Lead Product GRC Subject Matter Expert
Job description
About the role
You will own the interpretation and authoritative authorship of federal compliance content that becomes automated product guidance shipped to every Vanta customer pursuing federal authorization. You will translate complex regulatory frameworks into precise, testable controls that engineering can implement and customers can execute against with confidence. This role requires deep fluency in FedRAMP, NIST, and emerging federal mandates so you can define what compliance actually looks like in automated detection and evidence collection. You will work closely with security engineers, product managers, and public sector customers to ensure the content you produce is both technically accurate and practical to implement. Your written guidance will directly shape how organizations design their security programs and prove continuous compliance. You will be responsible for maintaining clarity and consistency across a growing library of federal frameworks and control artifacts. This is a high-impact role where your expertise becomes embedded directly into the platform that agencies and cloud providers rely on.
Key facts
What you'll do
- Build and own federal compliance frameworks by leading the creation, enhancement, and lifecycle management of controls, evidence requirements, and implementation guidance for FedRAMP Low, Moderate, and High, NIST SP 800-53, NIST SP 800-171, CMMC, DFARS, and StateRAMP.
- Interpret controls at the mechanics level by working fluently with 800-53A assessment procedures and 800-53B baselines, resolving organization-defined parameters, and applying FedRAMP constraints on NIST frameworks.
- Decompose controls into distinct technical obligations and correctly resolve inherited, shared, and customer-owned responsibilities within a customer responsibility matrix.
- Anchor evidence expectations in authoritative artifacts such as PPSM, STIG and CIS hardening standards, and their scan outputs across operating systems, databases, network devices, and endpoints.
- Author automated tests and continuous monitoring by translating controls and infrastructure context for AWS GovCloud, Azure Government, GCP, SaaS, endpoints, and CI/CD into spec-level automated tests and detectors.
- Define test logic, data sources, edge cases, and critically, failure conditions, explaining how unapproved items, exceptions, missing data, and unevaluated resources affect a result.
- Lead Vanta's machine-readable future by shaping how federal content is architected for OSCAL and FedRAMP 20x, including machine-readable SSPs, config-as-compliance, and continuous authorization workflows.
- Design and maintain bidirectional crosswalks across federal frameworks such as 800-53, 800-171, CMMC, and StateRAMP with canonical control IDs, mapping confidence, and traceability to source authority.
- Act as a product advisor during discovery and design by partnering with the V4G PM and Design team to review UI/UX for control, evidence, and authorization workflows.
- Author product requirements and acceptance criteria grounded in the needs of agencies, auditors, and 3PAOs to ensure feature readiness for federal customers.
- Enable AI-assisted compliance by partnering with Engineering and ML teams to design LLM-powered guidance and automation for federal workflows.
- Translate subject matter expertise into machine-readable specifications, define gold-standard evaluation sets, and implement quality and safety guardrails for automated guidance.
- Synthesize feedback loops by analyzing input from customers, government agencies, 3PAOs, and internal teams to identify content gaps and ship iterative updates quickly and safely.
- Raise the bar by mentoring and calibrating other subject matter experts, setting content quality standards for the federal portfolio, and defining framework strategy that others execute against.
Requirements
- Demonstrate 8-10+ years in GRC and/or Information Security with hands-on federal compliance work, including building or maintaining FedRAMP programs on the CSP side, authoring SSPs and supporting artifacts, and running continuous monitoring.
- Show evidence of working with 800-53A assessment procedures and 800-53B baselines, including the ability to resolve organization-defined parameters and apply FedRAMP constraints.
- Prove experience decomposing controls into distinct technical obligations and resolving shared, inherited, and customer-owned responsibilities within responsibility matrices.
- Provide examples of anchoring evidence expectations in authoritative artifacts such as PPSM, STIG and CIS hardening standards, and their scan outputs across operating systems, databases, network devices, and endpoints.
- Highlight experience translating controls and infrastructure context into automated test specifications for environments such as AWS GovCloud, Azure Government, GCP, SaaS, endpoints, and CI/CD.
- Illustrate how you have defined test logic, data sources, edge cases, and failure conditions, including how unapproved items, exceptions, missing data, and unevaluated resources affect results.
- Show a track record of working toward machine-readable compliance through OSCAL and FedRAMP 20x initiatives, including authoring machine-readable SSPs or config-as-compliance artifacts.
- Demonstrate experience designing crosswalks across federal frameworks with canonical control IDs, mapping confidence, and traceability to source authority.
Nice to have
- Prior experience as a product advisor on feature discovery and design sessions with agency PMs, security architects, and 3PAOs.
- Experience authoring PRDs and acceptance criteria that reflect the needs of auditors and assessors.
- Background in AI-assisted compliance, including designing evaluation sets and quality guardrails for LLM-generated guidance.
- DoD impact-level (IL4/IL5) or CMMC experience.
Practical notes
This role is fully remote within the United States and requires full-time engagement. No specific working hours are mandated beyond standard collaboration windows with distributed teams. Travel is not required. No visa sponsorship is provided for this position.