Vanta Logo

Vanta

GRC Subject Matter Expert, Product

Posted 18 Days Ago
Remote
Hiring Remotely in U.S.
Mid level
Remote
Hiring Remotely in U.S.
Mid level
As a GRC Subject Matter Expert at Vanta, you'll develop GRC solutions, optimize content, analyze feedback, and collaborate across teams to support customer compliance needs.
The summary above was generated by AI

At Vanta, our mission is to secure the internet and protect consumer data. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. 

As Vanta rapidly grows and moves upmarket, we’re working with increasingly sophisticated customers who have complex security and compliance needs. The GRC Subject Matter Experts play a critical role in delivering high-quality, scalable content to help these companies effectively manage their GRC programs.

As Vanta’s newest GRC Subject Matter Expert, you’ll be responsible for developing GRC solutions that support our growing list of global customers. Acting as a bridge between Product Management, customers, and compliance stakeholders, you’ll ensure that our solutions align with key security and privacy frameworks. You’ll play a pivotal role in designing, maintaining, and improving compliance-related content while providing strategic input to shape Vanta’s overall GRC product roadmap.

You’ll join Vanta’s Security organization, which provides essential security operational services, is directly involved in the software development process, sets policies and standards regarding enterprise-wide security requirements, and offers advisory services to enable our business to thrive while effectively managing risk. If you’re someone who has high initiative and enjoys problem solving while having impact at a high-growth company, we would love to hear from you!

You’ll be part of Vanta’s Security organization that directly influences product development, facilitates the creation of automated GRC solutions for customers, and provides expert advisory services to Vantans at large. If you love solving complex problems, thrive in a fast-paced environment, and want to make a real impact at a high-growth company, we’d love to hear from you!

What you’ll do as a GRC SME at Vanta

  • Develop New Compliance Frameworks – Assist in building new security, privacy, and risk management frameworks for end-users.

  • Optimize GRC Content – Map evidence requirements, improve control descriptions, write policies, risk scenarios, implementation guidance to enhance clarity and usability, and help to develop AI features.

  • Analyze Feedback – Identify and resolve issues with control mappings, evidence requirements, and framework content based on end-user and auditor input.

  • Collaborate Across Teams – Work with software engineers, product designers, and customer-facing teams to ensure that GRC content is appropriately integrated into Vanta’s platform and meets end-user needs.

  • Partner with Product – Work closely with our Product team to advise on the development of new GRC features in the platform.

How to be successful in this role:

  • 4-5 years of experience in GRC and/or Information Security – Consulting experience is a plus but not required.

  • Strong comprehension, communication, and collaboration skills – Ability to grasp core GRC concepts, apply them effectively across tasks, and clearly communicate findings to GRC Content Engineers, Product Managers, and non-technical stakeholders.

  • Technical understanding of security and compliance – Familiarity with industry frameworks such as ISO 27001, SOC 2, HIPAA, and NIST 800-53. Having a technical background (SOC Analyst, Security Engineer, Vuln Management, etc.) is a plus, but not required.

  • Attention to detail and analytical mindset – Comfortable working with cybersecurity frameworks, control mappings, and evidence requirements with precision and consistency.

  • Proficiency in MS Excel/Google Sheets – Ability to organize large data-sets, use lookup functions, and create pivot tables.

  • Self-motivated and independent – Able to work autonomously while contributing to team success.

  • Helpful and resourceful – Willing & excited to support cross-functional teams and improve compliance content.

  • Adaptable in a fast-paced environment – Skilled at managing change, solving problems proactively, and taking initiative.

  • Security certifications or formal education preferred – Certifications like Security+, CISA, or CISSP are a plus but not required.

What you can expect as a Vanta’n:

  • Industry-Competitive Salary and Equity

  • 100% covered Medical, Dental, and Vision Benefits with Dependents Coverage

  • 16 Weeks Fully Paid Parental Leave for All New Parents (Moms, Dads, Adoptive, Foster)

  • Health & Wellness Stipend

  • Remote Workspace Stipend

  • 401(k) Matching Plan

  • Flexible Work Hours and Location

  • Open & Encouraged PTO Policy

  • 9 Company Paid Holidays

  • Free Memberships to Online Wellness Platforms (One Medical, Headspace, and more!) 

  • Virtual Team Building Activities, Lunch and Learns, and other Company-Wide Events

  • Offices in SF and NYC with Hubs of Vantans forming across the US, including but not limited to, Seattle, Austin, Indianapolis, LA, Boston, and more!

To provide greater transparency to candidates, we share base pay ranges for all US-based job postings regardless of state. We set standard base pay ranges for all roles based on function, level, and country location, benchmarked against similar-stage growth companies. Final offer amounts are determined by multiple factors and may vary based on candidate location, skills, depth of work experience, and relevant licenses/credentials.

#LI-remote

At Vanta, we are committed to hiring diverse talent of different backgrounds and as such, it is important to us to provide an inclusive work environment for all. We do not discriminate on the basis of race, gender identity, age, religion, sexual orientation, veteran or disability status, or any other protected class. As an equal opportunity employer, we encourage and welcome people of all backgrounds to apply.

About Vanta

We started in 2018, in the wake of several high-profile data breaches. Online security was only becoming more important, but we knew firsthand how hard it could be for fast-growing companies to invest the time and manpower it takes to build a solid security foundation. Vanta was inspired by a vision to restore trust in internet businesses by enabling companies to improve and prove their security.From our early days automating security monitoring for compliance standards like SOC 2, HIPAA and ISO 27001 to creating the world's leading Trust Management Platform, our vision remains unchanged. 

Now more than ever, making security continuous—not just a point-in-time check— is essential. Thousands of companies rely on Vanta to build, maintain and demonstrate their trust— all in a way that's real-time and transparent.

Top Skills

Google Sheets
Hipaa
Iso 27001
Excel
Nist 800-53
Soc 2

Similar Jobs

Yesterday
Remote
Hybrid
United States
Mid level
Mid level
Artificial Intelligence • Cloud • Information Technology • Sales • Security • Software • Cybersecurity
The Product Security Consultant opens and manages security product deployments, advises on best practices, and automates solutions for customers. Responsibilities include documentation, scripting, and providing pre-sales support.
Top Skills: AWSGoogle Cloud PlatformGrcIdsIpsAzurePowershellPythonSIEMSQL
Yesterday
Easy Apply
Remote
2 Locations
Easy Apply
157K-217K Annually
Senior level
157K-217K Annually
Senior level
Artificial Intelligence • Fintech • Machine Learning • Social Impact • Software
As a Senior Offensive Security Engineer, you'll build and lead the Offensive Security program, test Upstart's controls, and collaborate with various security teams.
Top Skills: AWSCi/CdEksKubernetesmacOSOktaPython
Yesterday
Remote
USA
110K-180K Annually
Senior level
110K-180K Annually
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
The Sr. Cloud Red Team Engineer emulates threat actors in cloud environments, assesses security, and enhances CrowdStrike's Falcon security capabilities.
Top Skills: .NetAWSC/C++GdbGhidraGoIdaRustWindbg

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account