×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Lead Product GRC Subject Matter Expert

Job in San Diego, San Diego County, California, 92189, USA
Listing for: Socket.dev
Full Time position
Listed on 2026-08-19
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 180000 - 240000 USD Yearly USD 180000.00 240000.00 YEAR
Job Description & How to Apply Below

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it.

Vanta for Government (V4G) is how we bring that mission to the public sector. As federal compliance undergoes its biggest shift in a decade — FedRAMP 20x, machine-readable authorization, OSCAL — we're building the platform that turns federal frameworks into automated, continuously monitored product experiences. The GRC Subject Matter Experts on this team are the people who make that possible.

As Vanta's Lead GRC Subject Matter Expert for V4G, you'll own federal compliance content used by every customer pursuing or maintaining federal authorization on our platform. This is an interpretation-and-authoring role, not a compliance program administration role: your job is to interpret underlying control requirements, identify where FedRAMP modifies or constrains the NIST framework, and translate those interpretations into precise, technically testable guidance that engineering can build and customers can act on.

The content you write ships as product — a five-person startup and a Fortune 100 CSP both receive it — so calibrating depth, precision, and universality is the core craft.

You’ll join Vanta's Security organization, which directly influences product development, facilitates the creation of automated GRC solutions for customers, and provides expert advisory services across the company.

What you’ll do as a V4G GRC SME at Vanta:
  • Build and own federal compliance frameworks — Lead the creation, enhancement, and lifecycle management of controls, evidence requirements, and implementation guidance for FedRAMP (Low/Moderate/High), NIST SP 800-53, NIST SP 800-171, CMMC, DFARS, and StateRAMP.
  • Author clear control rationales, acceptance criteria, and customer-facing guidance shipped as out-of-the-box product content.
  • Interpret controls at the mechanics level — Work fluently with 800-53A assessment procedures and 800-53B baselines; resolve organization-defined parameters and FedRAMP's constraints on them; decompose controls into distinct technical obligations; correctly resolve inherited, shared, and customer-owned responsibilities within a customer responsibility matrix; and anchor evidence expectations in authoritative artifacts (PPSM, STIG and CIS hardening standards and their scan outputs across operating systems, databases, network devices, and endpoints).
  • Author automated tests continuous monitoring — Translate controls and infrastructure context (AWS Gov Cloud, Azure Government, GCP, SaaS, endpoints, CI/CD) into spec-level automated tests and detectors. Define test logic, data sources, edge cases, and — critically — failure conditions: how unapproved items, exceptions, missing data, and unevaluated resources affect a
#J-18808-Ljbffr
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary