Trigger
Vanta's Head of Design departed end of June 2026. The backfill posted July 6 at $365K–$513K for a ~40-person org. Three weeks prior, Vanta launched Agent for Risk, unifying internal and third-party risk through the Trust Graph (400+ integrations, 1,400+ continuous tests). The design problem underneath that product: a compliance team decides whether to trust automated risk judgment enough to act without manual verification. Confidence: high. The departing leader confirmed publicly this is her backfill.
Window
18 days old. You are early. Backfill searches at this level and stage run 8–14 weeks typically. Four named directors (Kowitz, Sheehan, Larson, Chang) are holding the line, so no operational fire is forcing a fast close. But Epling's July 30 AMA on product direction and leadership philosophy tells you he is actively shaping the narrative around what comes next. Outreach before that AMA positions you as someone who arrived with a thesis. Outreach after it positions you as someone who read the recap.
Outreach before the July 30 AMA is a different signal than outreach after it. You have 6 days.
What this trigger probably means for the design org
The departing leader grew the team from 5 to 45 and installed a four-director bench. That build phase is done. The next leader inherits a functioning org and a product that just made a major AI bet. Read the posting's dual mandate carefully: product trust surfaces across five areas (GRC, Trust, Platform, Self-serve, AI) AND an AI-native design practice with design systems and launch review frameworks. The posting emphasizes operating-model transformation, not headcount growth. The gap between what the departing leader built and what the successor posting asks for tells you the company learned something during the transition about what the next phase actually requires. The mandate: make a 40-person design org fluent in agentic product surfaces while Agent for Risk, Trust Graph, and the privacy operating system ship in parallel.
Your angle
Epling wrote on May 20: "Trust is the defining problem of the AI era." Your essay is titled "Trust Is the New Interface." That language arrived independently, weeks apart, from opposite directions. No other candidate in this pipeline has a published framework whose language mirrors the CPO's own framing before the role existed.
Lead with the Trust essay. The Decision Gate handoff maps directly to Agent for Risk's core UX problem: the moment a compliance team looks at an automated risk assessment and decides to act, escalate, or override. That decision compounds across 400+ integration surfaces in the Trust Graph, each with its own risk context. A trust architecture problem at system scale, and your framework was built for it.
Thermo Fisher is the secondary proof that closes the gap between framework and execution. Compliance teams, like pharma supply chain teams, operate where getting it wrong has regulatory and financial consequences. Exception-first design, bidirectional KPIs, at-risk flags surfaced early enough to act on. You shipped that pattern at $20M+ margin impact across 6 pharma partners.
Trust is the theme. Control is the mechanism. In conversation, name the specific mechanisms: visibility, escalation, reversibility, decision gates, audit trails. Do not say "trustworthy AI." That is a press release phrase. A CPO who still believes in human-in-the-loop and human approval evaluates mechanisms, not slogans.
Who to contact
Jeremy Epling, Chief Product Officer LinkedIn · Oversees engineering, product, and design. Reports directly to CEO Christina Cacioppo. Design reports through him. Classic CPO-as-design-buyer pattern: he owns design outcomes but does not want to make design decisions. He evaluates cognitive load reduction, not craft.
Public fingerprint (last 90 days):
- May 20 — Blog post: "Trust is the defining problem of the AI era." Frames the answer as intelligence + agents + automation + GRC experts for critical decisions.
- June 2 — Agent for Risk launch: framed around making risk visible "today rather than last quarter."
- June 2 — Fast Company coverage: emphasized human-in-the-loop, human approval, agent suggests edits rather than executes.
- March 2026 — First Round podcast: staying connected to product details, maintaining velocity, avoiding rigid hierarchy, open office hours.
- July 30 — AMA announced on product direction and leadership philosophy.
Warm path: None confirmed from public sources. No BCG DV, Alibaba North America, or ADPList overlap to Epling or Vanta's design leadership. Investor-adjacent paths exist through Sequoia and Craft Ventures, but no named mutual connection surfaced. This is cold outreach. Epling's active public posting gives you a strong cold hook. His May 20 post is 9 weeks old but still current because Agent for Risk shipped after it, validating the thesis he laid out.
Channel: LinkedIn cold DM. If routed to email, subject line: The decision gate underneath Agent for Risk.
Outreach messages
Warm message (use if a mutual connection surfaces):
[Name] suggested I reach out. Your May post framing trust as the defining problem of the AI era landed for me because I published "Trust Is the New Interface" in June making the same argument from the design side. The Decision Gate framework in that essay maps directly to the Agent for Risk surface: the moment a compliance team decides to act on an automated assessment, escalate, or override. I'm currently Head of Product at TinyFish (enterprise web agents, Series A), working through these trust problems in production daily, and returning to design to apply that depth to a specific high-stakes vertical. Would 20 minutes on how you're thinking about the design layer underneath Agent for Risk be useful?
Cold message (LinkedIn DM):
Your May post called trust "the defining problem of the AI era." I published an essay in June making the same argument from the design side. "Trust Is the New Interface" maps five handoff points where humans decide whether to trust what an agent produced. The Decision Gate framework maps directly to the Agent for Risk surface: the moment a compliance team looks at an automated risk assessment and decides to act, escalate, or override. I'm currently Head of Product at TinyFish (enterprise web agents, Series A), building through these trust problems in production daily, and I'm returning to design to apply that depth to a specific vertical domain. Would 20 minutes on how you're thinking about the design layer underneath Agent for Risk be useful? junochen.com has the full framework and portfolio.
What not to say:
- Do not reference the departing leader's name or call this a backfill. The org knows. Saying it signals you are reading the vacancy, not the product.
- Do not lead with org-building credentials. The org is built. Four directors are in place. Leading with "I've scaled design teams" tells Epling you misread the mandate.
Cover letter draft
The hardest design problem underneath Agent for Risk is the moment a compliance team decides whether to trust an automated risk assessment enough to act on it without manual verification. Across 400+ integration surfaces, each with its own risk context. That decision point is where AI-native compliance either earns adoption or dies in pilot.
I wrote "Trust Is the New Interface" to name exactly this problem. The essay maps five handoff points in agentic systems and a trust ladder (Watch → Verify → Delegate) that describes how human confidence in automated judgment evolves. The Decision Gate framework maps directly to Agent for Risk's core surface. Your engineering team has said it plainly: AI in compliance must be good enough for a compliance team to stake its program on it. The design architecture that earns that confidence is what I've spent the last three years building toward.
Before the essay, I designed trust architectures in production. At Alibaba.com ($50B+ GMV), I redesigned the B2B platform where a buyer commits six months of inventory spend on the strength of a screen, driving +20% daily transactions and +2.2pt NPS by surfacing trust signals at every decision point. At Thermo Fisher, I built mySupply from zero for pharma supply chain: exception-first order management, at-risk batch flags, bidirectional KPIs across 6 partners and 9 sites. That system recovered $20M+ in annual margin because it caught exceptions at the right gate, not the delivery dock. Compliance teams and pharma supply chain teams share the same design constraint: surfacing the wrong signal at the wrong moment has real consequences, and the system must earn trust through what it makes visible, not what it claims.
I am currently Head of Product at TinyFish, an enterprise web agent platform (Series A), where I shipped 3 products in 3 months and work daily with agent traces, auditability, attribution, and governance in production deployments. I moved to product to build AI-natively from zero. I am returning to design because I want to apply that technical depth to a specific, high-stakes vertical, and because the creative impact of design leadership is where I do my best work. The full framework and portfolio are at junochen.com.
Resume emphasis guidance
This role scores 3 on AI exposure quality (designing trust/supervision surfaces for agentic compliance) and 3 on craft depth (IC influence with strategic seat across five product areas).
- Lead with: Trust essay + Agentic Labs. Carrier IQ demonstrates all five handoffs in a regulated context. Place prominently.
- Follow with: Alibaba.com. Enterprise-scale trust architecture, measurable outcomes, structural gap identification. The "I've done this at scale" anchor.
- Third: Thermo Fisher mySupply. Regulated high-stakes, exception-first design, 0→1 build. Maps directly to compliance workflow design.
- De-emphasize: Equinox+ (consumer, less relevant). Red Cross can stay but move down.
- TinyFish framing: Header: "Head of Product, TinyFish (enterprise web agent platform, Series A)." One bullet: shipped 3 products in 3 months; works daily with agent traces, auditability, and governance in enterprise deployments. Frame as bridge, not destination.
The non-obvious thing
The Dovetail interview with the departing design leader reveals something most candidates will miss: Vanta's design philosophy centers on meeting users in their existing tools (Jira, GitHub, Slack) rather than pulling them into a new workflow. The trust problem at Vanta is not "will users trust our dashboard." It is "will users trust an automated assessment surfaced inside a tool they already use for something else." Harder problem. Name it in conversation and you separate yourself from every candidate pitching dashboard redesigns.
Competitive landscape (moderate confidence): The likely pipeline includes enterprise design directors from GRC-adjacent companies (ServiceNow, OneTrust, Drata) who bring domain fluency but thin AI-native credibility, and AI-native design leaders from well-funded startups who bring agentic product experience but no regulated-environment proof. Your differentiation is the combination: a published trust framework for agentic systems plus shipped regulated-environment work at Thermo Fisher and Red Cross. The vulnerability: a GRC-domain candidate who also has AI exposure would outperform on domain specificity. Counter: your Trust essay gives you a public artifact no domain candidate has, and Epling's own language validates the framework before you walk in.
Warning signs
Buyer ambiguity (partially resolved). The departing leader confirmed publicly she left at end of June and called the open role her "backfill." What remains uncertain: whether Vanta is using the search to re-scope the mandate. Her personal site says Head of Design. The careers page says VP of Design. The posting says Head of Design. That title inconsistency could mean nothing. It could mean the role is being repositioned under Epling with different scope. Outreach recommendation stands regardless. If the role is re-scoped, the Trust essay angle becomes more relevant, not less, because it signals you understand the new product reality rather than the inherited org chart.
Internal candidate risk. Braden Kowitz (Director of Design, ex-Stripe, GV, Google) has been at Vanta since April 2024. The role posted externally 6 days after the departure. That timing suggests either Kowitz is not a candidate or the committee wants a different profile. Monitor. Do not assume this is resolved.
Design reports through a CPO who owns everything. Epling oversees engineering, product, and design. Your outreach should demonstrate that you reduce his decision burden on design, not that you need his sponsorship to elevate design's influence. The departing leader named both Cacioppo and Epling as leaders who "gave her space to lead." Good signal, but one person's experience.
Post-outreach signals
- Response within 3–5 business days: Normal for growth-stage. Vanta has process.
- Silence past 7 business days: Likely in process with other candidates or the role is further along than posting age suggests. One follow-up at day 8 with a new hook. Reference the July 30 AMA or any new Vanta product signal that drops between now and then.
- Recruiter screen scheduled on first contact: Fast-moving search. Prioritize prep immediately. Frame the portfolio walkthrough around Trust essay → Alibaba → Thermo Fisher, in that order.
- Response asks for portfolio walkthrough: High-intent signal. Prepare the junochen.com walkthrough framed around the Decision Gate mapped to Agent for Risk before the conversation.
- Never follow up more than twice. Three unanswered messages = redirect energy to other Act targets.
- If the role goes dark after an initial screen: one follow-up at day 7 referencing the conversation specifically. No reply after that, move Vanta to Watch and monitor for a refresh.
- Epling's July 30 AMA: His community AMA on product direction and leadership philosophy drops next Wednesday and will likely reveal evaluation criteria for the design leader search that are not in the posting.
- Vanta's Trustcraft engineering post: Their engineering team published how they build AI products, including the line "good enough for a compliance team to stake its program on it," which is the strongest public framing of the quality bar the design leader will be held to.
- Departing leader's design-culture interview: The Dovetail interview with the outgoing VP of Design covers citations, approval workflows, transparency about model development, and meeting users in existing tools, all of which are likely inherited expectations the next leader will be evaluated against.
- VantaCon UK product roadmap signals: The May 2026 VantaCon UK recap names Privacy, Trust Graph, Agent, and "privacy operating system for the AI era" as the product moves Epling walked through publicly, giving you conversation-ready language about where the product is heading beyond Agent for Risk.

