Back to Jobs
Vanta
Legal & HR 2h ago

Subject Matter Expert (GRC) at Vanta

Vanta
🌍U
Full-time
Not Disclosed
Senior-Level

Job Description

Key Skills Required

Master these to land this role

AI GovernanceGRCComplianceISO 27001Risk Management

Want to know if you're a match for this job?

Calculate My Match Score

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it.

This is not a back-office compliance role and it is not a generic sales-engineering role. You will operate as a named member of deal teams under our pod model: paired with Strategic and Enterprise Account Executives, embedded in their weekly cadences, engaged from first discovery through POC, onsite, close, and expansion. You will be the practitioner in the room that a buyer's CISO or GRC lead trusts—and the internal expert our AEs, SEs, and marketing team build around.

What you’ll do as a Subject Matter Expert at Vanta:

  • Serve as the dedicated GRC SME for a book of Strategic/Enterprise Account Executives: join discovery and qualification calls at the earliest deal stages, scope compliance programs against Vanta's platform, and support demos, POCs, workshops, and customer onsites across Compliance, Third-Party Risk Management, Risk Management, and Trust/Questionnaire Automation.

  • Advise prospects on program architecture: multi-framework strategy, shared controls, business-unit and workspace scoping, custom frameworks, and audit sequencing.

  • Answer field questions through our SME channels at customer-forwardable quality—including reviewing and validating AI-agent-generated answers before they reach customers. Our team runs AI-first: you'll use agents daily, act as the quality gate on their output, and (ideally) build tooling of your own.

  • Design and deliver enablement: live sessions for GTM teams, bootcamp scenarios and mock-customer roleplay, async curriculum modules, and review of GRC marketing and SEO content.

  • Own monthly alignment cadences with sales front-line managers; feed structured product feedback to our Product and PM partners; carry deal context cleanly into post-sales handoffs.

  • Travel roughly once per quarter (a few days to a week) for customer onsites, POC workshops, team offsites, and events.

Domain coverage

We hire T-shaped practitioners: deep in two to three of the following pillars, conversant and demo-capable across all nine—Governance · Data Governance · Compliance · Risk Management (IT, Security, and Enterprise) · Third-Party Risk Management · Continuous Monitoring · Privacy · Trust · AI Security & Governance.

What we're looking for

  • 5+ years of hands-on GRC experience, with buyer-side depth: you've built, run, or transformed a multi-framework compliance program (SOC 2, ISO 27001/270017/270018/27701, HIPAA/HITRUST, PCI DSS 4.0, GDPR and the US privacy patchwork, NIST CSF 2.0), or advised many organizations doing so.

  • Working fluency in at least one emerging area—AI governance (ISO 42001, NIST AI RMF), GRC engineering / continuous monitoring, or enterprise risk—and genuine curiosity about the rest.

  • Evidence of customer-facing range: you're credible with a skeptical CISO, a first-time founder, and a procurement team in the same week, and you enjoy the thrill of winning deals.

  • Production-quality writing: answers, scoping docs, and playbooks that can go to a customer on first draft.

  • Demonstrated AI fluency: you use LLM tooling in your compliance work today, can judge AI output against authoritative sources, and want to build with it.

  • Teaching ability: you've trained, presented, published, or enabled others, and you're comfortable building and delivering a session to a large GTM audience.

  • Sales-process literacy (MEDDPICC or similar), audit-process depth from either side of the table, and the judgment to hold scope boundaries gracefully under deal pressure.

Certifications (CISSP, CISA/CISM, ISO 27001 LA/LI, CIPP/CIPT, AI-governance credentials) are welcome signals, not gates.

How would you rate this job post?

See what other professionals think about this role.

banner

Vanta is the leading trust management platform that simplifies and automates security compliance for growing companies. Traditionally, getting certifications like SOC 2, ISO 27001, or HIPAA took months of manual work, screenshots, and expensive consultants. Vanta changed the game by connecting directly to a company's tools (like AWS, GitHub, Slack, and Gusto) to automatically monitor security controls in real-time. Instead of just checking a box once a year, Vanta proves that a company is secure 24/7, helping businesses close deals faster by instantly building trust with their customers.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More