This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
As Vanta’s newest GRC Subject Matter Expert, you’ll be responsible for developing and maintaining multi-framework GRC solutions used by thousands of customers. Acting as a bridge between Product Management, Engineering, Design, Sales, and Customer Success, you’ll ensure our solutions align with key security, privacy, and risk frameworks and real-world customer needs. You’ll play a pivotal role in designing, validating, and improving compliance-related content and capabilities while providing strategic input to shape Vanta’s GRC product roadmap.
Job Responsibility:
Build and maintain compliance frameworks
Design crosswalks and mappings (framework‑agnostic)
Elevate content quality and usability
Drive end‑to‑end GRC product enablement
Act as a product advisor across discovery & design
Author automated tests & continuous monitoring
Partner with Product to drive roadmap
Enable AI‑assisted compliance
Synthesize feedback loops
Requirements:
5-7+ years in GRC and/or Information Security with hands‑on implementation or assessment across multiple frameworks (e.g., SOC 2, ISO 27001/27701, HIPAA, PCI DSS, NIST CSF/800‑53)
Experience with cloud environments and SaaS is strongly preferred
Federal experience (e.g., FedRAMP) is a plus but not required
Bachelor’s degree in Computer Science (preferred)
advanced degree a plus
Deep understanding of controls, risks, testing approaches, evidence standards, and program operations (policies, risk registers, issues/POA&M management, vendor risk, continuous monitoring)
Ability to translate requirements into productizable capabilities
comfort with experimentation and data‑driven prioritization
Build leverage with lightweight tools, LLMs, and automation workflows
Skilled at precise control wording, mapping accuracy, and evidence specificity
comfortable working in spreadsheets and large data sets (lookups, pivots)
Excellent written and verbal skills
able to partner effectively with engineers, designers, GTM teams, auditors, and customers
Able to work autonomously while contributing to team success
Willing & excited to support cross-functional teams and improve compliance content
Skilled at managing change, solving problems proactively, and taking initiative
Open to using AI to amplify their skills and strengthen their work - demonstrating curiosity, a willingness to learn, and sound judgment in applying AI responsibly to improve efficiency and impact
Nice to have:
Experience with privacy regulations (GDPR/CCPA), risk quantification (e.g., FAIR), audit/assessor background, or B2B SaaS content/enablement
Certifications (preferred, not required) - One or more of: CISA, CISSP, CCSK/CCSK+, ISO 27001 Lead Implementer/Lead Auditor, CIPM/CIPT, PCI‑ISA/QSA
What we offer:
Offers Equity
medical benefits
401(k) plan
other company perk programs
Comprehensive medical, dental, and vision coverage, with 100% of employee-only benefit premiums covered for most medical plans
16 weeks fully-paid Parental Leave for all new parents
Health & wellness stipend
Remote workspace, internet, and cellphone stipend
Commuter benefits for team members who report to the SF and NYC office
Family planning benefits
Matching 401(k) contribution with immediate vesting
Flexible PTO policy, plus 80 hours of Sick Time
11 company-paid holidays
Virtual team building activities, lunch and learns, and other company-wide events