PHASE 1 — THE MOMENT
Vanta's former VP of Design Deb Kawamoto appears to have departed. The Design Executive Council labels her "Fmr. VP of Design at Vanta." Vanta's own design careers page still lists her, but these pages lag departures by weeks or months. Moderate confidence on the departure: convergent signals, no confirmation. Act as if it's true while verifying.
The departure matters less than the delta between the old mandate and the new one. Kawamoto's scope was design quality, design systems, operational workflow. The new posting, titled "Head of Design (VP)," preserves the level but rewrites the job: agentic UX patterns, AI-native design practice, org-level AI fluency across a 40-person team spanning GRC, Trust, Platform, Self-serve, and AI. The product moved. The role description caught up.
The real mandate: Design the trust architecture that determines whether Vanta's compliance agents earn enough human confidence to shift GRC from periodic audit to continuous assurance.
Buyer: Jeremy Epling, CPO. Three years in seat. Owns engineering, product, and design. He is not a new CPO learning the org. He has a thesis, he had a design leader executing it, and now he needs the person who can execute the next version. His May 2026 Forrester GRC Wave post frames Vanta's direction around continuous assurance, embedded AI, agents, and "GRC experts pulled in for critical decisions." Read that last phrase carefully. It is the design problem. When does the human get pulled in, what do they see when they arrive, and is it enough to make a real call?
Company moment: $300M ARR crossed April 2026, growth accelerating across each of the prior four quarters. CFO with IPO-preparation pedigree hired 45 days ago (June 9, 2026). McCauley led IPO preparation at Seismic and supported ServiceNow's growth through its IPO. Series C at $2.45B valuation, Sequoia-led. 16,000 customers. Every signal points to IPO preparation. The equity window is open and narrowing.
Company 12 (AI centrality 3, stage/equity 3, design ceiling 3, trajectory 3). Role 15 (comp 3, scope 3, craft 3, AI exposure 3, portfolio value 3). Posting age unavailable from Ashby metadata, but concurrent Design Recruiter and Staff Design Systems postings signal they are building infrastructure around the leadership gap. Move this week.
AI centrality scores 3 because AI is not a feature bolted onto Vanta's compliance product. Vanta Agent, Custom Agents, QAuto, and Contract Gap Analysis are the product surfaces the posting explicitly asks this leader to own. The posting names "agentic UX patterns" and "AI-native design practice" as the role's core mandate. The entire product trajectory is agent-mediated compliance.
PHASE 2 — PORTFOLIO MAPPING
Intelligence layer check: positive. Vanta's entire product surfaces compliance intelligence for human decision-making. Every agent output — gap analysis finding, QAuto-filled questionnaire answer, risk flag from a Custom Agent — lands on a human who has to decide: is this right enough to act on? Lead with the intelligence layer frame. Entry point is the moment between what an AI surfaces and what a human decides. The Trust essay's five handoffs are the through-line.
Five handoffs → Vanta:
-
Intent-Setting → Custom Agents. Users create agents with a name, prompt, and schedule for recurring compliance work. How does a compliance manager communicate what they want monitored without thinking like an engineer? This is the cold-start problem you solved at TinyFish: blank input box, no scaffolding, users churning before reaching value.
-
In-Progress → Vanta Agent guided flows. The agent asks for information, takes actions after confirmation, guides users to next steps. Confidence forms through real-time visibility, not a loading state.
-
Output Review → QAuto + Contract Gap Analysis. QAuto auto-detects and fills response fields across documents and portals. Contract Gap Analysis reads commitments, compares against controls, returns ranked results with cited evidence. The design problem is provenance: evidence beside every finding so the reviewer calibrates against what the system reliably does, not what they hope it did.
-
Decision Gate → approve/remediate/accept risk. QAuto can optionally auto-approve unflagged answers. That word "optionally" is doing enormous work. It is a trust-ladder decision surface. Watch: review everything. Verify: review flagged items. Delegate: auto-approve. How that option is designed determines whether teams climb the ladder or stay locked at Watch.
-
Loop Feedback → compliance cycles. This assessment's results shape the next automated run. A slight miscategorization in cycle one compounds by cycle five. Same pattern you documented in Carrier IQ.
Lead with: Trust essay + Alibaba. The essay names the problem Vanta is hiring someone to solve. Alibaba proves you solved it at enterprise scale. A buyer committing six months of inventory spend on the strength of a screen is structurally identical to a compliance team committing audit readiness on the strength of an agent's findings. Both require trust architecture at the systems level. Outcomes that land: +20% daily transactions, -47% buyer security concerns, +2.2pt NPS across 25M+ sessions.
Support with: Thermo Fisher + Red Cross. Thermo Fisher proves you design for regulated, irreversible-consequence domains where exceptions must surface before the gate, not after. $20M+ margin recovered, 6 pharma partners, 100% adoption. Red Cross proves 0→1 under federal oversight for untrained operators in 6 months. Both are explicitly named in the Trust essay body. Citing the essay validates the cases. Citing the cases validates the essay. No other candidate has this structural advantage.
TinyFish: Current role context only. Head of Product at an enterprise web agent platform (Series A). Building and deploying agents in production daily, tracing agent runs with LangSmith, solving governance and auditability challenges firsthand. Bridge: moved to product to build AI-natively from zero, returning to design to apply that depth to a specific high-stakes vertical.
Your portfolio architecture is itself a trust ramp. Worth naming if it comes up in conversation. Your site's progressive disclosure — teaser cards visible to anyone, gated full cases requiring a conversation, interview-depth detail earned through engagement — structurally demonstrates Watch → Verify → Delegate. The teaser is Watch: enough to form initial trust. The gated case is Verify: enough evidence to confirm the signal. The interview is Delegate: enough trust to invest real time. You think in trust ramps as a design instinct, not a framework you read about.
Hardest objection: "No compliance/security/GRC domain experience."
Someone on the hiring committee from the compliance side will ask it. What makes it hard: the posting spans five product areas, and GRC practitioners are protective of domain credibility.
What answers it: Vanta's problem is not compliance expertise. It is trust architecture for agent-mediated decisions where consequences are irreversible. Thermo Fisher: pharma regulatory, batch QA release gates, rescheduling costs 3–5× more if exceptions surface late. Red Cross: federal disaster relief, untrained volunteers, $847K disbursed in two weeks. The domain was different each time. The design problem was the same each time.
PHASE 3 — THE OUTREACH PACKAGE
First contact message, to Jeremy Epling, CPO:
Jeremy — your Forrester GRC Wave post landed on something I've been building toward for two years: the design problem between what an agent surfaces and what a human decides to do about it. You wrote about GRC experts "pulled in for critical decisions." That pull-in moment is exactly where trust architecture succeeds or fails.
I'm Juno Chen, currently Head of Product at TinyFish (enterprise web agent platform, Series A), where I build and deploy agents in production daily. Before that, I led design for Alibaba.com's B2B platform ($50B+ GMV, 25M+ sessions), where I redesigned the trust signals that drove +20% daily transactions and cut buyer security concerns by 47%. I also built regulated platforms at Thermo Fisher (pharma supply chain, $20M+ margin recovered) and the American Red Cross (disaster relief, federal oversight, national deployment in 6 months).
I've been mapping the five critical handoffs between human and agent across enterprise deployments at TinyFish and in the design work that preceded it. Every one of those handoffs maps to what Vanta Agent, QAuto, and Custom Agents need to get right.
Would 20 minutes make sense to explore the fit?
(181 words)
Resume framing note:
Lead the summary with the trust-architecture problem. Not a title. Not years of experience. First line names the challenge: making agent-surfaced compliance intelligence trustworthy enough for humans to act on. Name the Trust essay ("Trust Is the New Interface," published June 2026) in the summary and link it. The essay explicitly names Alibaba, Thermo Fisher, and Red Cross in its body, so citing it validates the cases while the cases validate it. No other candidate has this structural advantage. Surface Alibaba metrics first (transaction and trust outcomes at enterprise scale), then Thermo Fisher (regulated, irreversible stakes), then Red Cross (0→1 under federal oversight). TinyFish goes in the current-role line as "Head of Product, TinyFish — enterprise web agent platform (Series A)" with one sentence on production agent deployment and governance. Subordinate Equinox+ and Allē entirely. Omit consumer language. Avoid "design-led culture" or "design maturity" framing. Epling is a three-year CPO who evaluates cognitive load reduction and product-outcome proof, not design-culture aspiration. Vocabulary anchors: trust architecture, decision surfaces, agent-mediated workflows, compliance intelligence.
Cover letter hook:
"Vanta's product bet is that compliance can shift from periodic audit to continuous assurance, but that shift only works if the humans responsible for compliance trust what the agents find enough to act without redoing the work. I've spent thirteen years solving that problem in production at Alibaba, Thermo Fisher, and the American Red Cross, and the last two building the design framework for it in agentic systems."
PHASE 4 — WINDOW SUMMARY
| Action | Deadline | What degrades without it |
|---|---|---|
| Verify posting is still active on Ashby | July 25, 2026 | Posting age unknown. Confirm before investing outreach effort. |
| Send first-contact message to Jeremy Epling via LinkedIn | July 28, 2026 | Design Recruiter posting signals active pipeline. Candidate pool is forming now. Every week of delay is a week closer to shortlist lock. |
| Prepare five-handoffs → Vanta mapping as a one-page leave-behind | July 31, 2026 | Without a concrete artifact mapping the framework to Custom Agents, QAuto, and Contract Gap Analysis, the Trust essay stays abstract. The mapping makes it operational. |
- Vanta's design-system expansion: The concurrent Staff Product Designer, Design Systems posting says the design-system team (Alpaca) is now responsible for AI-driven, runtime-composed UI and agent chat/canvas experiences, which tells you where the Head of Design's system-level authority will be tested first.
- QAuto auto-approve as trust-ladder precedent: Vanta's March 2026 release notes describe optional auto-approval of unflagged agent answers, which is the clearest live example of a Watch → Verify → Delegate decision surface in their product and worth referencing in any interview conversation about the trust ladder.
- Epling's agent-announcement language: His June 2025 AI Agent post describes an agent that keeps users informed and in control at key moments while operating autonomously, a framing that maps directly to the Decision Gate handoff and gives you a second public hook beyond the Forrester post.
- CFO hire as IPO clock: McCauley's background includes leading IPO preparation at Seismic and supporting ServiceNow through its IPO, and his arrival 45 days ago alongside $300M ARR and accelerating growth means the equity window conversation should be part of your comp-stage preparation, not an afterthought.

