Trigger
Vanta posted Head of Design on Ashby (July 6, remote US, $365K–$513K) while its current VP/Head of Design appears to have departed. Three independent signals point to backfill.
The signal chain. Deb Kawamoto, Vanta's VP/Head of Design, still shows up on Vanta's design careers page and her personal site. But the Design Executive Council now labels her "Fmr. VP of Design at Vanta." DEC profiles are self-reported. Her LinkedIn has gone quiet for roughly four months. The posting scope matches her full org: ~40 designers across GRC, Trust, Platform, Self-serve, and AI.
Confidence: moderate-high this is a backfill. Three independent signals converging. Not confirmed. Strong enough to move on.
Window
Thirteen days into a VP-level backfill at a $4.15B company with $300M+ ARR. The recruiter pipeline is filling now.
Backfills reward early movers for a specific reason: the hiring committee already knows what they lost and what they need next. Criteria are fresh, not drifted. Early outreach converts better because the committee's picture of the role is still sharp. Waiting for the org picture to resolve publicly means competing against candidates who moved while you were still confirming.
What this trigger probably means for the design org
Deb built the design function at Vanta. Her DEC profile describes setting the quality bar, investing in design systems, partnering with engineering and product. The org infrastructure exists. The leader is gone. They need someone who can inherit a functioning 40-person team, hold the craft bar, and push it into what comes next.
What comes next is already shipping. Vanta launched the Agent for Risk in June, built on their Trust Graph across 400+ integrations. The posting asks for "AI-native product experiences," "agentic UX patterns," and "definitions of done." Read that cluster. A compliance platform whose core product is becoming an agent needs a design leader who understands every surface the agent touches. Where does the human verify. What's reversible. What requires signoff before the agent proceeds.
Your angle
Narrative fit: Your Trust essay names the design problems this posting describes, in the vocabulary this company already uses. Vanta's compliance officers need to trust what an agent surfaces enough to act on it in sixty seconds. You designed that trust architecture at Alibaba at $50B+ GMV scale (−47% buyer security concerns, +20% daily transactions) and documented the pattern across domains. No other candidate walks in with a published framework that maps directly to agentic GRC and the shipped portfolio proof behind it.
Lead with the Trust essay. Alibaba is your proof.
Thermo Fisher is your secondary, and it's operationally closer to Vanta's daily reality than it looks. The 197-orders-surface-the-3-that-matter pattern from mySupply is the same design problem as a risk dashboard surfacing drifting controls across hundreds of vendors. Exception-first design in a compliance workflow where catching the problem a week earlier costs 3–5× less than catching it at the gate. For a GRC company, that's an operational match.
TinyFish amplifies both. You're building enterprise AI agents in production daily, working through agent traces, auditability, and governance firsthand. That practitioner depth separates you from candidates who've designed around AI but haven't shipped with it.
Who to contact
Name: Jeremy Epling, Chief Product Officer. Owns engineering, product, and design. Reports to CEO Christina Cacioppo. LinkedIn.
Public fingerprint: Jeremy appeared on First Round's Executive Function podcast in March 2026. Key phrase worth mirroring: "ICs are your company's influencers." He wants individual contributors reaching VP-level impact. He's doing a Vanta Community Q&A later this month on product direction and leadership philosophy. Before Vanta, he led GitHub Actions from zero to millions of developers, including supply-chain security and provenance for npm. Security-adjacent product scaling is his native context.
Warm path: Cold by default. No confirmed overlap between your network (BCG DV, Alibaba, ADPList) and Vanta's executive team from public sources. Check your LinkedIn for mutuals through Jeremy's GitHub/Microsoft network or Vanta's investor base (Sequoia, Craft, YC, Atlassian Ventures). If you find one, use them for the introduction. Don't burn the mutual as a hook.
Channel: LinkedIn cold DM to Jeremy. He's publicly active, recently engaged with podcast and community content.
Outreach messages
Subject line: The trust handoff problem in agentic GRC
Warm message (if a mutual surfaces):
Jeremy, your Executive Function point about ICs being a company's influencers landed. The design version of that problem at Vanta right now is the trust handoff: when the Agent for Risk surfaces a drifting control, the compliance officer staring at that finding needs to trust what the system produced enough to act on it in sixty seconds. I've spent the last decade designing that exact moment across high-stakes systems, most recently at Alibaba where I rebuilt enterprise procurement trust architecture at $50B+ GMV. I mapped the pattern into a framework: junochen.com/trust-is-the-new-interface. [Mutual name] suggested I reach out — would 20 minutes on how trust architecture changes when the product becomes the agent be useful?
Cold message:
Jeremy, before Vanta you built provenance and supply-chain security for npm — giving developers a reason to trust that the package they pulled was the package they expected. That's a trust-handoff problem. The design version of it now sits inside Vanta's agentic shift: when the Agent for Risk recommends a control to prioritize, the risk owner needs enough provenance to act, not just enough data to review. I've been designing that handoff in high-stakes enterprise systems for a decade. The pattern is documented here: junochen.com/trust-is-the-new-interface. Would 20 minutes on what "definitions of done" look like when the product is an agent be worth your time?
What not to say:
- Do not reference Deb Kawamoto's departure or the org transition. The team knows. A candidate signaling they've been reading tea leaves about internal changes reads as surveillance, not preparation.
- Do not open with "I'm interested in the Head of Design role." Jeremy is a CPO-buyer. He evaluates whether design accelerates product velocity. Lead with the problem, not the application.
The non-obvious thing
Vanta's Trustcraft engineering blog says they trace every customer-facing AI call: prompt, response, tool invocation, latency. The sentence that matters:
"Traceability separates an AI feature from an accountable AI feature."
That is §01 of your Trust essay in their engineering team's vocabulary. The traceability layer already exists. What's missing is the human-facing trust architecture that sits on top of it. Competing candidates will talk about designing AI products. You can walk in and say: your engineering team built the accountability infrastructure, and I've designed the trust interface that makes it legible to the person who has to act on what the agent found.
Most candidates won't have read the Trustcraft post. The ones who have won't know what to do with it.
Save this for the interview, not the DM. It's proof of homework depth that lands in conversation, not in a cold message.
Warning signs
The posting includes unusual language: the Head of Design is "responsible for protecting Vanta and customer data" in how the team operates. Atypical for a design leadership role. This may signal that data-handling compliance extends into design workflows in ways that constrain tooling, research methods, or AI-assisted design processes. Ask about this early. The gap between boilerplate and every Figma file going through compliance review matters for how you'd actually run the org.
- Deb Kawamoto's Dovetail interview: Her September 2025 piece on designing the future of security reveals how she framed AI trust at Vanta — citations, approval, transparency, human-in-the-loop — which tells you the design philosophy you'd be inheriting or evolving.
- Jeremy's upcoming community Q&A: Vanta Community announced that Jeremy Epling will answer questions later in July on product direction and leadership philosophy, which could surface buyer language worth mirroring in your outreach or interview prep.
- Vanta's MCP server launch: The April 2026 product update shows Vanta shipped a remote MCP server in public preview that lets AI tools query a customer's compliance program in real time — a product surface where trust architecture decisions are being made right now.
- Agent for Risk product page: The detailed product page explicitly says the agent "requires humans in the loop, with program owners reviewing, adjusting, and adding context to automated suggestions" — that's Decision Gate language you can reference directly in interview conversation.

