Vanta Logo

Vanta

Subject Matter Expert, GTM GRC - Revenue

Posted 7 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in U.S.
171K-201K Annually
Senior level
Remote
Hiring Remotely in U.S.
171K-201K Annually
Senior level
Serve as the GRC subject matter expert on strategic and enterprise deal teams, advising prospects on compliance, risk, privacy, trust, and AI governance programs. Support discovery, demos, POCs, workshops, customer onsite engagements, and expansions. Develop enablement for GTM teams, validate AI-generated content, provide product feedback, and ensure effective post-sales handoffs. Requires deep hands-on GRC experience, customer-facing credibility, strong writing and teaching skills, sales-process knowledge, audit expertise, and practical AI fluency.
The summary above was generated by AI

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. 

Compliance and trust are the products we sell — which means the people who understand GRC most deeply sit at the center of how we win. The GTM GRC SME team brings Governance, Risk, and Compliance expertise directly into customer conversations where it materially improves qualification, solution confidence, stakeholder alignment, and post-sale success.

This is not a back-office compliance role and it is not a generic sales-engineering role. You will operate as a named member of deal teams under our pod model: paired with Strategic and Enterprise Account Executives, embedded in their weekly cadences, engaged from first discovery through POC, onsite, close, and expansion. You will be the practitioner in the room that a buyer's CISO or GRC lead trusts — and the internal expert our AEs, SEs, and marketing team build around.

What you’ll do as a Subject Matter Expert, GTM at Vanta:

  • Serve as the dedicated GRC SME for a book of Strategic/Enterprise Account Executives: join discovery and qualification calls at the earliest deal stages, scope compliance programs against Vanta's platform, and support demos, POCs, workshops, and customer onsites across Compliance, Third-Party Risk Management, Risk Management, and Trust/Questionnaire Automation.

  • Advise prospects on program architecture: multi-framework strategy, shared controls, business-unit and workspace scoping, custom frameworks, and audit sequencing.

  • Answer field questions through our SME channels at customer-forwardable quality — including reviewing and validating AI-agent-generated answers before they reach customers. Our team runs AI-first: you'll use agents daily, act as the quality gate on their output, and (ideally) build tooling of your own.

  • Design and deliver enablement: live sessions for GTM teams, bootcamp scenarios and mock-customer roleplay, async curriculum modules, and review of GRC marketing and SEO content.

  • Own monthly alignment cadences with sales front-line managers; feed structured product feedback to our Product and PM partners; carry deal context cleanly into post-sales handoffs.

  • Travel roughly once per quarter (a few days to a week) for customer onsites, POC workshops, team offsites, and events.

Domain coverage. We hire T-shaped practitioners: deep in two to three of the following pillars, conversant and demo-capable across all nine — Governance · Data Governance · Compliance · Risk Management (IT, Security, and Enterprise) · Third-Party Risk Management · Continuous Monitoring · Privacy · Trust · AI Security & Governance.

How to be successful in this role:

  • 5+ years of hands-on GRC experience, with buyer-side depth: you've built, run, or transformed a multi-framework compliance program (SOC 2, ISO 27001/27017/27018/27701, HIPAA/HITRUST, PCI DSS 4.0, GDPR and the US privacy patchwork, NIST CSF 2.0), or advised many organizations doing so.

  • Working fluency in at least one emerging area — AI governance (ISO 42001, NIST AI RMF), GRC engineering / continuous monitoring, or enterprise risk — and genuine curiosity about the rest.

  • Evidence of customer-facing range: you're credible with a skeptical CISO, a first-time founder, and a procurement team in the same week, and you enjoy the thrill of winning deals.

  • Production-quality writing: answers, scoping docs, and playbooks that can go to a customer on first draft.

  • Demonstrated AI fluency: you use LLM tooling in your compliance work today, can judge AI output against authoritative sources, and want to build with it.

  • Teaching ability: you've trained, presented, published, or enabled others, and you're comfortable building and delivering a session to a large GTM audience.

  • Sales-process literacy (MEDDPICC or similar), audit-process depth from either side of the table, and the judgment to hold scope boundaries gracefully under deal pressure.

  • Open to using AI to amplify their skills and strengthen their work - demonstrating curiosity, a willingness to learn, and sound judgment in applying AI responsibly to improve efficiency and impact.

  • Certifications (CISSP, CISA/CISM, ISO 27001 LA/LI, CIPP/CIPT, AI-governance credentials) are welcome signals, not gates.

What you can expect as a Vanta’n:

  • Industry-competitive salary and equity

  • Comprehensive medical, dental, and vision coverage, with 100% of employee-only benefit premiums covered for most medical plans

  • 16 weeks paid Parental Leave for all new parents

  • Health & wellness stipend

  • Remote workspace, internet, and cellphone stipend

  • Commuter benefits for team members who report to the SF and NYC office

  • Family planning benefits

  • Matching 401(k) contribution with immediate vesting

  • Flexible PTO policy, plus 80 hours of Sick Time

  • 11 company-paid holidays

  • Virtual team building activities, lunch and learns, and other company-wide events!

  • Offices in SF, NYC, London, Dublin, Tel Aviv, and Sydney

To provide greater transparency to candidates, we share base pay ranges for all US-based job postings regardless of state. We set standard base pay ranges for all roles based on function, level, and country location, benchmarked against similar-stage growth companies. Final offer amounts are determined by multiple factors and may vary based on candidate location, skills, depth of work experience, and relevant licenses/credentials.

#LI-remote

At Vanta, we are committed to hiring diverse talent of different backgrounds and as such, it is important to us to provide an inclusive work environment for all. We do not discriminate on the basis of race, gender identity, age, religion, sexual orientation, veteran or disability status, or any other protected class. As an equal opportunity employer, we encourage and welcome people of all backgrounds to apply.

About Vanta

We started in 2018, in the wake of several high-profile data breaches. Online security was only becoming more important, but we knew firsthand how hard it could be for fast-growing companies to invest the time and manpower it takes to build a solid security foundation. Vanta was inspired by a vision to restore trust in internet businesses by enabling companies to improve and prove their security. From our early days automating security monitoring for compliance standards like SOC 2, HIPAA and ISO 27001 to creating the world's leading Trust Management Platform, our vision remains unchanged. 

Now more than ever, making security continuous—not just a point-in-time check— is essential. Thousands of companies rely on Vanta to build, maintain and demonstrate their trust— all in a way that's real-time and transparent.

Referral Instructions

If you are being referred for the role, please contact that person to apply on your behalf.

 
 
 

Similar Jobs

4 Minutes Ago
Easy Apply
Remote
US
Easy Apply
100K-125K Annually
Junior
100K-125K Annually
Junior
Information Technology • Cybersecurity
Monitor and investigate cybersecurity alerts, analyze endpoint telemetry, logs, forensic artifacts, malware, and Microsoft 365 activity, then coordinate threat remediation. The analyst also supports escalations, contributes to detection engineering and tuning, and collaborates across the SOC. The role requires knowledge of operating systems, enterprise administration, networking, web security, attacker techniques, and malware analysis while working a remote weekend 4x10 shift after training.
Top Skills: Active DirectoryAWSAzureBashCommand PromptEdrGCPGroup PolicyJavaScriptLinuxmacOSMicrosoft 365Mitre Att&CkOwasp Top 10PHPPowershellPythonRmm ToolsRubyWindowsWmic
4 Minutes Ago
Easy Apply
Remote
United States
Easy Apply
111K-187K Annually
Entry level
111K-187K Annually
Entry level
Cloud • Security • Software • Cybersecurity • Automation
Drives enterprise sales growth for GitLab across the Northeast by managing strategic accounts, developing account plans, generating pipeline, and leading complex B2B software sales cycles. Builds C-level relationships, coordinates solutions architects and partners, guides customers through evaluation to implementation, expands platform adoption, forecasts opportunities, analyzes wins and losses, and presents business value. The role is fully remote and focused on AI-powered DevSecOps solutions.
Top Skills: Artificial IntelligenceDevsecopsGitlabSaaSSalesforce
5 Minutes Ago
Easy Apply
Remote
US
Easy Apply
59K-78K Annually
Junior
59K-78K Annually
Junior
Information Technology • Cybersecurity
The Sales Development Representative conducts outbound prospecting to internal IT departments and channel partners through phone, email, and LinkedIn. Responsibilities include building pipelines, qualifying prospects, setting product demos, supporting Account Executives, meeting sales quotas, maintaining accurate Salesforce records, and learning cybersecurity solutions. The role also involves exploring AI tools for prospect research, prioritization, outreach preparation, and follow-up in a remote environment.
Top Skills: Artificial IntelligenceCybersecurityEndpoint SecurityLinkedInOutreachSales NavigatorSalesforce

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account