Lead Product GRC Subject Matter Expert
Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.
About the job
Responsibilities
- Build and own federal compliance frameworks, including FedRAMP Low/Moderate/High, NIST SP 800-53, NIST SP 800-171, CMMC, DFARS, and StateRAMP.
- Author control rationales, acceptance criteria, evidence requirements, implementation guidance, and customer-facing product content.
- Interpret NIST SP 800-53A assessment procedures, NIST SP 800-53B baselines, organization-defined parameters, FedRAMP constraints, inherited responsibilities, shared responsibilities, and customer-owned responsibilities.
- Anchor evidence expectations in PPSM, STIG, and CIS hardening standards and their scan outputs across operating systems, databases, network devices, and endpoints.
- Translate AWS GovCloud, Azure Government, GCP, SaaS, endpoint, and CI/CD contexts into automated tests and detectors with defined data sources, edge cases, and failure conditions.
- Partner with Engineering to implement and maintain detectors with versioned framework mappings.
- Shape OSCAL and FedRAMP 20x capabilities, including machine-readable SSPs, config-as-compliance, and continuous authorization workflows.
- Maintain bidirectional crosswalks across 800-53, 800-171, CMMC, and StateRAMP with canonical control IDs, mapping confidence, and source traceability.
- Partner with Product Management and Design on discovery, UI/UX, PRDs, and acceptance criteria for control, evidence, and authorization workflows.
- Partner with Engineering and ML on LLM-powered federal compliance guidance and automation, gold-standard evaluation sets, and quality and safety guardrails.
- Analyze customer, agency, 3PAO, and internal feedback to identify content gaps and ship iterative updates.
- Mentor and calibrate SMEs, establish content quality standards, and set federal framework strategy.
Requirements
- 8–10+ years of experience in GRC and/or information security with hands-on federal compliance work.
- Experience building or maintaining FedRAMP programs on the CSP side, authoring SSPs and supporting artifacts, and running continuous monitoring.
- Fluency with the NIST SP 800-53/FedRAMP relationship, NIST SP 800-53A/B, organization-defined parameters, control inheritance, non-applicability, customer responsibility matrices, PPSM, and STIG/CIS benchmarks.
- Working familiarity with OSCAL or other machine-readable compliance approaches and the direction of federal authorization.
- Ability to turn controls into functional tests with defined pass and failure conditions, evidence sufficiency criteria, and system-component coverage.
- Product mindset and ability to translate requirements into capabilities usable by organizations of varying sizes.
- Current use of AI in GRC work, including AI pair-programming tools, lightweight automations, APIs, webhooks, LLM-assisted guidance, cross-framework mapping, and evidence triage.
- Strong analytical, detail-oriented, written, verbal, and cross-functional collaboration skills.
- Ability to work autonomously at Lead level.
- Comfort with spreadsheets and large datasets.
Nice-to-haves
- DoD impact-level IL4/IL5 or CMMC experience.
- StateRAMP, CNSSI 1253, ICD 503, GovCloud, or IL-environment architecture experience.
- Product or content experience at a GRC platform.
- CISSP-ISSEP, CISA, FedRAMP 3PAO assessor credentials (CCP/CCA), CISM, or equivalent experience.
- Experience applying AI responsibly to improve efficiency and impact.
Compensation and Benefits
- Industry-competitive salary and equity.
- Comprehensive medical, dental, and vision coverage, with employee-only premiums covered for most medical plans.
- 16 weeks of paid parental leave.
- Health and wellness stipend.
- Remote workspace, internet, and cellphone stipend.
- Commuter benefits for team members reporting to the San Francisco and New York City offices.
- Family planning benefits.
- Matching 401(k) contribution with immediate vesting.
- Flexible PTO, 80 hours of sick time, and 11 company-paid holidays.
- Virtual team-building activities, lunch-and-learns, and company-wide events.
Skills
FedRAMP, Nist Sp 800-53, Nist Sp 800-171, Nist Sp 800-53A, Nist Sp 800-53B, Cmmc, Oscal, Aws Govcloud, Azure Government, GCP, Stig, Cis Benchmarks, Ai/Llm, Cross-Framework Mapping, Continuous Monitoring
Similar jobs
Security Engineering jobsLeads a hands-on security engineering function spanning AI security, application and cloud security, detection and response, identity, and compliance controls. The role requires 8+ years of security engineering experience, deep AWS expertise, production code review ability, and experience operating in PCI DSS scope.
Owns production-edge security for enterprise financial-institution connectivity, including PKI, mTLS, AWS networking, webhook security, and vulnerability remediation. Requires 6+ years of hands-on platform, infrastructure, or network security engineering experience.
Leads cybersecurity and cyber intelligence operations for high-risk user-safety decisions, combining strategic planning, operational systems, automation, and direct people management. Requires 8+ years in cybersecurity-related work and 4+ years leading teams.
Build secure, large-scale platforms, controls, monitoring, and AI-augmented pipelines that improve Snowflake’s cloud security posture across hundreds of millions of assets and multiple cloud providers. Requires 5+ years of software engineering experience and expertise in secure distributed systems.
Leads enterprise network architecture, cloud connectivity, security, operations, and incident response across corporate and manufacturing environments. Requires 10+ years of network engineering experience, people leadership, AWS networking expertise, and strong network security knowledge.