Vanta Logo

Vanta

Subject Matter Expert, GTM GRC - V4G

Posted 7 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in U.S.
171K-201K Annually
Senior level
Remote
Hiring Remotely in U.S.
171K-201K Annually
Senior level
Serve as a GRC subject matter expert on strategic and enterprise deal teams, supporting discovery, demos, POCs, workshops, customer onsites, and expansions. Advise prospects on multi-framework compliance, risk, privacy, trust, and governance programs. Validate AI-generated compliance responses, create enablement materials, train GTM teams, provide product feedback, and support post-sales handoffs. Travel approximately once per quarter.
The summary above was generated by AI

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. 

Vanta's government motion is expanding across federal and SLED, and this role is the practitioner engine behind it. As a V4G GTM GRC SME you bring deep public-sector compliance expertise — FedRAMP, CMMC, NIST 800-53 and 800-171, StateRAMP and state-program equivalents — directly into deals: scoping a SaaS ISV's path to FedRAMP authorization, helping a defense supplier reason about CMMC level and boundary, and showing state and local buyers how Vanta operationalizes their requirements.

This is a revenue seat, not a policy seat. You'll partner directly with V4G sales leadership on key deals, engage from first qualification through POC, onsite, and close, and serve as the trusted voice a government-market buyer's security team relies on. Because the government motion is a focused team inside a larger SME function, you'll also operate with unusual autonomy — triaging your own deal book, owning your relationship with sales leadership, and backstopping the broader SME channel on commercial frameworks when needed.

What you’ll do as a Subject Matter Expert, GTM GRC - V4G at Vanta:

  • Serve as the dedicated GRC SME for government-market opportunities: federal ISVs pursuing FedRAMP, defense industrial base companies facing CMMC, and SLED buyers and sellers — from discovery and qualification through demos, POCs, workshops, and onsites.

  • Advise on authorization strategy: FedRAMP path and impact-level selection, boundary definition, ConMon obligations, SSP/POA&M readiness, 3PAO engagement, agency sponsorship dynamics, and how Vanta's platform supports each phase. Stay current as the FedRAMP program modernizes — your knowledge must be this-year, not last-cycle.

  • Map federal and state requirements to Vanta's product: NIST 800-53/171 coverage, continuous monitoring and automated evidence, GovCloud-relevant architecture questions, and custom-framework strategy for state programs.

  • Answer field questions at customer-forwardable quality, including reviewing and validating AI-agent-generated answers before they reach customers; use AI tooling daily and help extend it into the government motion.

  • Build and deliver public-sector enablement for GTM teams; review government-market marketing content; feed structured product feedback that shapes Vanta's federal roadmap.

  • Travel roughly once per quarter (a few days to a week) for customer onsites, workshops, public-sector events, and team offsites.

Domain coverage. We hire T-shaped practitioners. For this role the required spikes are federal compliance and continuous monitoring (ConMon), with conversational, demo-capable coverage across the full pillar set: Governance · Data Governance · Compliance · Risk Management (IT, Security, and Enterprise) · TPRM · Continuous Monitoring · Privacy · Trust · AI Security & Governance. Commercial framework fluency (SOC 2, ISO 27001) remains required - government deals routinely carry both.

What we're looking for

  • 5+ years in US government compliance, with direct experience taking an organization to FedRAMP Ready or Authorized, assessing as a 3PAO, or both.

  • Current, working command of FedRAMP (all impact levels and the program's active modernization), CMMC 2.0 (including the shift to 800-171 rev. 3 alignment questions), NIST 800-53 and 800-171, and StateRAMP/state-program dynamics; SSP and POA&M authorship-level familiarity; ConMon operations (scan cadence, POA&M management, significant change).

  • SLED literacy: how state, local, and education procurement actually buys, and where compliance requirements enter the cycle.

  • Commercial framework baseline (SOC 2, ISO 27001) and comfort backstopping general GRC questions.

  • Self-directed operator: you can run a book, triage competing high-priority deals, and manage a leadership relationship without a daily manager cadence.

  • Production-quality writing, demonstrated AI fluency in your own work, teaching ability, and sales-process literacy — the same bar as every Revenue SME.

  • Certifications (CISSP, CISA/CISM, CCP/CCA, FedRAMP-relevant training) are welcome signals, not gates. US citizenship or equivalent status may be required for certain customer engagements.

What you can expect as a Vanta’n:

  • Industry-competitive salary and equity

  • Comprehensive medical, dental, and vision coverage, with 100% of employee-only benefit premiums covered for most medical plans

  • 16 weeks paid Parental Leave for all new parents

  • Health & wellness stipend

  • Remote workspace, internet, and cellphone stipend

  • Commuter benefits for team members who report to the SF and NYC office

  • Family planning benefits

  • Matching 401(k) contribution with immediate vesting

  • Flexible PTO policy, plus 80 hours of Sick Time

  • 11 company-paid holidays

  • Virtual team building activities, lunch and learns, and other company-wide events!

  • Offices in SF, NYC, London, Dublin, Tel Aviv, and Sydney

To provide greater transparency to candidates, we share base pay ranges for all US-based job postings regardless of state. We set standard base pay ranges for all roles based on function, level, and country location, benchmarked against similar-stage growth companies. Final offer amounts are determined by multiple factors and may vary based on candidate location, skills, depth of work experience, and relevant licenses/credentials.

#LI-remote

At Vanta, we are committed to hiring diverse talent of different backgrounds and as such, it is important to us to provide an inclusive work environment for all. We do not discriminate on the basis of race, gender identity, age, religion, sexual orientation, veteran or disability status, or any other protected class. As an equal opportunity employer, we encourage and welcome people of all backgrounds to apply.

About Vanta

We started in 2018, in the wake of several high-profile data breaches. Online security was only becoming more important, but we knew firsthand how hard it could be for fast-growing companies to invest the time and manpower it takes to build a solid security foundation. Vanta was inspired by a vision to restore trust in internet businesses by enabling companies to improve and prove their security. From our early days automating security monitoring for compliance standards like SOC 2, HIPAA and ISO 27001 to creating the world's leading Trust Management Platform, our vision remains unchanged. 

Now more than ever, making security continuous—not just a point-in-time check— is essential. Thousands of companies rely on Vanta to build, maintain and demonstrate their trust— all in a way that's real-time and transparent.

Referral Instructions

If you are being referred for the role, please contact that person to apply on your behalf.

 
 
 

Similar Jobs

4 Minutes Ago
Easy Apply
Remote
US
Easy Apply
100K-125K Annually
Junior
100K-125K Annually
Junior
Information Technology • Cybersecurity
Monitor and investigate cybersecurity alerts, analyze endpoint telemetry, logs, forensic artifacts, malware, and Microsoft 365 activity, then coordinate threat remediation. The analyst also supports escalations, contributes to detection engineering and tuning, and collaborates across the SOC. The role requires knowledge of operating systems, enterprise administration, networking, web security, attacker techniques, and malware analysis while working a remote weekend 4x10 shift after training.
Top Skills: Active DirectoryAWSAzureBashCommand PromptEdrGCPGroup PolicyJavaScriptLinuxmacOSMicrosoft 365Mitre Att&CkOwasp Top 10PHPPowershellPythonRmm ToolsRubyWindowsWmic
4 Minutes Ago
Easy Apply
Remote
United States
Easy Apply
111K-187K Annually
Entry level
111K-187K Annually
Entry level
Cloud • Security • Software • Cybersecurity • Automation
Drives enterprise sales growth for GitLab across the Northeast by managing strategic accounts, developing account plans, generating pipeline, and leading complex B2B software sales cycles. Builds C-level relationships, coordinates solutions architects and partners, guides customers through evaluation to implementation, expands platform adoption, forecasts opportunities, analyzes wins and losses, and presents business value. The role is fully remote and focused on AI-powered DevSecOps solutions.
Top Skills: Artificial IntelligenceDevsecopsGitlabSaaSSalesforce
5 Minutes Ago
Easy Apply
Remote
US
Easy Apply
59K-78K Annually
Junior
59K-78K Annually
Junior
Information Technology • Cybersecurity
The Sales Development Representative conducts outbound prospecting to internal IT departments and channel partners through phone, email, and LinkedIn. Responsibilities include building pipelines, qualifying prospects, setting product demos, supporting Account Executives, meeting sales quotas, maintaining accurate Salesforce records, and learning cybersecurity solutions. The role also involves exploring AI tools for prospect research, prioritization, outreach preparation, and follow-up in a remote environment.
Top Skills: Artificial IntelligenceCybersecurityEndpoint SecurityLinkedInOutreachSales NavigatorSalesforce

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account