--- title: 'Subject Matter Expert, GTM GRC - V4G at Vanta' canonical: 'https://feeny.ai/job/subject-matter-expert-gtm-grc-v4g-vanta-united-states-wz54ctm8p2bm' type: 'job' last_seen: '2026-09-17' --- # Subject Matter Expert, GTM GRC - V4G at Vanta - **Company:** [Vanta](https://feeny.ai/companies/vanta) - **Location:** United States - **Employment:** full-time - **Work type:** remote - **Posted:** 2026-09-04 - **Last confirmed live:** 2026-09-17 - **Apply:** https://jobs.ashbyhq.com/vanta/2f2ad814-2437-46bc-8829-9413f1840db0 ## Job description At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. Vanta's government motion is expanding across federal and SLED, and this role is the practitioner engine behind it. As a V4G GTM GRC SME you bring deep public-sector compliance expertise — FedRAMP, CMMC, NIST 800-53 and 800-171, StateRAMP and state-program equivalents — directly into deals: scoping a SaaS ISV's path to FedRAMP authorization, helping a defense supplier reason about CMMC level and boundary, and showing state and local buyers how Vanta operationalizes their requirements. This is a revenue seat, not a policy seat. You'll partner directly with V4G sales leadership on key deals, engage from first qualification through POC, onsite, and close, and serve as the trusted voice a government-market buyer's security team relies on. Because the government motion is a focused team inside a larger SME function, you'll also operate with unusual autonomy — triaging your own deal book, owning your relationship with sales leadership, and backstopping the broader SME channel on commercial frameworks when needed. What you’ll do as a Subject Matter Expert, GTM GRC - V4G at Vanta: - Serve as the dedicated GRC SME for government-market opportunities: federal ISVs pursuing FedRAMP, defense industrial base companies facing CMMC, and SLED buyers and sellers — from discovery and qualification through demos, POCs, workshops, and onsites. - Advise on authorization strategy: FedRAMP path and impact-level selection, boundary definition, ConMon obligations, SSP/POA&M readiness, 3PAO engagement, agency sponsorship dynamics, and how Vanta's platform supports each phase. Stay current as the FedRAMP program modernizes — your knowledge must be this-year, not last-cycle. - Map federal and state requirements to Vanta's product: NIST 800-53/171 coverage, continuous monitoring and automated evidence, GovCloud-relevant architecture questions, and custom-framework strategy for state programs. - Answer field questions at customer-forwardable quality, including reviewing and validating AI-agent-generated answers before they reach customers; use AI tooling daily and help extend it into the government motion. - Build and deliver public-sector enablement for GTM teams; review government-market marketing content; feed structured product feedback that shapes Vanta's federal roadmap. - Travel roughly once per quarter (a few days to a week) for customer onsites, workshops, public-sector events, and team offsites. Domain coverage. We hire T-shaped practitioners. For this role the required spikes are federal compliance and continuous monitoring (ConMon), with conversational, demo-capable coverage across the full pillar set: Governance · Data Governance · Compliance · Risk Management (IT, Security, and Enterprise) · TPRM · Continuous Monitoring · Privacy · Trust · AI Security & Governance. Commercial framework fluency (SOC 2, ISO 27001) remains required - government deals routinely carry both. ## What we're looking for - 5+ years in US government compliance, with direct experience taking an organization to FedRAMP Ready or Authorized, assessing as a 3PAO, or both. - Current, working command of FedRAMP (all impact levels and the program's active modernization), CMMC 2.0 (including the shift to 800-171 rev. 3 alignment questions), NIST 800-53 and 800-171, and StateRAMP/state-program dynamics; SSP and POA&M authorship-level familiarity; ConMon operations (scan cadence, POA&M management, significant change). - SLED literacy: how state, local, and education procurement actually buys, and where compliance requirements enter the cycle. - Commercial framework baseline (SOC 2, ISO 27001) and comfort backstopping general GRC questions. - Self-directed operator: you can run a book, triage competing high-priority deals, and manage a leadership relationship without a daily manager cadence. - Production-quality writing, demonstrated AI fluency in your own work, teaching ability, and sales-process literacy — the same bar as every Revenue SME. - Certifications (CISSP, CISA/CISM, CCP/CCA, FedRAMP-relevant training) are welcome signals, not gates. US citizenship or equivalent status may be required for certain customer engagements. What you can expect as a Vanta’n: - Industry-competitive salary and equity - Comprehensive medical, dental, and vision coverage, with 100% of employee-only benefit premiums covered for most medical plans - 16 weeks paid Parental Leave for all new parents - Health & wellness stipend - Remote workspace, internet, and cellphone stipend - Commuter benefits for team members who report to the SF and NYC office - Family planning benefits - Matching 401(k) contribution with immediate vesting - Flexible PTO policy, plus 80 hours of Sick Time - 11 company-paid holidays - Virtual team building activities, lunch and learns, and other company-wide events! - Offices in SF, NYC, London, Dublin, Tel Aviv, and Sydney To provide greater transparency to candidates, we share base pay ranges for all US-based job postings regardless of state. We set standard base pay ranges for all roles based on function, level, and country location, benchmarked against similar-stage growth companies. Final offer amounts are determined by multiple factors and may vary based on candidate location, skills, depth of work experience, and relevant licenses/credentials. #LI-remote At Vanta, we are committed to hiring diverse talent of different backgrounds and as such, it is important to us to provide an inclusive work environment for all. We do not discriminate on the basis of race, gender identity, age, religion, sexual orientation, veteran or disability status, or any other protected class. As an equal opportunity employer, we encourage and welcome people of all backgrounds to apply. ## About Vanta We started in 2018, in the wake of several high-profile data breaches. Online security was only becoming more important, but we knew firsthand how hard it could be for fast-growing companies to invest the time and manpower it takes to build a solid security foundation. Vanta was inspired by a vision to restore trust in internet businesses by enabling companies to improve and prove their security. From our early days automating security monitoring for compliance standards like SOC 2, HIPAA and ISO 27001 to creating the world's leading Trust Management Platform, our vision remains unchanged. Now more than ever, making security continuous—not just a point-in-time check— is essential. Thousands of companies rely on Vanta to build, maintain and demonstrate their trust— all in a way that's real-time and transparent. Referral Instructions If you are being referred for the role, please contact that person to apply on your behalf. ## About Vanta ## Company Overview - **One-liner**: Vanta provides the leading Agentic Trust Platform that automates compliance, risk management, and security proof for businesses. - **Entity Type**: Private (Series C) - **Headquarters**: San Francisco, USA (with offices in New York, Dublin, London, and Sydney) - **Founded**: 2018 - **Founders**: Christina Cacioppo (CEO) ## Core Business - **Primary Industry**: Governance, Risk, and Compliance (GRC) / Cybersecurity - **Target Customers**: B2B, ranging from startups to mid-market and enterprise (16,000+ customers) - **Mission/Purpose**: To protect consumer data and restore trust in internet businesses by enabling companies to improve and prove their security continuously. ## Products & Services - **Vanta Agentic Trust Platform**: An integrated platform with four core capabilities: - **Compliance**: Automates and continuously monitors compliance with 35+ frameworks (SOC 2, ISO 27001, HIPAA, GDPR, FedRAMP, HITRUST, NIST AI RMF, etc.), featuring 1,400+ automated tests and AI-powered policy generation. - **Risk**: Provides a unified view of internal and third-party risk, including vendor risk management (TPRM). - **Proof**: Enables real-time sharing of security posture through Trust Centers and automated questionnaire responses (reported to automate 93% of questionnaires). - **Vanta AI Agent**: A 24/7 GRC engineer that drafts policies, completes questionnaires, flags risks, remediates failed tests, and summarizes findings, saving teams an average of 4+ hours per week. ## Market Standing - **Valuation/Market Cap**: Not publicly disclosed. - **Key Metric**: Total funding of over $300 million. - **Notable Investors/Partners**: Backed by Sequoia Capital, Craft Ventures, Y Combinator, J.P. Morgan, and Goldman Sachs. - **Growth Signals**: - Trusted by over 16,000 customers. - Named a Leader in *The Forrester Wave™: Governance, Risk, and Compliance Platforms, Q2 2026*. - Forrester noted that "Vanta’s innovation approach is unparalleled" with "disruptive product launches." - Reports of significant customer wins, including saving 2,000 hours annually and eliminating 10 spreadsheets for one customer. ## Competitive Advantages - **First-mover & Category Leader**: Vanta pioneered automated compliance for fast-growing tech companies and is now the leading platform in the space. - **AI-Native Platform**: The Vanta AI Agent is a core differentiator, acting as a "24/7 GRC engineer" rather than a simple add-on, making it extremely sticky and efficient. - **Breadth of Coverage**: Supports 35+ frameworks and integrates with 400+ tools, providing a single source of truth for all trust-related work. - **Network Effects**: A large customer base and partner ecosystem (e.g., auditor portal) create a strong moat. ## Strategic Focus - **Continuous Trust**: Moving security from a point-in-time check to a continuous, real-time state. - **AI-Driven Automation**: Deepening the capabilities of the Vanta AI Agent to handle more complex GRC tasks autonomously. - **Enterprise Expansion**: Catering to larger, more complex organizations with features like FedRAMP support and advanced TPRM. - **Global Reach**: Expanding international presence (offices in Dublin, London, Sydney) to serve a global customer base. ## Why Work Here - **Culture & Values**: Emphasizes a "remote-first" setup in the US and a hybrid model internationally. Core principles include "Put customers first," "Bias for action," "Win as one team," "Lead with resilience," and "Decide with frameworks." - **Remote/Hybrid Policy**: Remote-first for US team members; hybrid options available at international offices (San Francisco, New York, Sydney, Dublin, London). - **Benefits**: Comprehensive benefits package includes medical/dental/vision, industry-competitive paid parental leave, generous PTO, and a 401k matching plan. - **Engineering Culture**: The company is building a platform where the AI Agent acts as an "experienced GRC engineer," offering a chance to work on cutting-edge AI problems in a high-growth environment. The CPO previously scaled engineering, product, and design teams at GitHub. ## Sources 1. [Vanta About Us](https://www.vanta.com/company/about) 2. [Vanta Website](https://www.vanta.com/) 3. [Vanta Careers Page](https://www.vanta.com/company/careers) 4. [Vanta - What is Vanta?](https://www.vanta.com/resources/what-is-vanta) 5. [Vanta Jobs on Ashby](https://jobs.ashbyhq.com/vanta/) ## Other roles at Vanta - [Sales Development Representative, Early Stage](https://feeny.ai/job/sales-development-representative-early-stage-vanta-new-york-yy9etp5tt5vj) — New York, NY - [Sr. Technical Recruiter](https://feeny.ai/job/sr-technical-recruiter-vanta-united-states-gbstqpsswfq5) — United States - [Account Executive - Japan](https://feeny.ai/job/account-executive-japan-vanta-tokyo-yybfp9n03nyt) — Tokyo, Japan - [Governance, Risk, and Compliance Expert, GTM, Pre-Sales](https://feeny.ai/job/governance-risk-and-compliance-expert-gtm-pre-sales-vanta-united-states-h9172c7er4g2) — United States - [Recruiting Coordinator](https://feeny.ai/job/recruiting-coordinator-vanta-london-362bd03m1f2w) — London, United Kingdom - [Sr. Technical Sourcer](https://feeny.ai/job/sr-technical-sourcer-vanta-united-states-dx94n47jge76) — United States - [Engineering Manager, App Primitives - CAN](https://feeny.ai/job/engineering-manager-app-primitives-can-vanta-canada-9mmyntcb8y84) — Canada - [Engineering Manager, App Primitives](https://feeny.ai/job/engineering-manager-app-primitives-vanta-united-states-s8y2nv9jk2kg) — United States - [Senior Data Analyst, Strategic Finance](https://feeny.ai/job/senior-data-analyst-strategic-finance-vanta-united-states-tpyrtntv40qr) — United States - [Director, Vanta for Government Partnerships](https://feeny.ai/job/director-vanta-for-government-partnerships-vanta-united-states-46qf5wfxxdt8) — United States