SlipstreamJobsFresh Startup & VC-Backed Jobs

Lead Product GRC Subject Matter Expert

Vanta - Remote - Remote - posted 2026-08-12

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Vanta is building the platform that automates federal compliance and continuous monitoring for government contractors and cloud service providers. As Lead GRC Subject Matter Expert for Vanta for Government (V4G), you will own the federal compliance content—FedRAMP, NIST 800-53/171, CMMC, DFARS, StateRAMP—that ships as product to customers ranging from startups to Fortune 100 companies. This is a content interpretation and authoring role, not compliance program administration. You will interpret control requirements at the mechanics level, identify where FedRAMP constrains NIST frameworks, and translate those interpretations into precise, technically testable guidance that engineering can build and customers can act on. Key responsibilities include: building and owning federal compliance frameworks with clear control rationales and customer-facing guidance; interpreting controls fluently with 800-53A assessment procedures and 800-53B baselines; authoring automated tests and continuous monitoring specs that translate controls into testable logic with defined pass/failure conditions; leading V4G's machine-readable future (OSCAL, FedRAMP 20x, config-as-compliance); designing and maintaining crosswalks across federal frameworks; partnering with product and design on feature discovery and UX review; enabling AI-assisted compliance by translating SME knowledge into machine-readable specs; synthesizing feedback from customers, agencies, 3PAOs, and internal teams; and mentoring other SMEs to raise content quality standards. You will work directly with engineering, product, and design to ship iterative updates quickly and safely. The role requires fluency with infrastructure contexts (AWS GovCloud, Azure Government, GCP, SaaS, endpoints, CI/CD) and the ability to define test logic, data sources, edge cases, and failure conditions. Success requires 8–10+ years in GRC and information security with hands-on federal compliance experience: building or maintaining FedRAMP programs on the CSP side, authoring SSPs and supporting artifacts, and running continuous monitoring. DoD impact-level (IL4/IL5) or CMMC experience is a strong plus. You should demonstrate fluency with NIST 800-53/FedRAMP relationships, 800-53A/B, organization-defined parameters, control inheritance, customer responsibility matrices, PPSM, and STIG/CIS benchmarks. Working familiarity with OSCAL or machine-readable compliance approaches is expected. You must have test-design rigor, a product mindset, and active use of AI tools in GRC work.

Similar roles