# Lead Product GRC Subject Matter Expert

**Company:** [Vanta](https://hotfix.jobs/companies/vanta)
**Location:** Remote
**Role:** Security Engineering
**Salary:** $230k – $270k/yr
**Experience:** 10+ years
**Skills:** FedRAMP, Nist Sp 800-53, Nist Sp 800-171, Nist Sp 800-53A, Nist Sp 800-53B, Cmmc, Oscal, Aws Govcloud, Azure Government, GCP, Stig, Cis Benchmarks, Ai/Llm, Cross-Framework Mapping, Continuous Monitoring
**Posted:** 2026-08-12

> Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.

## Job Description

## Responsibilities
- Build and own federal compliance frameworks, including FedRAMP Low/Moderate/High, NIST SP 800-53, NIST SP 800-171, CMMC, DFARS, and StateRAMP.
- Author control rationales, acceptance criteria, evidence requirements, implementation guidance, and customer-facing product content.
- Interpret NIST SP 800-53A assessment procedures, NIST SP 800-53B baselines, organization-defined parameters, FedRAMP constraints, inherited responsibilities, shared responsibilities, and customer-owned responsibilities.
- Anchor evidence expectations in PPSM, STIG, and CIS hardening standards and their scan outputs across operating systems, databases, network devices, and endpoints.
- Translate AWS GovCloud, Azure Government, GCP, SaaS, endpoint, and CI/CD contexts into automated tests and detectors with defined data sources, edge cases, and failure conditions.
- Partner with Engineering to implement and maintain detectors with versioned framework mappings.
- Shape OSCAL and FedRAMP 20x capabilities, including machine-readable SSPs, config-as-compliance, and continuous authorization workflows.
- Maintain bidirectional crosswalks across 800-53, 800-171, CMMC, and StateRAMP with canonical control IDs, mapping confidence, and source traceability.
- Partner with Product Management and Design on discovery, UI/UX, PRDs, and acceptance criteria for control, evidence, and authorization workflows.
- Partner with Engineering and ML on LLM-powered federal compliance guidance and automation, gold-standard evaluation sets, and quality and safety guardrails.
- Analyze customer, agency, 3PAO, and internal feedback to identify content gaps and ship iterative updates.
- Mentor and calibrate SMEs, establish content quality standards, and set federal framework strategy.

## Requirements
- 8–10+ years of experience in GRC and/or information security with hands-on federal compliance work.
- Experience building or maintaining FedRAMP programs on the CSP side, authoring SSPs and supporting artifacts, and running continuous monitoring.
- Fluency with the NIST SP 800-53/FedRAMP relationship, NIST SP 800-53A/B, organization-defined parameters, control inheritance, non-applicability, customer responsibility matrices, PPSM, and STIG/CIS benchmarks.
- Working familiarity with OSCAL or other machine-readable compliance approaches and the direction of federal authorization.
- Ability to turn controls into functional tests with defined pass and failure conditions, evidence sufficiency criteria, and system-component coverage.
- Product mindset and ability to translate requirements into capabilities usable by organizations of varying sizes.
- Current use of AI in GRC work, including AI pair-programming tools, lightweight automations, APIs, webhooks, LLM-assisted guidance, cross-framework mapping, and evidence triage.
- Strong analytical, detail-oriented, written, verbal, and cross-functional collaboration skills.
- Ability to work autonomously at Lead level.
- Comfort with spreadsheets and large datasets.

## Nice-to-haves
- DoD impact-level IL4/IL5 or CMMC experience.
- StateRAMP, CNSSI 1253, ICD 503, GovCloud, or IL-environment architecture experience.
- Product or content experience at a GRC platform.
- CISSP-ISSEP, CISA, FedRAMP 3PAO assessor credentials (CCP/CCA), CISM, or equivalent experience.
- Experience applying AI responsibly to improve efficiency and impact.

## Compensation and Benefits
- Industry-competitive salary and equity.
- Comprehensive medical, dental, and vision coverage, with employee-only premiums covered for most medical plans.
- 16 weeks of paid parental leave.
- Health and wellness stipend.
- Remote workspace, internet, and cellphone stipend.
- Commuter benefits for team members reporting to the San Francisco and New York City offices.
- Family planning benefits.
- Matching 401(k) contribution with immediate vesting.
- Flexible PTO, 80 hours of sick time, and 11 company-paid holidays.
- Virtual team-building activities, lunch-and-learns, and company-wide events.

## Similar jobs

- [Senior Engineering Manager, Security](https://hotfix.jobs/jobs/a494d8af-b2c7-4130-8cbb-ccf05cab01be) - Imprint - San Francisco, CA - $220k – $235k/yr
- [Senior Platform Security Engineer](https://hotfix.jobs/jobs/b4b51c15-4c17-4fab-8a56-b0c0bed0254e) - Spade - Remote - $210k – $240k/yr
- [Cyber Operations Lead, Critical Harm Operations](https://hotfix.jobs/jobs/aece8b0b-4900-4762-87e1-025b2cbe75c9) - OpenAI - San Francisco, CA - $252k – $335k/yr
- [Senior Software Engineer - Cloud Security](https://hotfix.jobs/jobs/4c2da306-e1e5-4a5f-9bd4-1504301784bc) - Snowflake - Menlo Park, CA - $200k – $288k/yr
- [Senior Manager - Network and Information Security](https://hotfix.jobs/jobs/9c9131aa-32b1-4bfe-baa8-f13261274796) - Atomicmachines - Emeryville, CA - $200k – $280k/yr

**Apply:** https://hotfix.jobs/jobs/57c937d5-05e3-4033-875a-890645c4aa6b
**Canonical:** https://hotfix.jobs/jobs/57c937d5-05e3-4033-875a-890645c4aa6b