Rubric: C11 / R14 — Act Tier: AI-native (regulated domain) — read AI-native playbook; load healthcare/regulated objection layer Portfolio match: Carrier IQ + Thermo Fisher + Trust essay — the moment a compliance professional decides whether an agent's finding is sufficient to stake a regulatory commitment on Posting age: 34 days (July 6). LinkedIn refresh within last 5 days. 200+ applicants.
PHASE 1 — THE MOMENT
Deb Kawamoto held VP/Head of Design from October 2023 through the end of June 2026. She grew the team from 5 to roughly 45 and built a four-director layer under her. In her departure post she named this posting as her backfill.
So this is a seat someone already occupied and shaped. I read it the other way in Issue #6, where simultaneous postings looked to me like a new function being stood up. That was wrong. You are inheriting an org, not building one, and the difference changes almost every line of your positioning below.
Trigger: Kawamoto left a company that crossed $300M ARR and tripled revenue in two years, at the point where the product is moving from compliance automation to agentic execution. CPO Jeremy Epling has said publicly that 20 agentic workflows shipped last year, with 90+ targeted by year-end. Agents now collect evidence, test controls, review vendors, and write remediation code. A governance, risk, and compliance professional then decides whether to trust what the agent produced.
Real mandate: Take over a working ~40-person design org with four directors covering GRC, Trust, Platform, Self-serve, and AI, and make it AI-forward while the number of surfaces where an agent's output becomes a binding compliance commitment multiplies every quarter.
Reports to: CPO Jeremy Epling.
"He described the Head of Design as someone he manages while operating with them as a peer." — First Round Review
In the same interview he says he wants leaders who stay close to product detail and raise quality through direct, specific feedback. Read that as a preference for someone who can look at a screen and say what is wrong with it, rather than someone who runs the function through the org chart.
Window read: Day 34 is late, but this one is still moving. The LinkedIn refresh is recent, Kawamoto is promoting the backfill herself, and a concurrent Design Recruiter posting suggests they are building hiring capacity around whoever lands. The 200+ applicant count looks alarming and mostly is not: LinkedIn applicant volume on a senior design leadership post is a poor proxy for qualified pipeline, and I would not let it change your timing. What it does change is where you spend the effort. At day 34 a differentiated direct message to Epling is worth more than a fast application.
Verify the search is still actively filling before you invest preparation time — the refresh and the recruiter posting both say yes, so a single confirming check is enough. If it holds, message Epling before day 37.
PHASE 2 — PORTFOLIO MAPPING
Intelligence layer: active. Vanta's product surfaces intelligence for a human to act on, so lead with the decision moment, not with "agentic products." The design problem is where a compliance professional looks at what an agent produced and decides whether it is sufficient to act on. Vanta creates several of those points: accepting a control recommendation, treating collected evidence as verified, relying on an extracted contractual obligation, applying generated infrastructure remediation. Trust the output wrongly and you have regulatory exposure. Verify all of it manually and the agent has bought you nothing. Your Trust essay's Watch → Verify → Delegate ladder describes exactly how these users calibrate.
Lead pillar: trust architecture in regulated systems.
-
Carrier IQ is the closest analog you have published. An agent completes a form, selects coverage, presents a recommendation, and a human decides whether to accept it — in an industry where accepting wrong carries regulatory consequence. Same structure as Vanta's problem, different vertical.
-
Thermo Fisher mySupply supplies the triage pattern. 197 orders, surface the 3 that matter. When an agent verifies 500 controls and flags 3 exceptions, the interface has to make those 3 legible without forcing the GRC lead to re-audit the 497. You have shipped that pattern in a regulated, auditable system with 100% partner adoption.
-
Trust essay. Users anchor to the worst outcome, not the average accuracy. Epling's line about retaining GRC experts for critical decisions is the same principle expressed as org design. Cite the essay by name; it gives you a published position that matches what he is already saying operationally.
Supporting: Alibaba ($50B+ GMV, Head of Design and Research, North America). Three cross-functional sprints across homepage, search, and PDP is your evidence of operating across multiple product surfaces at once, which is what five product areas and four directors will ask of you.
TinyFish: Head of Product at an enterprise web agent platform, $47M Series A. Agent traces, auditability, attribution, governance in production daily — that is current practitioner depth in Vanta's technical domain. The bridge line is short: you went to product to build AI-natively from zero, and you are returning to design to apply that depth to one high-stakes vertical rather than a horizontal platform. Use it as context and currency, not as portfolio proof.
Nothing in your published work states team sizes or experience managing directors, and this role inherits four of them. Have the numbers ready before any screen: team size, direct reports, years managing managers. If you hesitate on "how many people have you managed," the recruiter writes down "strong IC, unproven at scale," and that sentence reaches Epling before your portfolio does.
The published answer is Alibaba — Head of Design and Research for North America, running cross-functional sprints on a $50B+ GMV platform. And the inherited director layer works in your favour, since leading an established team through a product shift is not the same job as recruiting one. The specific numbers still have to come from your mouth.
PHASE 3 — THE OUTREACH PACKAGE
First Contact Message — to Jeremy Epling via LinkedIn
Jeremy — in your First Round interview you described wanting design leaders who stay close to the product detail and raise quality through direct, specific feedback. That reads as the right instinct for where Vanta is going. Once agents are collecting evidence, testing controls, and generating remediation, the screen where a compliance lead decides whether to trust that output is a craft problem, and it does not get solved from the org chart.
I've been working on that problem from both sides. At Agentic Labs I built three live agent products, each one centred on the handoff between what the agent produced and what the human decides to do about it, and I published the framework behind them as "Trust Is the New Interface." I'm currently Head of Product at TinyFish, an enterprise web agent platform, working with agent traces, auditability and governance in production. Before that I led design and research for Alibaba.com North America, and built regulated systems at Thermo Fisher and the American Red Cross.
Would you have 20 minutes?
Resume Framing Note
Open the summary with the current role (Head of Product, TinyFish — enterprise web agent platform) and the Trust essay, then Alibaba for scale. Surface +20% transactions, +2.2pt NPS at $50B+ GMV as the first metric on the page. Keep Equinox+ and Allē on the resume but below the fold; consumer work is not what this room is grading.
Avoid:
- "Design-led culture." Epling runs a CPO-led org with design as a peer function. Using "design-led" tells him you have not read how his team actually works.
- "Building a design org from scratch." This is a handover. Framing it as a build misreads the mandate and reads as though you skimmed the posting.
TinyFish line: "Head of Product, TinyFish — enterprise web agent platform ($47M Series A). Building and deploying agentic AI products in production; 3 products shipped in first 3 months."
Cover Letter Hook
Vanta's move from compliance automation to agentic execution creates a design problem at every point where a GRC professional has to decide whether an agent's control recommendation, evidence check, or remediation is sufficient to act on. I have designed for that decision in regulated systems at Thermo Fisher and the Red Cross, in agent products at Agentic Labs, and I am building enterprise agents in production at TinyFish now.
PHASE 4 — WINDOW SUMMARY
| Action | Deadline | What degrades without it |
|---|---|---|
| Send first contact message to Epling via LinkedIn | Aug 11 | The refresh says the funnel is still being shaped; after day 37 you are arriving to a shortlist someone else wrote |
| Apply through Ashby ATS with tailored resume | Aug 12 | An application on its own is indistinguishable from the other 200; one that follows the Epling message confirms it |
| Prepare the org-scale narrative — team sizes, director-management examples from Alibaba and prior roles | Aug 15 | The hardest question has no published answer, and if a screen gets booked first, you improvise it live |
- Vanta's agent sandbox architecture: Their engineering team describes how the Vanta Agent gets an isolated Linux workspace for multi-step document review and gap analysis, with writes scoped by authorization and permission — useful for understanding the specific control surfaces you'd be designing.
- Epling on operating with design: His First Round interview goes deeper than the leadership preference quoted above, covering why Cacioppo consolidated product, engineering, and design under one CPO and what that means for the Head of Design's actual authority.
- Meaningful oversight beyond presence: A recent peer-reviewed paper in npj Digital Medicine argues that human oversight requires understanding, cognitive room, authority to disagree, and effective intervention — vocabulary that maps directly to Vanta's GRC trust problem and strengthens how you discuss the Trust essay in conversation.
- NIST agent standards initiative: NIST's 2026 initiative on AI agent identity and authorization focuses on secure agent authentication, interoperable human-agent interactions, and permission scoping — the regulatory framework Vanta's customers will increasingly need to satisfy.

