Vanta11 days ago

Product GRC Subject Matter Expert, (V4G)

Salary not specified
MARKET
13,534median for this role
Tech Lead / Team Lead · 166 jobs with disclosed pay
5,250half of the offers: 9,771–18,1061.2 млн
The employer didn't disclose pay — compare with the market yourself.
Полная занятостьУдалёнка

Responsibilities

  • 01Build and own federal compliance frameworks — Lead the creation, enhancement, and lifecycle management of controls, evidence requirements, and implementation guidance for FedRAMP (Low/Moderate/High), NIST SP 800-53, NIST SP 800-171, CMMC, DFARS, and StateRAMP
  • 02Author clear control rationales, acceptance criteria, and customer-facing guidance shipped as out-of-the-box product content
  • 03Interpret controls at the mechanics level — Work fluently with 800-53A assessment procedures and 800-53B baselines; resolve organization-defined parameters and FedRAMP's constraints on them; decompose controls into distinct technical obligations; correctly resolve inherited, shared, and customer-owned responsibilities within a customer responsibility matrix; and anchor evidence expectations in authoritative artifacts
  • 04Author automated tests & continuous monitoring — Translate controls and infrastructure context into spec-level automated tests and detectors
  • 05Define test logic, data sources, edge cases, and failure conditions
  • 06Pair with Engineering to implement and maintain detectors with versioned framework mappings
  • 07Lead V4G's machine-readable future — Shape how Vanta's federal content is architected for OSCAL and FedRAMP 20x
  • 08Design crosswalks and mappings — Maintain bidirectional crosswalks across federal frameworks with canonical control IDs, mapping confidence, and traceability to source authority
  • 09Act as a product advisor across discovery & design — Partner with the V4G PM and Design on feature discovery, review UI/UX for control, evidence, and authorization workflows, and author PRDs and acceptance criteria
  • 10Enable AI-assisted compliance — Partner with Engineering/ML to design LLM-powered guidance and automation for federal workflows
  • 11Synthesize feedback loops — Analyze input from customers, agencies, 3PAOs, and internal teams to identify content gaps and ship iterative updates
  • 12Raise the bar — Mentor and calibrate other SMEs, set content quality standards for the federal portfolio, and set framework strategy

Requirements

  • 018–10+ years in GRC and/or Information Security with hands-on federal compliance work: building or maintaining FedRAMP programs on the CSP side, authoring SSPs and supporting artifacts, and running continuous monitoring
  • 02DoD impact-level (IL4/IL5) or CMMC experience is a strong plus
  • 03Demonstrated fluency with the NIST 800-53/FedRAMP relationship, 800-53A/B, organization-defined parameters, control inheritance vs. non-applicability, customer responsibility matrices, PPSM, and STIG/CIS benchmarks
  • 04Working familiarity with OSCAL or other machine-readable compliance approaches, and an informed point of view on where federal authorization is heading
  • 05Ability to turn a control into a functional test with defined pass and failure conditions, evidence sufficiency criteria, and coverage across relevant system components
  • 06Ability to translate requirements into productizable capabilities usable by organizations of every size; comfort with experimentation and data-driven prioritization
  • 07Active, current use of AI in GRC work: AI pair-programming tools to accelerate specs, mappings, and test logic; lightweight automations across Sheets/Airtable, APIs, and webhooks