Full-Time

Product GRC Subject Matter Expert

Updated on 9/4/2026

Vanta

Vanta

1,001-5,000 employees

Automates SOC 2 compliance checks via SaaS

Compensation Overview

$230k - $270k/yr

+ Equity

Remote in USA

Remote

Category
Cybersecurity (1)
Required Skills
LLM
FedRAMP
Webhooks
Product Management
Machine Learning
REST APIs
DevOps
Google Cloud Platform

Get referred to Vanta

See people who can refer or advise you

Requirements
  • 8–10+ years in governance, risk, and compliance and/or information security with hands-on federal compliance work, including building or maintaining FedRAMP programs on the cloud service provider side, authoring system security plans and supporting artifacts, and running continuous monitoring.
  • Fluency with the NIST Special Publication 800-53 and FedRAMP relationship, NIST Special Publications 800-53A and 800-53B, organization-defined parameters, control inheritance versus non-applicability, customer responsibility matrices, PPSM, and STIG/CIS benchmarks.
  • Working familiarity with OSCAL or other machine-readable compliance approaches, with an informed perspective on the direction of federal authorization.
  • Ability to turn a control into a functional test with defined pass and failure conditions, evidence sufficiency criteria, and coverage across relevant system components.
  • Ability to translate requirements into productizable capabilities usable by organizations of every size, with comfort in experimentation and data-driven prioritization.
  • Current use of AI in GRC work, including AI pair-programming tools, lightweight automations across Sheets/Airtable, APIs and webhooks, AI-augmented control guidance, cross-framework mapping, evidence triage, measured outcomes, and safe-use patterns for prompts and agents.
  • Precision in control wording, mapping accuracy, and evidence specificity, with comfort working in spreadsheets and large datasets.
  • Ability to communicate and collaborate effectively with engineers, designers, go-to-market teams, agencies, 3PAOs, and customers.
  • Ability to operate autonomously at Lead level and set direction independently.
Responsibilities
  • Build, enhance, and manage the lifecycle of federal compliance frameworks, controls, evidence requirements, implementation guidance, control rationales, acceptance criteria, and customer-facing product content for FedRAMP Low/Moderate/High, NIST SP 800-53, NIST SP 800-171, CMMC, DFARS, and StateRAMP.
  • Interpret controls at the mechanics level, including 800-53A assessment procedures, 800-53B baselines, organization-defined parameters, FedRAMP constraints, technical obligations, inherited/shared/customer-owned responsibilities, and evidence expectations based on authoritative artifacts.
  • Translate controls and infrastructure context across AWS GovCloud, Azure Government, GCP, SaaS, endpoints, and CI/CD into automated tests and detectors; define test logic, data sources, edge cases, failure conditions, and versioned framework mappings with Engineering.
  • Shape federal content architecture for OSCAL and FedRAMP 20x, including machine-readable system security plans, configuration-as-compliance, and continuous authorization workflows.
  • Maintain bidirectional crosswalks across 800-53, 800-171, CMMC, and StateRAMP with canonical control IDs, mapping confidence, and traceability to source authority.
  • Partner with the V4G product manager and Design on feature discovery, review control/evidence/authorization workflows, and author product requirements documents and acceptance criteria grounded in agency, auditor, and 3PAO needs.
  • Partner with Engineering and machine learning teams to design LLM-powered guidance and automation, translate subject-matter expertise into machine-readable specifications, define gold-standard evaluation sets, and implement quality and safety guardrails.
  • Analyze feedback from customers, agencies, 3PAOs, and internal teams to identify content gaps and ship iterative updates.
  • Mentor and calibrate other subject-matter experts, set content quality standards for the federal portfolio, and set framework strategy for others to execute.
  • Pair with Engineering to implement and maintain automated compliance detectors.
Desired Qualifications
  • DoD impact-level 4 or impact-level 5 experience.
  • CMMC experience.
  • StateRAMP experience.
  • CNSSI 1253 or ICD 503 experience.
  • GovCloud or impact-level environment architecture experience.
  • Prior product or content experience at a GRC platform.
  • One or more of CISSP-ISSEP, CISA, FedRAMP 3PAO assessor credentials such as CCP/CCA, CISM, or equivalent experience.
  • Experience using AI to amplify skills and improve work efficiency and impact responsibly.

Vanta provides a SaaS platform that helps small to mid-sized organizations obtain and maintain SOC 2 certification through automated checks and continuous monitoring. The product integrates with a company’s systems to run checks, track control effectiveness, and generate ready evidence, reports, and submission-ready documentation. It differentiates itself by offering ongoing compliance instead of one-off audits, with scalable checks and automated workflows tailored to SMEs and tech companies. The goal is to make SOC 2 faster, cheaper, and easier to sustain so organizations can focus on their core business while keeping strong security controls.

Company Size

1,001-5,000

Company Stage

Series D

Total Funding

$503M

Headquarters

San Francisco, California

Founded

2018

Get referred to Vanta

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • April 2026 FedRAMP 20x Moderate opened federal sales before October procurement cycles.
  • July 2026 AI governance launch targets ISO 42001 and EU AI Act demand.
  • August 2026 CMO Sarah Scharf and June 2026 CFO John McCauley sharpen execution.

What critics are saying

  • Drata, Secureframe, and OneTrust commoditize compliance automation, crushing Vanta pricing power by 2027.
  • AI governance hype invites Microsoft, AWS, and ServiceNow into Vanta's core workflows.
  • If enterprise AI compliance standardizes, Vanta's startup-led growth engine loses relevance.

What makes Vanta unique

  • Vanta spans 35-plus frameworks, from SOC 2 to FedRAMP 20x and ISO 42001.
  • Its Trust Graph ties controls, vendors, and agents into one live risk system.
  • Sixteen thousand customers, including Snowflake and GitHub, validate category leadership.

Help us improve and share your feedback! Did you find this helpful?

Benefits

100% Benefits Coverage

Flexible & Remote Work

Paid Parental Leave

Unlimited PTO

Health & Wellness

401(k)

Growth & Insights and Company News

Headcount

6 month growth

1%

1 year growth

3%

2 year growth

3%
wallstreet:online AG
Aug 22nd, 2026
Vanta announces closing of First Tranche of Private Placement and board of Directors Update.

Vanta announces closing of First Tranche of Private Placement and board of Directors Update. VANCOUVER, BC / ACCESS Newswire / August 21, 2026 / Vanta Holdings Inc. (CSE:VNTA)(OTC:VNTXF)(FSE:7BC, WKN:A4205J) ("Vanta" or the "Company"), a consumer health sciences and longevity company focused on preventative wellness and healthspan... VANCOUVER, BC / ACCESS Newswire / August 21, 2026 / Vanta Holdings Inc. (CSE:VNTA)(OTC:VNTXF)(FSE:7BC, WKN:A4205J) ("Vanta" or the "Company"), a consumer health sciences and longevity company focused on preventative wellness and healthspan extension, and parent of the Vanta premium longevity brand, announces that, further to its news release dated May 29, 2026, the Company has closed the first tranche (the "First Tranche") of its previously announced non-brokered private placement (the "Private Placement"), through the issuance of 124,579 units of the Company (each, a "Unit") at a price of $1.00 per Unit, for aggregate gross proceeds of $124,579.42. Each Unit consists of one common share in the capital of the Company (each, a "Share") and one transferable common share purchase warrant (each, a "Warrant"). Each Warrant entitles the holder to acquire one additional Share (each, a "Warrant Share") at an exercise price of $1.25 per Warrant Share, exercisable until August 21, 2028. The securities issued under the Private Placement will be subject to a statutory hold period expiring December 22, 2026. The Private Placement remains ongoing following the closing of the First Tranche. The Company expects to close the remaining portion of the Private Placement, in whole or in part, in one or more additional tranches on or before October 5, 2026, subject to compliance with the policies of the Canadian Securities Exchange. This press release shall not constitute an offer to sell or the solicitation of an offer to buy securities in the United States, nor shall there be any sale of the securities in any jurisdiction in which such offer, solicitation or sale would be unlawful. The securities being offered have not been, nor will they be, registered under the U.S. Securities Act of 1933, as amended (the "1933 Act"), or under any U.S. state securities laws, and may not be offered or sold in the United States absent registration or an applicable exemption from the registration requirements of the 1933 Act and applicable state securities laws. Board of Directors Update The Company also announces, that Mr. Norman John Campbell has resigned from the Company's board of directors, effective August 21, 2026, as he transitions to a new professional opportunity as a partner in an asset management firm and seeks to avoid potential conflicts associated with his new role. The Company extends its sincere appreciation to Mr. Campbell for his longstanding service and contributions to Vanta and wishes him continued success in this next chapter of his career. Following Mr. Campbell's resignation, Vanta's board of directors is comprised of four members, including two independent directors and two non-independent directors. Accesswire Autor folgen Mehr anzeigen We are ACCESS Newswire, a globally trusted Public Relations (PR) and Investor Relations (IR) solutions provider. With a focus on innovation, customer service, and value-driven offerings, ACCESS Newswire empowers brands to connect with their audiences where it matters most. From startups and scale-ups to multi-billion-dollar global brands, we ensure your most important moments make an impact and resonate with your audiences. Verfasst von Letzte Änderung22.08.2026, 04:55

Panoptic Scans
Aug 12th, 2026
Stop treating SOC 2 vulnerability scanning like a checkbox.

Stop treating SOC 2 vulnerability scanning like a checkbox. Stop treating SOC 2 vulnerability scanning like a checkbox written on aug 12, 2026. Posted in how-to. The annual scan is dead. Auditors stopped accepting a single 300-page Nessus PDF years ago. Under CC7.1, SOC 2 vulnerability management requires continuous monitoring. A vulnerability disclosed today affects code you shipped six months ago; finding out about it during your annual audit means you failed the control. You need a defined way to identify newly discovered flaws affecting the packages your software already uses. If your tool alerts the team when a new CVE affects lodash or spring-core, that alert becomes part of your CC7.1 evidence. The process matters more than the specific scanner you buy. Panoptic Scans, LLC. saw a Series B startup fail their Type II audit earlier this year because they had no ticket history showing they actually fixed the critical findings their scanner found. They bought the tool but ignored the alerts. What auditors actually look for in 2026. A strong process includes automated scanning, alert review, severity-based SLAs, ticket history, and reporting. Your tooling can vary, but the evidence must show a repeatable process. * Infrastructure Scanning: Checks the operating system and network layers for open ports, outdated Linux kernels, and missing patches on web servers like Nginx. * Dynamic Application Security Testing (DAST): Crawls your application to inject commands, execute cross-site scripting, and find misconfigurations in HTTP headers. Authenticated scans catch the flaws hiding behind your login screen. * Software Composition Analysis (SCA): Looks at your package.json or requirements.txt files to see if you import libraries with known flaws. * Cloud Security Posture Management (CSPM): Scans your AWS or Azure environments for public S3 buckets and overly permissive IAM roles. You can automate much of this. Hosted Nuclei scans run continuously against your external attack surface. Panoptic Scans integrates directly with Vanta to pull your scan results into your compliance dashboard automatically. You don't have to manually upload CSVs every Friday at 4pm. Set SLAs you can actually meet. SOC 2 does not mandate specific remediation timelines. You define them in your security policy. Common industry practice sets clear deadlines based on severity. | Severity | Expected SLA | Audit Reality | | Critical | 7 to 15 days | Requires immediate Jira ticket and verified fix | | High | 30 days | Must not exceed the SLA window | | Medium | 90 days | Often accepted as risk exceptions if documented | | Low | 180 days | Rarely scrutinized unless ignored entirely | Missing your own documented SLAs is a frequent audit failure. Do not promise 24-hour remediation for high-severity bugs if your engineering team deploys once a week. Set a 30-day SLA. Meet it consistently. Auditors prefer a slow, reliable process over a fast, broken one. Focus on context-aware prioritization that factors in asset criticality and exposure. A critical CVE on an internal testing server matters less than a medium-severity flaw on your public API gateway. Stop fighting your compliance tools. Automate the discovery phase and let the scanners generate the evidence for you.

Associated Press
Aug 12th, 2026
Vanta names Sarah Scharf CMO as trust platform hits $300M ARR

Vanta has appointed Sarah Scharf as chief marketing officer. Scharf joined Vanta in 2020 as its first product marketer and has since led every function within the company's marketing organisation. Reporting directly to CEO Christina Cacioppo, she will oversee product marketing, brand, communications, content, growth, and revenue marketing. During her tenure, Scharf led Vanta's positioning through three category shifts: from automated compliance to trust management to agentic trust. The appointment comes as Vanta surpassed $300 million in annual recurring revenue, reaching the milestone nine months after hitting $200 million. Over 16,000 companies, including Snowflake, GitHub, and Ramp, use Vanta's platform. Before Vanta, Scharf spent seven years at Google in product marketing roles. She holds a degree from Stanford University.

AOL
Aug 12th, 2026
Vanta names Sarah Scharf Chief Marketing Officer as trust becomes the defining challenge of the AI era.

Vanta names Sarah Scharf Chief Marketing Officer as trust becomes the defining challenge of the AI era. Updated Aug 12, 2026 SAN FRANCISCO-(BUSINESS WIRE)-Aug 12, 2026- Vanta, the leading Agentic Trust Platform, today announced the appointment of Sarah Scharf as Chief Marketing Officer. Joining the executive team and reporting directly to CEO Christina Cacioppo, Scharf will oversee the entire marketing organization, including product marketing, brand, communications, content, growth, and revenue marketing. Sarah Scharf has joined the executive team at Vanta as Chief Marketing Officer, reporting directly to CEO Christina Cacioppo and overseeing the entire marketing organization. Scharf joined Vanta in 2020 as its first product marketer and has since led every function within Vanta marketing. During her tenure, she has led the company's positioning through three category shifts, from automated compliance, to trust management, to agentic trust. "Sarah created our category and then led its next two chapters as we led the market," said Christina Cacioppo, CEO of Vanta. "Over the past six years, Sarah has led every part of marketing at Vanta: PMM, brand, communications, content, and revenue marketing. She knows Vanta in the way one only can by being in the business for years." Scharf takes on the role as trust becomes a central concern for companies adopting AI. Customers, regulators, and partners increasingly want proof that AI systems are secure and governed - a category Vanta created and has since expanded into AI governance and agentic trust. She has led Vanta through each of these shifts, most recently steering the company's own AI transformation, giving her firsthand experience building an AI-native organization. "Trust is the defining problem of the AI era. Solving it takes a brand that's earned trust itself, and helps others earn it, too," said Scharf. "At Vanta, the story and the product move forward together, and right now that means transforming how we work with and for AI, without losing the 'with a wink' spirit that our customers love. I'm proud to lead a team I've helped build since the very beginning." Before Vanta, Scharf spent seven years at Google in product marketing roles across Account Settings, Next Billion Users, and the Platforms team supporting Android and Google Play. She holds a degree from Stanford University. Her appointment comes as Vanta surpassed $300 million in ARR, reaching the milestone just nine months after $200 million, with growth accelerating each of the past four quarters. The company was recently named to the CNBC Disruptor 50 list and recognized as a Leader in The Forrester Wave(TM) for Governance, Risk, and Compliance Platforms. About Vanta Vanta is the leading Agentic Trust Platform, setting the standard for how businesses earn and prove trust as AI reshapes security and compliance. Over 16,000 companies like Snowflake, GitHub, Ramp, Cursor, Golden State Warriors, and Icelandair rely on Vanta to guide, automate, and improve the GRC work that trust is built on. [email protected] KEYWORD: CALIFORNIA UNITED STATES NORTH AMERICA INDUSTRY KEYWORD: SOFTWARE TECHNOLOGY ARTIFICIAL INTELLIGENCE SECURITY PUB: 08/12/2026 09:00 AM/DISC: 08/12/2026 09:03 AM

Business Insider
Aug 12th, 2026
$4 billion Vanta has a new CMO who wants to make security compliance marketing 'a little zingier'

$4 billion Vanta has a new CMO who wants to make security compliance marketing 'a little zingier' Aug 12, 2026, 4:00 AM PT Security-compliance software startup Vanta wants to become known as a "trust company" that can also have a bit of fun. It's entrusting a new CMO to get it there. Vanta has promoted its VP of marketing, Sarah Scharf, to CMO, the company exclusively told CMO Insider. In an interview, Scharf said the two tasks at the top of her to-do list are to solidify the Vanta brand's association with trust among its clients and potential customers, and to reinvent how the company gets marketing done internally in the age of AI. "How can we capture the moment and also reposition Vanta in a way to showcase how we help businesses of all sizes instill and maintain that trust in a world where AI makes it harder to come by and maintain?" Scharf said. Founded in 2018, Vanta offers an automated platform that helps companies assess the security and compliance of their products. While it's best known for helping startups complete processes like SOC 2 audits, it's branched out to offer services to larger enterprise customers, in areas such as assessing third-party risk and AI governance. Its customers include Snowflake, GitHub, and the Golden State Warriors. Vanta said it was valued at about $4 billion in a funding round last year. Vanta has sought to stand out from its competitors with playful marketing, such as plastering San Francisco with billboards reading: "Compliance that doesn't SOC 2 much." Scharf, who joined the company in 2020, said she wants Vanta to continue marketing "with a wink," while other security brands tend to focus on fear and posturing to emphasize their strength. "We're a compliance company, we're giving you security information. Some of that is going to be bland and boring, but what can we do to make it just a little zingier?" Scharf said. "We want to be seen as trusted experts, someone you can come to with a question," she added. "We're not arrogant or looking down." While these marketing efforts can help humanize the brand in an often dusty sector, Sarah Ashdown, consumer marketing and revenue director at the consultancy Manifesto Growth Architects, said Vanta can't simply build "trust" into a platform or claim it through positioning alone. "Trust is earned over time through the quality of the service, the outcomes customers achieve, and the relationship a business builds with them," Ashdown said. Where Scharf is investing Vanta's marketing budget. Scharf said the company is investing its marketing budget in areas such as influencer marketing and podcasts. This summer, it launched a video podcast called "The Tabletop," in which it invites chief information security officers to role-play live "situation-room"-style scenarios, such as how they would respond to a security breach. "That's what people want to watch and engage with, and also has the added benefit now that LLM search is blowing up, and high-authority, owned content is very additive for LLM discovery," Scharf said. Internally, Scharf said Vanta is using AI to streamline repetitive tasks, like resizing advertising assets and editing content. It's also using tools like Midjourney to prototype campaigns. When hiring, Scharf said she is screening candidates for AI proficiency - though "not from a tokenmaxxing perspective."