Full-Time

Product GRC SME

Vanta

Vanta

1,001-5,000 employees

Automates SOC 2 compliance checks via SaaS

Compensation Overview

$171k - $201k/yr

Remote in USA

Remote

Category
IT & Security (1)
Required Skills
LLM
SOC 2
Risk Management
Requirements
  • 5-7+ years in Governance, Risk and Compliance and/or Information Security with hands-on implementation or assessment across multiple frameworks (e.g., SOC 2, ISO 27001/27701, HIPAA, PCI DSS, NIST CSF/800-53)
  • Experience with cloud environments and Software as a Service is strongly preferred
  • GRC craft deep understanding of controls, risks, testing approaches, evidence standards, and program operations (policies, risk registers, issues/POA&M management, vendor risk, continuous monitoring)
  • Product mindset with ability to translate requirements into productizable capabilities; comfort with experimentation and data-driven prioritization
  • Technical and automation capability including use of lightweight tools, large language models, and automation workflows; ability to build automated tests and detectors; design AI-augmented workflows; establish safe-use guidelines and reusable patterns for prompts and agents
  • Analytical and detail-oriented; skilled at precise control wording, mapping accuracy, and evidence specificity; comfortable working with spreadsheets and large data sets (lookups, pivots)
  • Communication and collaboration; excellent written and verbal skills; ability to partner with engineers, designers, GTM teams, auditors, and customers
  • Self-motivated and independent; able to work autonomously while contributing to team success
  • Helpful and resourceful; willing and excited to support cross-functional teams and improve compliance content
  • Adaptable in a fast-paced environment; capable of managing change, solving problems proactively, and taking initiative
Responsibilities
  • Build and maintain compliance frameworks - Lead the creation, enhancement, and lifecycle management of controls, evidence requirements, and implementation guidance for standards such as SOC 2, ISO/IEC 27001 & 27701, HIPAA, PCI DSS, NIST CSF, NIST SP 800-53, and regional regulations (e.g., GDPR/CCPA). Author clear control rationales, acceptance criteria, and customer-facing guidance.
  • Design crosswalks and mappings (framework-agnostic) - Create and steward an internal common-control approach informed by industry catalogs; Maintain bidirectional crosswalks across industry-leading security and privacy regulatory frameworks; Define canonical control IDs, mapping confidence, and evidence data dictionaries; version crosswalks with changelogs and traceability to source authority; Partner with Engineering to operationalize mappings in-product.
  • Elevate content quality and usability - Define standards for control wording, evidence specificity, testing method, and reviewer guidance; Establish content QA processes, audits, and metrics to continually improve outcomes.
  • Drive end-to-end GRC product enablement - Build modular content, guidance, and templates for risk management, issue & corrective action management, policy management, access reviews, customer trust artifacts, and third-party risk management.
  • Act as a product advisor across discovery & design - Partner with PM/Design to support feature discovery, review UI/UX for control, evidence, and review workflows, run usability tests, and author PRDs/acceptance criteria grounded in auditor and customer needs.
  • Author automated tests & continuous monitoring - Translate controls and infrastructure contexts into spec-level automated tests and detectors; define test logic, data sources/integrations, edge cases, and acceptance criteria; pair with Engineering to implement and maintain detectors with versioned mappings to frameworks for continuous monitoring.
  • Partner with Product to drive roadmap - Translate customer and market needs into GRC requirements, propose experiments, validate solutions through discovery with Design/UX Research; own backlog for framework/content improvements.
  • Enable AI-assisted compliance - Design and ship LLM-powered guidance and automation; translate SME knowledge into machine-readable specs; define gold-standard evaluation sets and acceptance criteria; implement guardrails; instrument features to monitor accuracy and drift.
  • Synthesize feedback loops - Analyze input from customers, auditors, partners, and internal teams to identify gaps and deliver iterative updates quickly and safely.
Desired Qualifications
  • Bachelor’s degree in Computer Science; advanced degree a plus
  • Experience with privacy regulations (GDPR/CCPA), risk quantification (e.g., FAIR), audit/assessor background, or B2B Software as a Service content/enablement
  • Certifications (preferred, not required) - CISA, CISSP, CCSK/CCSK+, ISO 27001 Lead Implementer/Lead Auditor, CIPM/CIPT, PCI-ISA/QSA
  • Open to using AI to amplify skills and strengthen work - curiosity, willingness to learn, and sound judgment in applying AI responsibly to improve efficiency and impact
  • Federal experience (e.g., FedRAMP) is a plus but not required

Vanta provides a SaaS platform that helps small to mid-sized organizations obtain and maintain SOC 2 certification through automated checks and continuous monitoring. The product integrates with a company’s systems to run checks, track control effectiveness, and generate ready evidence, reports, and submission-ready documentation. It differentiates itself by offering ongoing compliance instead of one-off audits, with scalable checks and automated workflows tailored to SMEs and tech companies. The goal is to make SOC 2 faster, cheaper, and easier to sustain so organizations can focus on their core business while keeping strong security controls.

Company Size

1,001-5,000

Company Stage

Series D

Total Funding

$500.1M

Headquarters

San Francisco, California

Founded

2018

Simplify Jobs

Simplify's Take

What believers are saying

  • Vanta tripled ARR to $300M since 2024, serving 16,000 customers including Atlassian and Snowflake.
  • LiteLLM switched to Vanta from Delve in April 2026 for reliable re-certification post-malware incident.
  • Partnership with Automat-it integrates Vanta into AWS Compliance Guard for HIPAA and PCI startups.

What critics are saying

  • Delve fraud erodes trust in automated compliance, driving 25% customer churn within 12 months.
  • Enterprise vendors like CrowdStrike bundle compliance tools, compressing Vanta margins by 2028.
  • API changes in AWS or Okta integrations break evidence collection, causing non-compliance by 2027.

What makes Vanta unique

  • Vanta's Agentic Trust Platform unifies compliance, risk, and proof with 1,400+ automated tests.
  • Vanta AI Agent automates questionnaires and vendor reviews 50% faster than manual processes.
  • Native Trust Center reflects live compliance posture, eliminating stale documentation issues.

Help us improve and share your feedback! Did you find this helpful?

Benefits

100% Benefits Coverage

Flexible & Remote Work

Paid Parental Leave

Unlimited PTO

Health & Wellness

401(k)

Growth & Insights and Company News

Headcount

6 month growth

-2%

1 year growth

-1%

2 year growth

-2%
Vanta
Apr 29th, 2026
Vanta crosses $300M in ARR as growth accelerates

Vanta reached $300M ARR just 9 months after hitting $200M, with growth rate increasing each of the past four quarters. 16,000 companies now use the platform.

Epium Limited
Apr 1st, 2026
LiteLLM drops Delve after security compliance dispute.

LiteLLM drops Delve after security compliance dispute. LiteLLM is replacing Delve and redoing its security certifications after a malware incident and escalating allegations around Delve's compliance practices. The company plans to use Vanta and an independent third-party auditor to verify its controls. LiteLLM, makers of a popular Artificial Intelligence gateway used by millions of developers, said it is severing ties with compliance startup Delve and will redo its security certifications with another provider and auditor. The move follows a damaging week in which LiteLLM's open source version was hit by credential-stealing malware. Before that incident, LiteLLM had obtained two security compliance certifications by hiring Artificial Intelligence compliance startup Delve. Those certifications are meant to confirm that a company has procedures in place to reduce the likelihood of security incidents. The reversal now raises fresh questions about the reliability of the earlier compliance work and about how LiteLLM intends to validate its controls going forward. Delve has been accused of misleading customers about their actual compliance status by allegedly generating fake data and relying on auditors that rubber-stamped reports. Delve's founder has denied those allegations and offered free re-tests and audits to all customers. The dispute intensified after an anonymous whistleblower renewed the claims and released alleged supporting receipts over the weekend. On Monday, LiteLLM CTO Ishaan Jaffer posted on X that his company will be using Delve competitor Vanta to re-certify and will find its own, independent third-party auditor to verify its compliance controls. The decision signals a clear break from Delve as LiteLLM responds to both the fallout from the malware incident and the broader controversy surrounding Delve's certification process. 52. Impact score. April 1, 2026 OpenAI says GPT-5 produces fewer false claims than earlier models, especially when it can browse the web. The gains look smaller without web access, underscoring how much reliability still depends on live sourcing. April 1, 2026 ARC-AGI-3 introduces interactive, instruction-free environments designed to test whether frontier Artificial Intelligence systems can adapt to genuinely novel situations. Early results show top models performing near zero, highlighting a sharp gap between pattern recognition and open-ended exploration. April 1, 2026 NVIDIA is reportedly running into manufacturing problems with Rubin Ultra as its planned package pushes beyond current TSMC capabilities. The issue centers on CoWoS-L packaging for a much larger multi-die, high-bandwidth memory design. April 1, 2026 Intel's Binary Optimization Tool is changing how executable applications run on Arrow Lake Refresh systems, with measurable gains in some workloads. Primate Labs found that the tool cuts instruction counts and aggressively shifts execution from scalar code to vector instructions, prompting Geekbench to label BOT-enhanced results. April 1, 2026 Medical chatbots from major tech companies are arriving quickly as questions grow about how little outside testing they receive before public release. A judge has also temporarily halted the Pentagon's effort to label Anthropic a supply chain risk, exposing a dispute escalated outside normal government channels.

Daily News N Blog
Mar 30th, 2026
Popular AI gateway startup LiteLLM ditches controversial startup Delve.

Popular AI gateway startup LiteLLM ditches controversial startup Delve. LiteLLM, makers of popular AI gateway used by millions of developers, has publicly announced that it is ditching compliance startup Delve and will redo its security certifications with another company and auditor. The announcement comes after LiteLLM's open source version fell victim to some horrific credential-stealing malware last week. Prior to the incident, LiteLLM had obtained two security compliance certifications by hiring AI compliance startup Delve. Such certifications are intended to verify that a company has procedures in place to minimize potential incidents. Delve has been accused of misleading its customers about their true compliance by allegedly generating fake data and using auditors that rubber-stamped their reports. Delve's founder has denied those allegations and offered free re-tests and audits to all of its customers. That denial encouraged the anonymous Delve whistleblower to double down, including releasing alleged receipts over the weekend. On Monday, LiteLLM CTO Ishaan Jaffer posted on X that his company will be using Delve competitor Vanta to re-certify and will find its own, independent third-party auditor to verify its compliance controls. After such a harsh week, LiteLLM is voting with its feet.

Business Wire
Mar 19th, 2026
Vanta launches AI agents to automate compliance and eliminate audit chaos for CISOs

Vanta, a trust management platform, has announced new AI agents and enterprise controls designed to automate compliance and security workflows. The suite includes context-aware agents for compliance, third-party risk management and customer trust, alongside privacy automation features for data governance. The company's agents operate as 24/7 GRC engineers, coordinating tasks, collecting evidence and surfacing material risks whilst keeping humans in decision-making roles. New enterprise capabilities include adaptive business unit scoping and a standardised control framework to reduce redundancy across multi-framework programmes. Vanta's privacy automation integrates data governance into broader compliance systems, centralising Record of Processing Activities management, data inventories and Data Protection Impact Assessments. The platform serves over 15,000 businesses, including Atlassian, Duolingo and Ramp.

Enactia
Mar 19th, 2026
Best GRC tool Cyprus: powering 2026 digital transformation.

Best GRC tool Cyprus: powering 2026 digital transformation. Cyprus is undergoing a "Digital Metamorphosis." As banks in Nicosia and shipping giants in Limassol move to the cloud, the risk landscape has shifted. A 2026 GRC tool must do more than store files; it must be the engine of your digital growth. * NIS2 and DORA Readiness: With the full enforcement of the NIS2 Directive and DORA, Cypriot critical entities and financial firms must prove operational resilience. * The M&A Wave: Following the 2025 consolidation in retail and banking, 2026 is the year of integration. Enactia helps merged entities unify their risk posture across legacy systems. * Fintech & Forex: For the massive CIF (Cyprus Investment Firm) sector, CySEC compliance and AML/KYC risk management are now automated within Enactia. The Enactia Edge: As a Nicosia-founded company, Enactia Ltd provide on-the-ground support that global competitors like Vanta or Drata cannot match. Its platform is the preferred choice for Cyprus firms transitioning from manual spreadsheets to automated governance. FAQ: GRC tools in Cyprus. * Why does a Cyprus company need a GRC tool? To centralize ISO 27001, GDPR, and local CySEC/FCA requirements into a single "Source of Truth." * Can Enactia host data in Cyprus? Yes. Enactia Ltd understand the local need for data sovereignty and offer hosting options that satisfy Cypriot regulators. * Does Enactia support local frameworks? Yes, including specific templates for the Cyprus Digital Strategy and local cybersecurity standards.