Full-Time

Enterprise Account Executive

Drata

Drata

501-1,000 employees

Automates continuous security compliance monitoring

Compensation Overview

$270k - $315k/yr

+ RSUs + Variable Compensation

Los Angeles, CA, USA

Remote

Remote within the United States.

Category
Sales & Account Management (1)

Get referred to Drata

Find people who can refer or advise you

Requirements
  • 7+ years of experience in a customer-facing B2B SaaS Sales role, with at least 2 years in a closing new business capacity
  • Ability to focus on bringing in Enterprise accounts with 1K+ full time employees
  • Preferred background in the start-up space
  • Self-starter who brings ideas to life and takes pride in results
  • Resourceful, finding ways to get things done regardless of the obstacles
  • Mission-Driven and focused on using talents to make the world a better place
  • Organized and detail-oriented with an ability to handle a variety of different projects
  • A talented communicator and a “people person” who enjoys working with others. You are thoughtful about the ways you communicate and the impact that may have on a customer. You have the ability to sense when a conversation is progressing in a positive or negative way and have the confidence to address concerns.
  • Confident but always striving to do better. You are not afraid to ask for help. You value honest, action-oriented feedback and believe it is a tool to improve as a team
Responsibilities
  • Responsible for bringing new partners on board and consistently growing revenue by exceeding revenue targets/quota
  • Identify prospects based on their mission alignment
  • Develop and execute strategies for driving partnerships and revenue
  • Build and manage your pipeline of prospects; become an expert on a region and understanding the complexities of that specific market
  • Consult senior executives to discover their needs and educate them through an accelerated buying process
  • Identify opportunities to improve our product offering based on deep understanding of the needs of our partners
Desired Qualifications
  • Background in the start-up space

Drata automates security and regulatory compliance for fast-growing technology and SaaS companies. It helps achieve and maintain continuous compliance with standards such as SOC 2, ISO 27001, and HIPAA. The platform works by continuously monitoring a company’s security posture and automatically collecting audit evidence. It integrates with over 75 technologies to provide a unified view of compliance status, streamline workflows, and replace manual tasks (like screenshots and spreadsheets) with automated evidence gathering. Compared with competitors, Drata emphasizes continuous, end-to-end automation across a wide range of tools to keep organizations audit-ready as they scale. The company’s goal is to save time and resources for its customers while building and demonstrating trust through ongoing compliance, supported by a subscription business model with recurring revenue.

Company Size

501-1,000

Company Stage

Series C

Total Funding

$328.2M

Headquarters

San Francisco, California

Founded

2020

Get referred to Drata

Find people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • AI Agent Governance launched June 2026 addresses 30% surge in AI security questions from 8,500 organizations.
  • AI Trust Center Setup reduces build time from months to hours by auto-generating artifacts from existing evidence.
  • New procurement and spend integrations close finance-security gaps, auto-triggering vendor reviews for SOC 2 and ISO 27001.

What critics are saying

  • Vanta will undercut Drata's $7,500 minimum with a $5,000 startup plan, eroding SaaS revenue within 6–12 months.
  • AWS Guardrails or Azure AI Security may embed AIUC-1 natively within 12–18 months, eliminating Drata's third-party AI layer.
  • Sprinto's $12,000 unlimited FTE plan will win mid-market deals by undercutting Drata's $15,000 Foundation tier within 9–15 months.

What makes Drata unique

  • Drata uniquely supports AIUC-1, the first insurance-backed AI agent standard with $50M liability coverage.
  • Its Agentic TPRM Assessment automates vendor security reviews using live trust data instead of manual evidence collection.
  • Drata integrates with over 75 technologies including native Zip, Ramp, and Accio Data for automated compliance workflows.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health benefits

Learning enrichment stipends

Flexible PTO

Work from home stipend

401k

Parental leave

Growth & Insights and Company News

Headcount

6 month growth

↑ 0%

1 year growth

↑ 3%

2 year growth

↑ 3%
Scadable
Jul 12th, 2026
Vanta, Drata, Secureframe, and Oneleet: how the fix-first model is different.

Vanta, Drata, Secureframe, and Oneleet: how the fix-first model is different. An honest comparison of Vanta, Drata, Secureframe, and Oneleet. Each is genuinely good at what it does. None of them remediate findings, which is the one real gap Scadable is built to close. Vanta, Drata, Secureframe, and Oneleet are all real, well-built products, each genuinely good at parts of the compliance workflow. Vanta and Drata lead the category on breadth of frameworks and integrations, with large customer bases and mature self-serve motions. Secureframe competes at the same tier. Oneleet is the closest thing to a consolidated platform, combining AI risk review, code scanning, and pentest bundling. What none of the four do, by their own public product descriptions, is fix what they find. They identify a gap and hand it to a human to close. Scadable identifies the gap and closes it. That is not a knock on any of them. It is the honest shape of the category today, and it is worth naming plainly before making the one comparison that actually matters. What is Vanta actually good at? Vanta is the category leader by customer count, citing more than 16,000 customers and a dense wall of named logos across software companies. Its homepage leads with "trust," positions itself as an "Agentic Trust Platform," and backs that up with quantified time-saved metrics like thousands of hours saved annually and a large share of security questionnaires automated. Vanta's real strength is scale: broad framework coverage (SOC 2, ISO 27001, ISO 42001, GDPR, HIPAA, PCI DSS, FedRAMP, and more), a large integration catalog, and a self-serve-to-enterprise motion that has clearly worked for thousands of companies. If your need is broad, mature, self-serve coverage across many frameworks today, Vanta is a legitimate answer to that need. What is Drata actually good at? Drata sits at near feature parity with Vanta and uses almost identical language to describe itself, down to calling itself an "Agentic Trust Management Platform." It cites more than 8,500 customers and a 4.8 rating on G2, with its own metrics around audit-prep time reduction and hours saved annually. Like Vanta, Drata's strength is breadth: the same wide framework badge wall, a comparable integration footprint, and a product built for teams that want one dashboard covering everything from evidence collection to auditor-facing documentation. Drata's agentic layer automates evidence gathering and the paperwork that goes with it, which is a real and useful thing to automate well. What is Secureframe actually good at? Secureframe competes in the same tier as Vanta and Drata: evidence collection, continuous control monitoring, and audit-readiness workflows aimed at the same buyer. It is a known, credible option in this category for teams evaluating compliance automation platforms, and belongs in the same conversation as the other three. Its specific product depth is closer to Vanta and Drata's shape than to Oneleet's, built around the same evidence-and-monitoring core loop common to this category. What is Oneleet actually good at? Oneleet is the closest structural comparison to how Scadable is built: a single consolidated platform rather than a dashboard stitched to a separate audit process, combining AI-driven risk assessment, a code scanner, and pentest bundling in one place. It has real traction, a 4.9 rating on G2, more than 1,000 teams, and a $33 million Series A per public reporting. Oneleet's own homepage is also the most candid in the category about where its product stops: it describes its AI as reviewing evidence against control requirements and flagging issues. That is an honest, accurate description of what the tool does, and it is worth taking at face value rather than reading past it. Vanta, Drata, Secureframe, and Oneleet at a glance. | / | Genuine strength | Shared limitation | Scadable's approach | | Vanta | Largest customer base and logo density, deepest framework and integration breadth | Ends at a flagged gap list; remediation is manual | Identifies the gap and closes it | | Drata | Near-parity breadth with Vanta, strong G2 rating, mature agentic evidence automation | Automates the paperwork around a finding, not the fix | Writes the fix, not just the report | | Secureframe | Established, credible player in the same evidence-and-monitoring tier | Same category-wide pattern: evidence collection ends at a human handoff | Closes the finding inside the same pipeline that surfaced it | | Oneleet | Consolidated platform combining AI risk review, code scanning, and pentest referral | Own copy states it flags issues rather than fixing them | Reviews, fixes, and files, not just flags | What is the one real difference? Every one of these four platforms, by its own public positioning, ends at a list. Vanta and Drata's product loops are evidence collection, continuous monitoring, and questionnaire automation, all of which conclude with an open item for someone on your team to go close, in a pull request, a config change, or a Jira ticket outside the platform. Oneleet says this about itself directly: its AI reviews evidence against control requirements and flags issues. Flagging is genuinely useful. It is also, by every one of these four vendors' own description of their own product, where the automation stops. Scadable's product loop does not stop there. It identifies what needs to change, whether that is a missing control for SOC 2, a documentation gap under ISO 27001, or an actively exploited component across a device fleet under the Cyber Resilience Act, and then it writes the control, implements the configuration change, and closes the gap. The finding does not sit in a queue waiting for a human to get to it. That is the difference stated as plainly as it can be: they identify and flag, Scadable identifies and fixes. How does Scadable make sure its evidence can be trusted? Separately from the fix-versus-flag distinction, Scadable treats evidence integrity as a standing principle, not a feature. Every document and every approval Scadable generates lives in its own object storage, hashed, versioned, and write-once-read-many locked once finalized. Every document and approval carries a verification link. Nothing in that pipeline is a Google Doc that can be quietly edited after the fact. This matters because the entire value of compliance evidence is that it holds up to scrutiny months or years later, in front of an auditor or a regulator, exactly as it looked the day it was produced. Evidence that can be silently changed after the fact does not earn that trust, so Scadable's system is built so it cannot be. Frequently asked questions. What is the main difference between Scadable and Vanta, Drata, Secureframe, or Oneleet? All four collect evidence, monitor controls, and flag gaps for a human to close. Scadable closes the gap itself, writing the control, implementing the fix, and filing the report, not just producing a list of what is still open. Is Scadable a Vanta alternative? Scadable is a fix-first alternative for teams that want findings closed, not just flagged. If your priority is broad self-serve multi-framework coverage today across a large integration catalog, Vanta may genuinely be the better fit. If your priority is getting findings remediated, that is what Scadable is built around. Is Oneleet a good product? Yes. Oneleet is a well-built, consolidated platform bundling AI risk assessment, code scanning, and pentest referral, with real traction including a G2 rating of 4.9 and over 1,000 teams. Its own homepage copy describes its AI as reviewing evidence against control requirements and flagging issues, which is the same evidence-and-flag pattern shared across this category. Do Vanta, Drata, Secureframe, and Oneleet fix compliance and security findings automatically? No. All four are evidence-collection, monitoring, and questionnaire-automation platforms. Their product loops end with a list of open findings for a human to remediate, in a ticket, a pull request, or a spreadsheet, outside the platform itself. How does Scadable keep evidence trustworthy? Every document and approval Scadable generates lives in hashed, versioned, WORM-locked storage with a verification link. Once a piece of evidence is finalized it cannot be quietly edited, which matters because compliance evidence only has value if it holds up to scrutiny. Should I switch from Vanta or Drata to Scadable? That depends on what you actually need. If broad multi-framework self-serve coverage across a large number of integrations is your priority today, Vanta or Drata may be the right tool. If your findings keep piling up faster than your team can close them, Scadable is built specifically for that gap. Last reviewed: July 12, 2026. Where Scadable fits. Scadable is not trying to out-feature Vanta, Drata, Secureframe, or Oneleet on framework breadth or integration count. Breadth is table stakes at this point, any well-resourced team can build a wide badge wall and a long integrations list, and all four of these platforms already have. The differentiation is what happens after a gap is found: Scadable writes the fix and closes it, and every piece of evidence it produces is hashed, versioned, and verifiable on its own. If what you need today is broad, self-serve, multi-framework coverage across a mature integration catalog, one of the four platforms above may honestly be the right tool for that job. If what you need is for the findings to actually get closed instead of accumulating in a queue, that is what Scadable does. Book a call to see the fix-first model against your own stack.

Drata
Jun 17th, 2026
From intake request to security approved: how Zip and Drata automate vendor reviews.

From intake request to security approved: how Zip and Drata automate vendor reviews. Drata's Zip integration auto-creates vendor records and kicks off security reviews. No more manual handoffs. Every time your team submits a new vendor intake in Zip, someone on the security team has to be notified, a review has to be kicked off, and the result has to make its way back to procurement before anything gets approved. For fast-growing companies, this manual handoff is one of the most persistent sources of friction between procurement and security - and it often keeps third-party risk reviews stuck in spreadsheets or limited to only "critical" vendors, leaving gaps that raise overall risk. The Drata and Zip integration helps eliminate this. The problem: procurement and compliance don't talk to each other. Most companies manage vendor intake and vendor security in separate systems. Zip handles the procurement side - intake submissions, approval workflows, spend controls. Drata handles the compliance side - vendor security reviews, evidence collection, control monitoring. The gap between them is manual. Someone on the procurement team submits a vendor intake in Zip and emails the security team. The security team creates the vendor record in Drata and kicks off a review. Eventually they email back with an approval. The whole process takes days, sometimes weeks - and requires both teams to stay in sync across systems that don't communicate. For companies targeting SOC 2, ISO 27001, or any framework that requires vendor due diligence, this friction doesn't just slow things down - it creates risk. Vendors can get approved for spend before a security review is complete. The solution: Zip x Drata integration. Drata now integrates directly with Zip. When a team member submits an intake request in Zip for a new vendor, Drata detects it automatically and does three things: * Creates the vendor record in Drata - no manual entry required. * Maps standard fields from Zip intake directly to the Drata vendor record, so all context carries through. * Kicks off a vendor security review according to your configured Drata program settings. When the review is complete and approved in Drata, the status syncs back to Zip automatically. Procurement sees the approval. Vendor onboarding keeps moving. No email chains. No duplicate data entry. No vendor slips through the gap. How it works: step by step. * A team member submits an intake request in Zip and selects a new vendor. * Zip detects that the vendor is new and triggers the Drata integration. * Drata automatically creates the vendor record and starts a security review based on your program configuration. * Relevant documents (SOC 2, ISO certification, bridge letters, pen test reports) are attached automatically based on your configured document type filters. * The security team completes and approves the review in Drata. * Drata syncs the approval back to Zip via webhook - immediately and at scale. * The Zip request is now cleared for approval with a verified security review on record. What's Included in the Integration. * Standard Zip vendor fields can map to Drata vendor records out of the box. Custom fields are on the roadmap for a future phase. * Vendor contact name and email from the Zip vendor contact object are automatically mapped to Drata - no manual configuration needed. * Intake data can be converted to PDF and attached directly to the Drata vendor record. * Document attachments are filtered by type (SOC 2, ISO, bridge letters, pen test) and are configurable per deployment. * Deep links to Drata vendor records are now returned directly in the Zip API response. Setup in Drata. In Drata, go to Settings | Integrations and select Zip. From there: * Generate API credentials with the required scopes. * Paste credentials into Zip - the integration pulls what it needs automatically. * Configure field mappings and set the default Drata User ID as vendor owner. * Select which document types should be attached per deployment. That's the setup. Once live, the integration runs in the background - no ongoing configuration needed. Get started. The Zip x Drata integration is available now. If you use both Zip and Drata, connect the integration in Settings | Integrations in your Drata account. Not yet a Drata customer? See how Drata works and book a demo now. Monica Olmsted is Group Lead of Partner Marketing at Drata, where she leads revenue-generating co-marketing strategies with strategic partners - especially cloud service providers - and helps scale Drata's partner ecosystem. Before Drata, she held partner marketing roles at Seismic and led partner communications and marketing communications at Sesame Software, bringing a strong blend of partnership strategy, multi-channel marketing, and storytelling to every program. She holds a BFA in Visual & Performing Arts from Cornish College of the Arts (cum laude). Partnerships Get biweekly expert insights so you never miss what's next. Chart your course. Navigate to new worlds of trust with Drata.

Valiido
Jun 1st, 2026
Valiido vs Drata for ISO(R) 27001 and TISAX(R).

Valiido vs Drata for ISO(R) 27001 and TISAX(R). Drata is a strong product - a broad compliance-automation platform covering more than 30 frameworks, built around integrations and automated evidence collection for larger organizations running multiple compliance programs at once. Valiido takes the opposite approach: one specialized ISMS platform, built for small and mid-sized companies and for exactly two standards - ISO(R) 27001 and TISAX(R). Which philosophy fits you depends on your size, your stack and what you actually need to achieve. Here is the factual comparison. Head to head Valiido vs Drata at a glance. All statements about Drata verified against drata.com in June 2026.

Drata
Apr 29th, 2026
From spend request to security approved: how Ramp and Drata automate vendor reviews.

From spend request to security approved: how Ramp and Drata automate vendor reviews. Drata and Ramp now integrate to automate vendor security reviews from spend requests, closing the loop between procurement, security, and compliance. Every time someone adds a new vendor in Ramp, security or GRC needs to get involved, a review has to start, and the decision needs to find its way back to procurement before the purchase moves forward. That manual handoff is one of the most persistent points of friction between finance and security. It slows down purchasing, adds back-and-forth over email and tickets, and makes it harder to prove that every vendor was actually reviewed. The Drata and Ramp integration closes that gap. The challenge: procurement and compliance live in different systems. Most companies manage vendor spend and vendor security in separate tools. Ramp owns spend requests, approvals, and budget controls. Drata owns vendor security reviews, evidence collection, and control monitoring. The connection between them is usually email, tickets, and spreadsheets. It starts when someone on the finance team adds a vendor in Ramp and emails security. Then, the security team creates the vendor in their own system and kicks off a review. Eventually, someone sends an approval back so the request can move forward. The whole process can take days or weeks and depends on both teams staying perfectly in sync across systems that don't actually talk to each other. For companies working toward SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, or any framework that requires vendor due diligence, this isn't just an efficiency problem. It creates real risk when vendors are approved for spend before a security review is complete. The solution: The Ramp x Drata integration. Drata now integrates directly with Ramp to connect spend management with vendor security compliance. When a team member submits a spend request in Ramp that includes a new vendor, Drata detects it automatically and: * Creates the vendor record in Drata - no redundant data entry. * Maps any configured custom fields from the Ramp form directly to the Drata vendor record, so context carries through. * Kicks off a vendor security review based on your Drata program configuration. When the review is complete and approved in Drata, the status syncs back to Ramp automatically - every hour by default, or immediately via manual sync. Finance sees when a vendor is cleared, and procurement keeps moving without tracking down status over email or Slack. No email chains. No copy-paste. No vendors slipping through the gap between procurement and security. How the integration works. Here's what happens behind the scenes once Ramp and Drata are connected: * A team member submits a spend request in Ramp and selects a new vendor. * Ramp detects that the vendor is new and triggers the Drata integration. * Drata automatically creates the vendor record and starts a security review based on your program configuration (review type, deadline, and required fields). * The security team completes and approves the review in Drata. * Drata syncs the approval back to Ramp automatically every hour, or immediately via manual sync. * The Ramp request is cleared for approval with a documented security review on record. From the requester's perspective, they stay in their existing Ramp workflow. From the security team's perspective, every new vendor appears in Drata with the right details and a linked review, without manual intake work. How finance and security teams benefit. The Ramp x Drata integration is designed for companies where finance and security need to stay aligned - without turning every new vendor into a multi-week project. Finance and procurement teams can eliminate manual notifications to security every time you add a vendor. Instead, Drata picks up new vendors from Ramp automatically and starts the review. They can also see review status without leaving Ramp, so they know exactly when a vendor is ready for approval. It helps keep spend moving without waiting on email threads or chasing approvers. For security and compliance teams, they see every new vendor requested in Ramp in the Drata vendor security review queue automatically. They can stop chasing procurement for vendor details or re-entering the same information in multiple systems. Plus they can configure review types, deadlines, and required fields once in Drata - the integration applies those settings every time. Get set up in under 10 minutes. Connecting Ramp and Drata does not require engineering work in most environments. You can get up and running in a few steps: * In Ramp, go Company > Integrations and select for Drata * Select Connect and follow instructions to create an OAuth application in Drata. * In Drata, go to Settings | Integrations and select Ramp. * Create an application in Drata with the required API scopes: Events, VendorCreate, VendorCreateUpdate, VendorCreateAndRead, and VendorSecurityReviews. * Copy the application credentials into Ramp. The integration pulls the required data from Drata automatically. * Configure a Drata Program with your review type, deadline, and any field mappings from your Ramp forms. Once live, the integration runs in the background. You manage your vendor security reviews in Drata; Ramp reflects the latest status automatically. Who this is for. The Ramp x Drata integration is built for teams that want procurement and compliance to move in lockstep from the start. For instance, organizations building or maturing a compliance program toward SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, or similar frameworks with vendor due diligence requirements will also see value. If you're scaling procurement and expecting vendor reviews to happen automatically, not through ad hoc email, or if you want to cut the back-and-forth between procurement and security on every new vendor, this integration is designed with your needs in mind. It removes friction without forcing teams to abandon their existing workflows. Common questions, answered. Does this work with existing vendors in Ramp? The integration triggers for new vendors that Ramp hasn't seen before. Requests for existing vendors continue to follow your current workflow. What if I need the sync to happen immediately? Drata syncs vendor review status back to Ramp automatically every hour. If you need an immediate update, you can trigger a manual sync from the integration flow. Can I control which fields carry over from Ramp to Drata? Yes. When you configure a Drata Program, you define which Ramp form fields - including custom fields - map to which Drata vendor fields. The information entered in Ramp carries through to Drata according to those mappings. What compliance frameworks does this support? Vendor security reviews completed in Drata through the Ramp integration support Drata's framework library, including SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, and others, and can be used as evidence across applicable frameworks. Getting started. The Ramp x Drata integration is available today. If you already use both Ramp and Drata, open Settings | Integrations in your Drata account and select Ramp to connect the integration. Not using Drata or Ramp yet? See how Drata connects to your existing stack and book a demo to explore how Ramp and Drata can help you automate vendor security reviews end to end. Monica Olmsted is Group Lead of Partner Marketing at Drata, where she leads revenue-generating co-marketing strategies with strategic partners - especially cloud service providers - and helps scale Drata's partner ecosystem. Before Drata, she held partner marketing roles at Seismic and led partner communications and marketing communications at Sesame Software, bringing a strong blend of partnership strategy, multi-channel marketing, and storytelling to every program. She holds a BFA in Visual & Performing Arts from Cornish College of the Arts (cum laude). Get biweekly expert insights so you never miss what's next. Chart your course. Navigate to new worlds of trust with Drata.

The Associated Press
Mar 24th, 2026
Drata launches agentic AI to automate third-party risk assessment and security questionnaires

Drata, a trust management platform, has unveiled agentic AI capabilities designed to automate enterprise trust workflows. The company is addressing third-party risk management and customer assurance with AI agents that autonomously handle security assessments and questionnaires. The Agentic TPRM Assessment, now available to all customers, automates vendor security reviews by accessing live trust data and eliminating manual evidence collection. Agentic Questionnaire Response, currently in beta, orchestrates the complete security questionnaire lifecycle whilst maintaining human oversight. Drata also introduced AI Trust Center Setup, which reduces initial build time from months to hours by automatically generating complete trust centres from existing artifacts. The company appointed Bharat Guruprakash as Chief Product and Technology Officer to advance its platform, which serves 8,000 organisations worldwide.