Vanta11 days ago
Product GRC Subject Matter Expert, (V4G)
Salary not specified
MARKET
13,534 ₽median for this role
Tech Lead / Team Lead · 166 jobs with disclosed pay
5,250half of the offers: 9,771–18,1061.2 млн
The employer didn't disclose pay — compare with the market yourself.
Полная занятостьУдалёнка
Responsibilities
- 01Build and own federal compliance frameworks — Lead the creation, enhancement, and lifecycle management of controls, evidence requirements, and implementation guidance for FedRAMP (Low/Moderate/High), NIST SP 800-53, NIST SP 800-171, CMMC, DFARS, and StateRAMP
- 02Author clear control rationales, acceptance criteria, and customer-facing guidance shipped as out-of-the-box product content
- 03Interpret controls at the mechanics level — Work fluently with 800-53A assessment procedures and 800-53B baselines; resolve organization-defined parameters and FedRAMP's constraints on them; decompose controls into distinct technical obligations; correctly resolve inherited, shared, and customer-owned responsibilities within a customer responsibility matrix; and anchor evidence expectations in authoritative artifacts
- 04Author automated tests & continuous monitoring — Translate controls and infrastructure context into spec-level automated tests and detectors
- 05Define test logic, data sources, edge cases, and failure conditions
- 06Pair with Engineering to implement and maintain detectors with versioned framework mappings
- 07Lead V4G's machine-readable future — Shape how Vanta's federal content is architected for OSCAL and FedRAMP 20x
- 08Design crosswalks and mappings — Maintain bidirectional crosswalks across federal frameworks with canonical control IDs, mapping confidence, and traceability to source authority
- 09Act as a product advisor across discovery & design — Partner with the V4G PM and Design on feature discovery, review UI/UX for control, evidence, and authorization workflows, and author PRDs and acceptance criteria
- 10Enable AI-assisted compliance — Partner with Engineering/ML to design LLM-powered guidance and automation for federal workflows
- 11Synthesize feedback loops — Analyze input from customers, agencies, 3PAOs, and internal teams to identify content gaps and ship iterative updates
- 12Raise the bar — Mentor and calibrate other SMEs, set content quality standards for the federal portfolio, and set framework strategy
Requirements
- 018–10+ years in GRC and/or Information Security with hands-on federal compliance work: building or maintaining FedRAMP programs on the CSP side, authoring SSPs and supporting artifacts, and running continuous monitoring
- 02DoD impact-level (IL4/IL5) or CMMC experience is a strong plus
- 03Demonstrated fluency with the NIST 800-53/FedRAMP relationship, 800-53A/B, organization-defined parameters, control inheritance vs. non-applicability, customer responsibility matrices, PPSM, and STIG/CIS benchmarks
- 04Working familiarity with OSCAL or other machine-readable compliance approaches, and an informed point of view on where federal authorization is heading
- 05Ability to turn a control into a functional test with defined pass and failure conditions, evidence sufficiency criteria, and coverage across relevant system components
- 06Ability to translate requirements into productizable capabilities usable by organizations of every size; comfort with experimentation and data-driven prioritization
- 07Active, current use of AI in GRC work: AI pair-programming tools to accelerate specs, mappings, and test logic; lightweight automations across Sheets/Airtable, APIs, and webhooks