Trigger
Vanta posted a Director of Product Design, TPRM on August 25. Four days old. It sits beneath a Head of Design role that's been open 54 days. On August 28, design leader Jenny Chang publicly announced she left Vanta the previous month, naming Braden Kowitz, Conor Sheehan, and Jerrod Larson as the remaining design leadership bench.
Confidence: High on the posting and departure. Moderate on what the departure means for this role's scope.
Window
You are in the first week. The Head role at 54 days means the design org is actively thinning — Chang's exit removed a director-level leader from a bench already stretched thin. Early candidates matching fresh posting language get outsized attention when a search is new and the team is short-staffed. The window narrows after day 14, when the first screening slate is likely assembled.
What this trigger probably means for the design org
Posting a Director for TPRM while the Head search is still open tells you the TPRM work can't wait for the Head to arrive and set the org. This Director will likely operate with significant autonomy for months — reporting to CPO Epling directly, or to a Head who hasn't started yet.
The question you need answered before committing: Does this Director own the governance rules for AI-assisted risk decisions — the acceptance thresholds, override mechanisms, escalation logic — or only the product surfaces that display agent outputs?
The posting says "net-new experience for an AI-centric workflow builder" and covers risk registers, dashboards, and reporting. It does not say who decides when an AI-generated vendor assessment is good enough to act on. Your first conversation with Epling should surface which one this Director owns.
Rubric
Company: 11/12 — Act.
| Dimension | Score | Evidence |
|---|---|---|
| AI centrality | 3 | TPRM agent automates vendor discovery through scoring. AI is the product. |
| Stage / equity | 3 | Series D, $4.15B valuation, $300M ARR, pre-IPO. |
| Design influence ceiling | 2 | Director leads area team and strategy. Head unfilled; reporting ambiguous. |
| Trajectory | 3 | 60% YoY customer growth, 250%+ daily Agent user growth, 16K+ customers. |
Role: 14/15 — Act.
| Dimension | Score | Evidence |
|---|---|---|
| Comp potential | 3 | $275K–$323K cash plus pre-IPO equity at $4.15B. |
| Scope expandability | 3 | Risk-area strategy, no structural ceiling if the Head hire is collaborative. Drops to 2 if the Head centralizes. |
| Craft depth | 2 | Design direction and team leadership. Posting doesn't specify how much direct execution the Director retains. |
| AI exposure quality | 3 | Trust boundaries around AI-generated vendor assessments in consequential enterprise decisions. |
| Portfolio value | 3 | Agent governance in regulated risk workflows. Publishable, differentiated. |
Company 11/12, Role 14/15. Both clear the threshold. The window is day 4 of 14.
Your angle
Lead with Carrier IQ.
Carrier IQ is live at junochen.com — an agent-assisted insurance workflow where the system collects evidence and extracts risk, but the human holds the approval gate. Vanta's TPRM agent does the same thing in a different domain: discovers vendors, collects evidence, extracts risks, applies customer-specific scoring, surfaces assessments for human decision. The design questions are identical. When does the human review? What does the agent show to earn trust? What happens when the agent is wrong and the customer already accepted the assessment?
Your Trust essay names this precisely. The five handoffs — Intent-Setting through Loop Feedback — map to TPRM's workflow. The trust ladder (Watch, Verify, Delegate) is the progression Vanta needs its enterprise customers to travel.
The Human-Agent System Design artifacts would strengthen this case, but they're not published at junochen.com yet. The window is too tight to wait. Carrier IQ and the Trust essay differentiate at the outreach stage. Prioritize publishing those artifacts before the interview, not before the first message.
Secondary: Thermo Fisher mySupply. You built a regulated supply-chain platform from zero across six pharma partners as Product Design Director at BCG DV — compliance-first design where errors have real consequences. Same stakes profile as vendor risk management.
Narrative fit: You've already built a live, inspectable agent-assisted decision workflow in a regulated domain — the trust boundary between an AI assessment and a human approval, working in production. Most candidates will describe this problem abstractly. You can point to a URL.
Who to contact
Jeremy Epling — CPO, Vanta. LinkedIn. Product, Engineering, and Design all report to him. He is the confirmed buyer for the Head role. The Director's hiring chain isn't public yet, but all of Design reports into his org — he's the strongest route for both roles.
Public fingerprint (Fresh — August 21): Epling told Benzinga that "everybody's become a builder" — AI enables nontechnical employees to create software and automated workflows, and security through obscurity no longer works because agents may act unexpectedly. He reported 250%+ growth in daily Agent users and 50-fold MCP-server growth during 2026. He's introducing custom agents and end-to-end workflows at a September 10 product event.
His First Round interview (March 2026) reveals how he evaluates: short decision documents, customer evidence, and prototypes over long specs. He responds to a defined problem with underlying evidence, not a feature list.
Warm path: No verified connection through BCG DV, Alibaba, or named investors. Check your LinkedIn for mutual connections before sending. Three or more mutuals — reference them in the close. A direct connection — ask for an introduction instead of messaging cold.
Channel: LinkedIn cold DM unless your mutual-connection check reveals a warm path.
Outreach
Warm message to Epling (use only if your LinkedIn check reveals a mutual path)
[Mutual connection] suggested I reach out. I built Carrier IQ (live at junochen.com) — an agent-assisted workflow where the system handles evidence collection and risk extraction while the human holds the approval gate. The trust architecture maps directly to what your TPRM agent needs as vendor assessment scales past per-action review. I'd welcome 20 minutes on how the Director role draws the boundary between agent-generated risk scores and customer acceptance decisions.
Cold message to Epling
Your Benzinga point about agents finding data and acting unexpectedly — that's the design problem I've been building around. I shipped Carrier IQ (live at junochen.com), an agent-assisted insurance workflow where the system collects evidence and extracts risk, but the human holds the approval gate. The trust architecture maps directly to what your TPRM agent needs as vendor assessment scales past per-action review. I'd welcome 20 minutes on how you're drawing the boundary between agent-generated risk scores and customer acceptance decisions, especially with custom agents and workflows rolling out September 10.
What not to say
- Don't lead with org-building or team management. Epling values craft proximity and product detail. Opening with "I've managed teams of X" pitches the wrong surface for this buyer.
- Don't reference the Head of Design role or speculate about reporting structure. Asking "who does this report to?" in a first message signals you're evaluating the org chart before the work. Save it for the conversation.
Cover letter
Vanta's TPRM agent automates the hardest parts of vendor assessment — discovery, evidence collection, risk extraction, scoring. The design problem underneath that automation: when an AI system generates a consequential assessment, what does the interface need to show to make the human decision trustworthy?
I built Carrier IQ (live at junochen.com) as an agent-assisted insurance workflow where the system handles evidence collection and risk extraction while the human operator holds the approval gate. It demonstrates all five handoffs from my Trust framework — intent-setting through loop feedback — in a regulated, agent-assisted workflow. That architecture maps directly to TPRM's vendor assessment flow. My Trust essay (junochen.com/trust-is-the-new-interface) formalizes this as five handoffs, with a trust ladder that moves users from watching to verifying to delegating. Before that, as Product Design Director at BCG Digital Ventures, I built Thermo Fisher's mySupply platform from zero — a regulated supply-chain system across six pharma partners that recovered $20M+ in annual margin, where compliance-first design and decision gates were structural requirements.
Most recently as Head of Product at TinyFish, an enterprise web agent platform, I shipped the agentic platform from 0 to 1 within three months — working through agent traces, auditability, and governance challenges in production. I moved to product to build AI-natively from zero; I've returned to design to apply that technical depth to a specific, high-stakes domain. TPRM's agent-assisted vendor governance is that domain.
I'd welcome a conversation about how the Director role draws the line between what the agent decides and what the customer decides. Portfolio and case studies at junochen.com.
Resume emphasis
- Carrier IQ and Agentic Labs lead. The exact workflow TPRM needs — evidence collection, risk extraction, human gate.
- Trust essay — name it and link it. The framework shows you've formalized the problem they're hiring someone to solve.
- Thermo Fisher mySupply (Product Design Director, BCG DV) — regulated 0-to-1, compliance-first, decision gates.
- Alibaba.com — enterprise scale credibility ($50B+ GMV).
- TinyFish — header context only. "Most recently, Head of Product at TinyFish (enterprise web agent platform, Series A). Shipped agentic platform 0-to-1 in 3 months."
- Move down: Equinox+, Allē, Red Cross. None map to this role's core problem.
Competitive landscape
GRC-domain design leader (high confidence this archetype is in the pipeline). Someone from a compliance or security company with deep regulatory vocabulary and existing GRC buyer relationships. Most GRC products are still form-and-dashboard tools — these candidates will understand the domain but won't have agent-governance proof. Counter: Carrier IQ and the Trust essay show the governance layer working in production. Domain knowledge without agent-trust architecture is incomplete for this role.
Enterprise design director (moderate confidence). Salesforce or ServiceNow pedigree, larger team. Epling's stated preference for craft proximity and product detail means org-size credentials may actually work against this archetype. Counter: Lead with the artifact, not the org chart.
AI-native designer (moderate confidence). Anthropic or OpenAI pedigree with stronger AI brand recognition. Most AI-native designers build internally, though — no inspectable regulated-domain proof in public. Counter: Carrier IQ is live at a URL. The Trust essay is published. A hiring manager can verify both before the first conversation.
Internal candidate — Kowitz, Sheehan, or Larson (speculative). Chang's departure narrows the bench to three. Kowitz's stated scope is GRC, adjacent but distinct from TPRM. Larson owns automations and the design system. Sheehan's pillar is unknown. If one is being considered, the posting may be a formality. You can't control this, so move anyway.
The non-obvious thing
On August 5, Vanta's engineering team published a technical post on AI verifiers for compliance evidence. It draws a specific distinction: a verifier judges whether an individual work product is correct, while an evaluator measures whether the AI system itself is performing well. Right now, Engineering is framing this problem. I flagged this pattern in Issue #6: Vanta's AI-quality narrative has been authored by Engineering, not Design.
This Director posting may be the moment Design gets to own the trust architecture for agent-generated assessments. If Epling engages, ask him directly: does the Director own the verifier's acceptance criteria, or does Engineering? His answer tells you whether this role has real authority over the governance layer.
Warning signs
The Head role at 54 days is a yellow flag. Senior design searches commonly stall around this point — the first slate fails, the committee recalibrates. The Director's scope and autonomy depend on who fills the Head seat and when. If the Head hire centralizes authority, the Director's strategic ownership could contract to execution. Ask Epling how the Director and Head will divide decision rights over AI governance in the TPRM product.
Design's voice is being carried by Engineering and Product, not Design. The AI-quality verifier post came from Engineering. The design careers page still lists departed VP Kawamoto. Glassdoor shows 3.4/5 from 233 reviews with no identifiably design-specific signal. None of this is disqualifying on its own, but the pattern suggests Design's internal influence may not match the ambition of these postings. The diagnostic question about governance ownership tests exactly this.
Post-outreach signals
Vanta is growth-stage (~1,000 employees, $300M ARR).
- Response within 3–5 business days = normal. Epling runs Product, Engineering, and Design — he's busy.
- Recruiter screen in the first reply = fast-moving search. Prioritize prep immediately.
- Silence past 7 business days = likely in process with other candidates. One follow-up at day 8 referencing the September 10 product event. No reply after the follow-up — close the loop and redirect.
- A reply engaging the trust-boundary question = strong signal. Respond within 24 hours with a specific observation about their TPRM product's current review flow.
- Epling's September 10 event: Vanta is previewing custom agents, skills, and end-to-end workflows at Vanta Delivers, which will likely reveal the TPRM workflow builder's scope before your interview.
- Chang's departure ripple: Jenny Chang named Kowitz, Sheehan, and Larson as the remaining design leadership bench in her LinkedIn departure post, and watching whether any of those three update their profiles or scope in the next two weeks signals internal reorg.
- AI governance as a product line: Vanta announced early access to an AI-governance layer covering agent inventory, guardrails, and continuous evidence — which may expand the Director's mandate beyond TPRM into org-wide agent oversight.
- Verifier vs. evaluator framing: The engineering team's technical post on building AI verifiers distinguishes judging individual work products from measuring the AI system itself, and whether Design or Engineering owns that distinction is the sharpest authority question to bring into your conversation.

