Skip to main content
Vanta

Product GRC Subject Matter Expert, (V4G)

RemoteUnited States only
Published
Role
Product
Experience
Lead
Employment
Full-time
Company size
Mid-size
$230k–$270k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Senior GRC/product SME for federal compliance (FedRAMP/NIST/CMMC) who can author machine-readable, testable federal control content and tests. Requires deep FedRAMP/NIST 800-53 experience, OSCAL familiarity, and 8+ years in GRC/InfoSec. U.S. remote role.

Core skills

FedRAMP / NIST 800-53 interpretationOSCAL / machine-readable compliance

Required skills

FedRAMPNIST SP 800-53NIST SP 800-171CMMCDFARSStateRAMPOSCALSSP authoringPPSMSTIGCISAWS GovCloudAzure GovernmentGCPtest designcontinuous monitoringcontrol mappingevidence requirementsPRD authoringLLM/AI-augmented workflows

Optional skills

StateRAMPCNSSI 1253/ICD 503GovCloud or IL-environment architecture experienceprior product/content roles at a GRC platformCISSP-ISSEPCISAFedRAMP 3PAO assessor credentials (CCP/CCA)CISM

What you'll do

  • Build and own federal compliance frameworks: create, enhance, and manage controls, evidence requirements, and implementation guidance for FedRAMP (Low/Moderate/High), NIST SP 800-53, NIST SP 800-171, CMMC, DFARS, and StateRAMP.
  • Interpret controls at the mechanics level: work with 800-53A assessment procedures and 800-53B baselines; decompose controls into technical obligations; resolve inheritance and responsibility matrices; anchor evidence expectations in authoritative artifacts (PPSM, STIG, CIS).
  • Author automated tests & continuous monitoring: translate controls and infrastructure context into spec-level automated tests and detectors; define test logic, data sources, edge cases, and failure conditions; pair with Engineering to implement detectors.
  • Lead V4G's machine-readable future: shape how federal content is architected for OSCAL and FedRAMP 20x, including machine-readable SSPs and continuous authorization workflows.
  • Design crosswalks and mappings: maintain bidirectional crosswalks across federal frameworks with canonical control IDs, mapping confidence, and traceability.
  • Act as a product advisor across discovery & design: partner with PM and Design, review UI/UX for control/evidence workflows, and author PRDs and acceptance criteria.
  • Enable AI-assisted compliance: partner with Engineering/ML to design LLM-powered guidance, translate SME knowledge into machine-readable specs, and define evaluation sets and safety guardrails.
  • Synthesize feedback loops: analyze input from customers, agencies, 3PAOs, and internal teams to identify content gaps and ship updates.
  • Raise the bar: mentor and calibrate other SMEs, set content quality standards and framework strategy.

What they require

  • 8–10+ years in GRC and/or Information Security with hands-on federal compliance work (building or maintaining FedRAMP programs on the CSP side, authoring SSPs and supporting artifacts, and running continuous monitoring).
  • Demonstrated fluency with the NIST 800-53/FedRAMP relationship, 800-53A/B, organization-defined parameters, control inheritance vs. non-applicability, customer responsibility matrices, PPSM, and STIG/CIS benchmarks.
  • Working familiarity with OSCAL or other machine-readable compliance approaches and informed perspective on federal authorization trends (FedRAMP 20x).
  • Ability to design tests: turn controls into functional tests with pass/fail conditions, evidence sufficiency criteria, and coverage across system components.
  • Product mindset: translate requirements into productizable capabilities usable by organizations of every size.
  • Technical & automation experience: active use of AI in GRC work, automations (Sheets/Airtable, APIs, webhooks), and AI-augmented workflows with measured outcomes and safe-use patterns.
  • Analytical & detail-oriented: precise control wording, mapping accuracy, and comfort with spreadsheets and large datasets.
  • Excellent written and verbal communication; ability to collaborate with engineers, designers, GTM teams, agencies, 3PAOs, and customers.
  • Self-motivated and independent: operates autonomously at Lead level.
  • Preferred: DoD impact-level (IL4/IL5) or CMMC experience; StateRAMP, CNSSI 1253/ICD 503, GovCloud or IL-environment architecture experience, or prior product/content roles at a GRC platform.
  • Preferred certifications (not required): CISSP-ISSEP, CISA, FedRAMP 3PAO assessor credentials (CCP/CCA), CISM, or equivalent experience.

Benefits

  • Offers Equity
  • Comprehensive medical, dental, and vision coverage (100% employee-only premiums for most medical plans)
  • This role is also eligible for medical benefits, 401(k) plan, and other company perk programs
  • 16 weeks paid Parental Leave for all new parents
  • Health & wellness stipend
  • Remote workspace, internet, and cellphone stipend
  • Commuter benefits for team members who report to the SF and NYC office
  • Family planning benefits
  • Matching 401(k) contribution with immediate vesting
  • Flexible PTO policy, plus 80 hours of Sick Time
  • 11 company-paid holidays
  • Virtual team building activities, lunch and learns, and other company-wide events
  • Offices in SF, NYC, London, Dublin, Tel Aviv, and Sydney

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. Vanta's Core Platform team provides the foundational infrastructure that powers all engineering at Vanta. We're expanding upmarket to support enterprise customers, which requires strategic investment in platform systems that ensure security, reliability, and developer productivity at scale. As we expand upmarket to support enterprise and regulated customers, we’re investing heavily in platform capabilities that scale securely while reducing cognitive load for product teams.

🇺🇸 United StatesTechnologyMid-size

What people say about this company

2.5/ 5

$230k–$270k/yr