
Lead Product GRC Subject Matter Expert
Jobgether • US
No Relocation
Posted: August 13, 2026
Additional Content
Job Description
- This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Lead Product GRC Subject Matter Expert based in the United States. This is a senior-level opportunity to shape how federal compliance is translated into an automated product experience. You will own compliance content spanning FedRAMP, NIST, CMMC, DFARS, and StateRAMP, with direct influence on product capabilities. The role combines deep GRC expertise with technical product thinking, automation, and machine-readable compliance. You will turn complex regulatory requirements into precise controls, evidence expectations, automated tests, and customer guidance. Working closely with Product, Engineering, Design, ML, customers, agencies, and assessment organizations, you will help define the future of continuous authorization. Your work will serve organizations ranging from emerging companies to large enterprises, making accuracy, scalability, and usability critical. This is a highly autonomous role for a builder who wants to establish standards, influence strategy, and mentor other compliance experts.
- Accountabilities: Own federal compliance frameworks: Lead the creation, enhancement, and lifecycle management of controls, evidence requirements, implementation guidance, rationales, acceptance criteria, and customer-facing content across FedRAMP Low/Moderate/High, NIST SP 800-53, NIST SP 800-171, CMMC, DFARS, and StateRAMP. Interpret controls at a technical level: Analyze NIST 800-53A/B assessment procedures, baselines, organization-defined parameters, control inheritance, shared responsibilities, and customer-owned responsibilities, while grounding evidence requirements in authoritative standards such as PPSM, STIG, and CIS benchmarks. Design automated compliance tests: Translate regulatory controls and infrastructure environments such as AWS GovCloud, Azure Government, GCP, SaaS, endpoints, and CI/CD systems into functional tests and detectors with clearly defined data sources, edge cases, pass conditions, and failure scenarios. Partner with Engineering: Collaborate on the implementation and maintenance of automated detectors, framework mappings, and versioned compliance logic, ensuring technical solutions accurately reflect regulatory requirements. Shape machine-readable compliance: Help define how federal compliance content can support OSCAL, FedRAMP 20x, machine-readable System Security Plans, configuration-as-compliance, and continuous authorization workflows. Develop cross-framework mappings: Maintain accurate, traceable bidirectional crosswalks between frameworks such as NIST 800-53, NIST 800-171, CMMC, and StateRAMP, including canonical identifiers and mapping confidence. Influence product development: Partner with Product and Design on discovery, feature definition, PRDs, acceptance criteria, and user experiences for controls, evidence, and authorization workflows. Enable AI-assisted compliance: Work with Engineering and ML teams to translate subject-matter expertise into machine-readable specifications, LLM-powered guidance, evaluation datasets, automation workflows, and appropriate quality and safety controls. Build continuous feedback loops: Analyze input from customers, agencies, assessment organizations, and internal stakeholders to identify gaps and prioritize accurate, timely content improvements. Set standards and mentor others: Establish quality standards for federal compliance content, calibrate other SMEs, mentor team members, and define framework strategy for the broader portfolio. Requirements: Federal GRC experience: 8–10+ years of experience in GRC and/or information security, including substantial hands-on federal compliance work such as building or maintaining FedRAMP programs, authoring SSPs and supporting artifacts, and managing continuous monitoring. Deep federal compliance knowledge: Strong understanding of the relationship between NIST SP 800-53 and FedRAMP, including 800-53A/B, organization-defined parameters, control inheritance and non-applicability, customer responsibility matrices, PPSM, STIGs, and CIS benchmarks. Builder mindset: Experience creating and operationalizing compliance content is essential; candidates whose experience is primarily limited to third-party assessment or compliance program coordination may be less suited to the product-building nature of the role. OSCAL and FedRAMP 20x familiarity: Working knowledge of OSCAL or other machine-readable compliance approaches, along with an informed perspective on the evolution of federal authorization. Test-design expertise: Ability to convert regulatory controls into functional tests with clear pass/fail conditions, evidence sufficiency criteria, and appropriate system-component coverage. Product orientation: Ability to translate complex requirements into scalable product capabilities that can serve organizations of different sizes, with comfort using experimentation and data to guide prioritization. Technical and automation skills: Fluency with APIs, automation, spreadsheets, datasets, and related technical workflows, with current experience using AI tools to accelerate specifications, mappings, test logic, evidence analysis, or compliance guidance. AI proficiency: Demonstrated ability to use AI responsibly in GRC workflows, including LLM-assisted analysis, control mapping, evidence triage, automation, and agent-based workflows, with appropriate quality and safety safeguards. Analytical precision: Exceptional attention to detail, particularly around control language, framework mappings, evidence requirements, traceability, and large datasets. Communication and collaboration: Excellent written and verbal communication skills, with the ability to work effectively with engineers, designers, product teams, go-to-market stakeholders, government agencies, assessment organizations, and customers. Leadership and autonomy: Ability to operate independently at Lead level, establish direction in ambiguous environments, influence stakeholders, and mentor other subject-matter experts. Preferred experience: Familiarity with StateRAMP, CNSSI 1253, ICD 503, GovCloud or Impact Level environments, or prior product/content work within a GRC platform is advantageous. Preferred certifications: CISSP-ISSEP, CISA, CISM, FedRAMP 3PAO assessor credentials such as CCP/CCA, or equivalent professional experience are valued but not required. Growth mindset: Curiosity and willingness to use emerging AI capabilities to improve efficiency, quality, and impact while applying sound judgment and responsible practices. Benefits: Cash compensation: $230,000–$270,000 base salary range, plus equity. Comprehensive medical, dental, and vision coverage, with employee-only premiums fully covered for most medical plans. 16 weeks of paid parental leave for all new parents. Health and wellness stipend. Remote workspace, internet, and cellphone stipends. Flexible PTO policy plus 80 hours of paid sick time. 11 company-paid holidays. Family planning benefits. 401(k) matching with immediate vesting. Commuter benefits for employees who use designated offices. Virtual team-building activities, lunch-and-learn sessions, and company-wide events. Remote-first work environment with access to offices in San Francisco, New York City, London, Dublin, Tel Aviv, and Sydney. Compensation may vary based on location, skills, experience, and relevant credentials.
- How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1
- We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
- apply for this job