--- title: 'Product GRC Subject Matter Expert, (V4G) at Vanta' canonical: 'https://feeny.ai/job/product-grc-subject-matter-expert-v4g-vanta-united-states-dnxs0vc1t18d' type: 'job' last_seen: '2026-09-10' --- # Product GRC Subject Matter Expert, (V4G) at Vanta - **Company:** [Vanta](https://feeny.ai/companies/vanta) - **Location:** United States - **Employment:** full-time - **Work type:** remote - **Posted:** 2026-08-12 - **Last confirmed live:** 2026-09-10 - **Apply:** https://jobs.ashbyhq.com/vanta/8738b34f-cf9a-4d68-90ac-76a19dc56ac0 ## Job description At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. Vanta for Government (V4G) is how we bring that mission to the public sector. As federal compliance undergoes its biggest shift in a decade — FedRAMP 20x, machine-readable authorization, OSCAL — we're building the platform that turns federal frameworks into automated, continuously monitored product experiences. The GRC Subject Matter Experts on this team are the people who make that possible. As Vanta's GRC Subject Matter Expert for V4G, you'll own federal compliance content used by every customer pursuing or maintaining federal authorization on our platform. This is an interpretation-and-authoring role, not a compliance program administration role: your job is to interpret underlying control requirements, identify where FedRAMP modifies or constrains the NIST framework, and translate those interpretations into precise, technically testable guidance that engineering can build and customers can act on. The content you write ships as product — a five-person startup and a Fortune 100 CSP both receive it — so calibrating depth, precision, and universality is the core craft. You'll join Vanta's Security organization, which directly influences product development, facilitates the creation of automated GRC solutions for customers, and provides expert advisory services across the company. What you’ll do as a V4G GRC SME at Vanta: - Build and own federal compliance frameworks — Lead the creation, enhancement, and lifecycle management of controls, evidence requirements, and implementation guidance for FedRAMP (Low/Moderate/High), NIST SP 800-53, NIST SP 800-171, CMMC, DFARS, and StateRAMP. Author clear control rationales, acceptance criteria, and customer-facing guidance shipped as out-of-the-box product content. - Interpret controls at the mechanics level — Work fluently with 800-53A assessment procedures and 800-53B baselines; resolve organization-defined parameters and FedRAMP's constraints on them; decompose controls into distinct technical obligations; correctly resolve inherited, shared, and customer-owned responsibilities within a customer responsibility matrix; and anchor evidence expectations in authoritative artifacts (PPSM, STIG and CIS hardening standards and their scan outputs across operating systems, databases, network devices, and endpoints). - Author automated tests & continuous monitoring — Translate controls and infrastructure context (AWS GovCloud, Azure Government, GCP, SaaS, endpoints, CI/CD) into spec-level automated tests and detectors. Define test logic, data sources, edge cases, and — critically — failure conditions: how unapproved items, exceptions, missing data, and unevaluated resources affect a result. Pair with Engineering to implement and maintain detectors with versioned framework mappings. - Lead V4G's machine-readable future — Shape how Vanta's federal content is architected for OSCAL and FedRAMP 20x: machine-readable SSPs, config-as-compliance, and continuous authorization workflows. - Design crosswalks and mappings — Maintain bidirectional crosswalks across federal frameworks (800-53 ↔ 800-171 ↔ CMMC ↔ StateRAMP) with canonical control IDs, mapping confidence, and traceability to source authority. - Act as a product advisor across discovery & design — Partner with the V4G PM and Design on feature discovery, review UI/UX for control, evidence, and authorization workflows, and author PRDs and acceptance criteria grounded in agency, auditor, and 3PAO needs. - Enable AI-assisted compliance — Partner with Engineering/ML to design LLM-powered guidance and automation for federal workflows. Translate SME knowledge into machine-readable specs, define gold-standard evaluation sets, and implement quality and safety guardrails. - Synthesize feedback loops — Analyze input from customers, agencies, 3PAOs, and internal teams to identify content gaps and ship iterative updates quickly and safely. - Raise the bar — Mentor and calibrate other SMEs, set content quality standards for the federal portfolio, and set framework strategy that others execute against. How to be successful in this role: - Experience — 8–10+ years in GRC and/or Information Security with hands-on federal compliance work: building or maintaining FedRAMP programs on the CSP side, authoring SSPs and supporting artifacts, and running continuous monitoring. DoD impact-level (IL4/IL5) or CMMC experience is a strong plus. Note: this is a builder role — candidates whose federal experience is primarily assessment (3PAO) or compliance program coordination will find the day-to-day is materially different from that work. - Federal interpretation depth — Demonstrated fluency with the NIST 800-53/FedRAMP relationship, 800-53A/B, organization-defined parameters, control inheritance vs. non-applicability, customer responsibility matrices, PPSM, and STIG/CIS benchmarks. - OSCAL & FedRAMP 20x — Working familiarity with OSCAL or other machine-readable compliance approaches, and an informed point of view on where federal authorization is heading. - Test-design rigor — Ability to turn a control into a functional test with defined pass and failure conditions, evidence sufficiency criteria, and coverage across relevant system components. - Product mindset — Ability to translate requirements into productizable capabilities usable by organizations of every size; comfort with experimentation and data-driven prioritization. - Technical & automation (AI-augmented) — Active, current use of AI in GRC work: AI pair-programming tools to accelerate specs, mappings, and test logic; lightweight automations across Sheets/Airtable, APIs, and webhooks; AI-augmented workflows (LLM-assisted control guidance, cross-framework mapping, evidence triage) with measured outcomes; and safe-use patterns for prompts and agents. - Analytical & detail-oriented — Precise control wording, mapping accuracy, and evidence specificity; comfortable in spreadsheets and large datasets. - Communication & collaboration — Excellent written and verbal skills; effective with engineers, designers, GTM teams, agencies, 3PAOs, and customers. - Self-motivated and independent — Operates autonomously at Lead level, setting direction rather than awaiting it. - Nice-to-have — StateRAMP, CNSSI 1253/ICD 503, GovCloud or IL-environment architecture experience, or prior product/content roles at a GRC platform. - Certifications (preferred, not required) — One or more of: CISSP-ISSEP, CISA, FedRAMP 3PAO assessor credentials (CCP/CCA), CISM, or equivalent experience. - Open to using AI to amplify their skills and strengthen their work - demonstrating curiosity, a willingness to learn, and sound judgment in applying AI responsibly to improve efficiency and impact. What you can expect as a Vanta’n: - Industry-competitive salary and equity - Comprehensive medical, dental, and vision coverage, with 100% of employee-only benefit premiums covered for most medical plans - 16 weeks paid Parental Leave for all new parents - Health & wellness stipend - Remote workspace, internet, and cellphone stipend - Commuter benefits for team members who report to the SF and NYC office - Family planning benefits - Matching 401(k) contribution with immediate vesting - Flexible PTO policy, plus 80 hours of Sick Time - 11 company-paid holidays - Virtual team building activities, lunch and learns, and other company-wide events! - Offices in SF, NYC, London, Dublin, Tel Aviv, and Sydney To provide greater transparency to candidates, we share base pay ranges for all US-based job postings regardless of state. We set standard base pay ranges for all roles based on function, level, and country location, benchmarked against similar-stage growth companies. Final offer amounts are determined by multiple factors and may vary based on candidate location, skills, depth of work experience, and relevant licenses/credentials. #LI-remote At Vanta, we are committed to hiring diverse talent of different backgrounds and as such, it is important to us to provide an inclusive work environment for all. We do not discriminate on the basis of race, gender identity, age, religion, sexual orientation, veteran or disability status, or any other protected class. As an equal opportunity employer, we encourage and welcome people of all backgrounds to apply. ## About Vanta We started in 2018, in the wake of several high-profile data breaches. Online security was only becoming more important, but we knew firsthand how hard it could be for fast-growing companies to invest the time and manpower it takes to build a solid security foundation. Vanta was inspired by a vision to restore trust in internet businesses by enabling companies to improve and prove their security. From our early days automating security monitoring for compliance standards like SOC 2, HIPAA and ISO 27001 to creating the world's leading Trust Management Platform, our vision remains unchanged. Now more than ever, making security continuous—not just a point-in-time check— is essential. Thousands of companies rely on Vanta to build, maintain and demonstrate their trust— all in a way that's real-time and transparent. Referral Instructions If you are being referred for the role, please contact that person to apply on your behalf. ## About Vanta ## Company Overview - **One-liner**: Vanta provides the leading Agentic Trust Platform that automates compliance, risk management, and security proof for businesses. - **Entity Type**: Private (Series C) - **Headquarters**: San Francisco, USA (with offices in New York, Dublin, London, and Sydney) - **Founded**: 2018 - **Founders**: Christina Cacioppo (CEO) ## Core Business - **Primary Industry**: Governance, Risk, and Compliance (GRC) / Cybersecurity - **Target Customers**: B2B, ranging from startups to mid-market and enterprise (16,000+ customers) - **Mission/Purpose**: To protect consumer data and restore trust in internet businesses by enabling companies to improve and prove their security continuously. ## Products & Services - **Vanta Agentic Trust Platform**: An integrated platform with four core capabilities: - **Compliance**: Automates and continuously monitors compliance with 35+ frameworks (SOC 2, ISO 27001, HIPAA, GDPR, FedRAMP, HITRUST, NIST AI RMF, etc.), featuring 1,400+ automated tests and AI-powered policy generation. - **Risk**: Provides a unified view of internal and third-party risk, including vendor risk management (TPRM). - **Proof**: Enables real-time sharing of security posture through Trust Centers and automated questionnaire responses (reported to automate 93% of questionnaires). - **Vanta AI Agent**: A 24/7 GRC engineer that drafts policies, completes questionnaires, flags risks, remediates failed tests, and summarizes findings, saving teams an average of 4+ hours per week. ## Market Standing - **Valuation/Market Cap**: Not publicly disclosed. - **Key Metric**: Total funding of over $300 million. - **Notable Investors/Partners**: Backed by Sequoia Capital, Craft Ventures, Y Combinator, J.P. Morgan, and Goldman Sachs. - **Growth Signals**: - Trusted by over 16,000 customers. - Named a Leader in *The Forrester Wave™: Governance, Risk, and Compliance Platforms, Q2 2026*. - Forrester noted that "Vanta’s innovation approach is unparalleled" with "disruptive product launches." - Reports of significant customer wins, including saving 2,000 hours annually and eliminating 10 spreadsheets for one customer. ## Competitive Advantages - **First-mover & Category Leader**: Vanta pioneered automated compliance for fast-growing tech companies and is now the leading platform in the space. - **AI-Native Platform**: The Vanta AI Agent is a core differentiator, acting as a "24/7 GRC engineer" rather than a simple add-on, making it extremely sticky and efficient. - **Breadth of Coverage**: Supports 35+ frameworks and integrates with 400+ tools, providing a single source of truth for all trust-related work. - **Network Effects**: A large customer base and partner ecosystem (e.g., auditor portal) create a strong moat. ## Strategic Focus - **Continuous Trust**: Moving security from a point-in-time check to a continuous, real-time state. - **AI-Driven Automation**: Deepening the capabilities of the Vanta AI Agent to handle more complex GRC tasks autonomously. - **Enterprise Expansion**: Catering to larger, more complex organizations with features like FedRAMP support and advanced TPRM. - **Global Reach**: Expanding international presence (offices in Dublin, London, Sydney) to serve a global customer base. ## Why Work Here - **Culture & Values**: Emphasizes a "remote-first" setup in the US and a hybrid model internationally. Core principles include "Put customers first," "Bias for action," "Win as one team," "Lead with resilience," and "Decide with frameworks." - **Remote/Hybrid Policy**: Remote-first for US team members; hybrid options available at international offices (San Francisco, New York, Sydney, Dublin, London). - **Benefits**: Comprehensive benefits package includes medical/dental/vision, industry-competitive paid parental leave, generous PTO, and a 401k matching plan. - **Engineering Culture**: The company is building a platform where the AI Agent acts as an "experienced GRC engineer," offering a chance to work on cutting-edge AI problems in a high-growth environment. The CPO previously scaled engineering, product, and design teams at GitHub. ## Sources 1. [Vanta About Us](https://www.vanta.com/company/about) 2. [Vanta Website](https://www.vanta.com/) 3. [Vanta Careers Page](https://www.vanta.com/company/careers) 4. [Vanta - What is Vanta?](https://www.vanta.com/resources/what-is-vanta) 5. [Vanta Jobs on Ashby](https://jobs.ashbyhq.com/vanta/) ## Other roles at Vanta - [Account Executive - Japan](https://feeny.ai/job/account-executive-japan-vanta-tokyo-yybfp9n03nyt) — Tokyo, Japan - [Subject Matter Expert, GTM GRC - Revenue](https://feeny.ai/job/subject-matter-expert-gtm-grc-revenue-vanta-united-states-h9172c7er4g2) — United States - [Recruiting Coordinator](https://feeny.ai/job/recruiting-coordinator-vanta-london-362bd03m1f2w) — London, United Kingdom - [Subject Matter Expert, GTM GRC - Revenue](https://feeny.ai/job/subject-matter-expert-gtm-grc-revenue-vanta-united-states-wz54ctm8p2bm) — United States - [Sr. Technical Sourcer](https://feeny.ai/job/sr-technical-sourcer-vanta-united-states-dx94n47jge76) — United States - [Engineering Manager, App Primitives - CAN](https://feeny.ai/job/engineering-manager-app-primitives-can-vanta-canada-9mmyntcb8y84) — Canada - [Engineering Manager, App Primitives](https://feeny.ai/job/engineering-manager-app-primitives-vanta-united-states-s8y2nv9jk2kg) — United States - [Senior Data Analyst, Strategic Finance](https://feeny.ai/job/senior-data-analyst-strategic-finance-vanta-united-states-tpyrtntv40qr) — United States - [Sales Development Representative, Upmarket](https://feeny.ai/job/sales-development-representative-upmarket-vanta-new-york-xmzpf9ms6vx0) — New York, NY - [Sales Development Representative - Commercial + Enterprise](https://feeny.ai/job/sales-development-representative-commercial-enterprise-vanta-san-francisco-eh1w8thr4f1a) — San Francisco, CA