity and disposal standards
- Partner with Legal Security on contract terms and risk acceptance: translate what Anthropic needs into terms vendors can actually meet, find the position that protects us without killing the deal, and own the documented trade when we accept less than the ideal
- Design and build the supplier-risk and hardware approval systems in our data platform: the data model, the scoring logic, and the evidence pipeline that turns vendor assessments and component verdicts into queryable, auditable state that deal-gating and audit consumers depend on
- Lead partner security engagement across the compute portfolio: own the security exhibits, the questionnaire and assessment cycle, and the cadence with neocloud and silicon vendors so platform engineers stay focused on technical vetting rather than vendor meetings
- Drive industry participation that compounds: shepherd hardware vendors through third-party hardware security certification, author and land Anthropic's secure-DC and platform-security requirements with silicon and OEM partners (NVIDIA and others), and represent us in OCP and equivalent forums so the ecosystem does our vetting for us
- Coordinate across security, compliance, legal, and infrastructure teams with minimal senior direction; you set the roadmap for this function and the org follows it
You may be a good fit if you have
- 10+ years in data center hardware operations, supply chain security, or hardware security at hyperscaler scale, with at least the last several spent independently directing a function
- Built and run a data-bearing-device, media protection, or component traceability program from inception, including the tooling and data systems behind it, not just the policy
- Deep, practitioner-level command of supply chain risk management frameworks (NIST 800-161, NIST 800-53 supply chain and media protection control families, or equivalent) and the evidence model auditors expect for them
- A track record of authoring security requirements that landed in vendor and partner contracts and