Lead Product GRC Subject Matter Expert

Vanta
United States
Workplace: RemoteFull timeUSD 230,000 - 270,000 annuallyFunction: Administration & Executive AssistanceExperience: 8-10 yearsSkills: ["Written and verbal communication","Analytical thinking","Attention to detail","Collaboration","Self-motivation"]

Own federal compliance content that powers automated, continuously monitored product experiences for Vanta’s public-sector platform. Interpret FedRAMP and its constraints on the NIST framework, decompose controls into technically testable guidance, and translate them into product shipped guidance and spec-level automated tests/detectors. Lead framework mappings across FedRAMP, NIST 800-53/800-171, CMMC, and StateRAMP while partnering with Engineering, Design, and ML on machine-readable OSCAL workflows.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Vanta
Vanta
1 day ago

Lead Product GRC Subject Matter Expert

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 6 hours agoStatus: Live

Job Summary

Own federal compliance content that powers automated, continuously monitored product experiences for Vanta’s public-sector platform. Interpret FedRAMP and its constraints on the NIST framework, decompose controls into technically testable guidance, and translate them into product shipped guidance and spec-level automated tests/detectors. Lead framework mappings across FedRAMP, NIST 800-53/800-171, CMMC, and StateRAMP while partnering with Engineering, Design, and ML on machine-readable OSCAL workflows.
Location: United States
Workplace: Remote
Employment Type: Full time
Job Function: Administration & Executive Assistance
Seniority: Sr. Manager level

Key Responsibilities

  • •Build and own federal compliance frameworks by creating and maintaining controls, evidence requirements, and implementation guidance for FedRAMP (Low/Moderate/High), NIST SP 800-53, NIST SP 800-171, CMMC, DFARS, and StateRAMP.
  • •Interpret controls at the mechanics level by working with 800-53A assessment procedures and 800-53B baselines and translating constraints into technically testable obligations.
  • •Author automated tests and continuous monitoring detectors by defining test logic, data sources, edge cases, and failure conditions, and pairing with Engineering to maintain framework version mappings.
  • •Lead V4G’s machine-readable future by shaping how federal content is architected for OSCAL and FedRAMP 20x, including machine-readable SSPs and continuous authorization workflows.
  • •Maintain crosswalks and mappings across federal frameworks (800-53 ↔ 800-171 ↔ CMMC ↔ StateRAMP) with canonical control IDs, traceability, and mapping confidence.

Pay and Benefits

Salary: USD 230,000 - 270,000 annually
Equity and Bonus:Equity
Perks:Health InsuranceDentalVision401kParental LeaveRemote Work

Key Requirements

  • •8–10+ years in GRC and/or information security with hands-on federal compliance work, including building or maintaining FedRAMP programs on the CSP side.
  • •Fluency with the NIST 800-53/FedRAMP relationship, 800-53A/B, organization-defined parameters, control inheritance, and customer responsibility matrices.
  • •Working familiarity with OSCAL or other machine-readable compliance approaches and an informed point of view on where federal authorization is heading.
  • •Ability to turn a control into functional test logic with clear pass/failure conditions, evidence sufficiency criteria, and coverage across system components.
  • •Experience authoring or interpreting federal compliance content/deliverables with precise control wording, mapping accuracy, and evidence specificity.
Experience:8-10 yearsGRCInformation securityFederal complianceFedRAMPOSCALMachine-readable compliance
Skills:Written and verbal communicationAnalytical thinkingAttention to detailCollaborationSelf-motivation
Certifications:CISSP-ISSEPCISAFedRAMP 3PAO assessor credentials (CCP/CCA)CISM
Tech Stack:FedRAMPNIST SP 800-53NIST SP 800-171800-53A800-53BCMMCDFARSStateRAMPOSCALSSPPPSMSTIGCIS hardeningCISAWS GovCloudAzure GovernmentGCPSaaSCI/CDAPIs

Company Brief

Vanta
Provides automated security and compliance software that helps companies achieve and maintain SOC 2, ISO 27001, and other security certifications by continuously monitoring systems, controls, and evidence.
Industry: Cybersecurity
Company Size: Large (251 to 1,000 employees)
Growth: Scaleup
Valuation: Unicorn (USD 1B+)
Funding: Series D
Headquarters: San Francisco, United States
Founded: 2017
WebsiteLinkedIn