Full-Time

Account Executive

Secureframe

Secureframe

51-200 employees

AI-powered platform automating security compliance

Compensation Overview

$120k - $220k/yr

Washington, DC, USA

In Person

On-site in Washington, DC; approximately 30% in-office time within defined radius of Secureframe office.

Category
Sales & Account Management
Required Skills
Salesforce

Get referred to Secureframe

See people who can refer or advise you

Requirements
  • 5+ years of experience selling SaaS or compliance automation tools, specifically in the defense or highly regulated sectors
  • Proven track record as an Account Executive at A-LIGN, Schellman, or similar firms, with an existing network and pipeline engaged in CMMC, DFARS, or NIST compliance sales
  • Experienced in closing mid-market or enterprise deals (~$30K–$250K ARR) within 3–6 month sales cycles
  • Skilled with Salesforce or equivalent CRM tools for pipeline management and forecasting
  • Strong consultative selling, technical presentation, and demo skills—especially around compliance and security automation tools
  • Comfortable in fast-growing startup environments
Responsibilities
  • Own full sales cycle for mid‑market to enterprise accounts, closing deals in the $20K–$250K+ ARR range, leveraging your existing CMMC pipeline and network
  • Engage contacts developed at A‑LIGN, Schellman, or other compliance consultancies to drive outreach into DoD contractor organizations
  • Prospect and expand within target accounts using a multi-channel approach: cold outreach, referrals, LinkedIn, and defense-industry events
  • Deliver tailored product demos aligned with DFARS/NIST/CMMC compliance needs, showcasing how Secureframe’s platform accelerates readiness and maintains trust
  • Manage pipeline forecasting rigorously using Salesforce, collaborating with Sales Engineering, Marketing, RevOps, and Customer Success to drive deals through close
  • Provide in-market intelligence and feedback to inform product roadmap, GTM messaging, and compliance-focused sales strategies
  • Position Secureframe as the trusted automation provider for compliance frameworks throughout the defense ecosystem

Secureframe provides a platform that automates cybersecurity compliance, using AI to gather evidence, monitor controls, and simplify meeting security standards. It continuously inventories assets and user access to sensitive data, helping organizations identify risks in real time. The service is offered as platform-as-a-service, with pricing based on usage for managing security, risk, and compliance across multiple standards. Its goal is to help businesses protect data, demonstrate trust to customers, and accelerate growth by streamlining compliance and security management.

Company Size

51-200

Company Stage

Series B

Total Funding

$78.5M

Headquarters

San Francisco, California

Founded

2020

Get referred to Secureframe

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • CMMC Phase 2 begins November 2026, requiring mandatory third-party assessments for 80,000 defense contractors[3]
  • User Access Reviews automation addresses top compliance challenge: 25% of leaders cite audit preparation difficulty[news]
  • Strategic Coalfire partnership and CMMC.com platform expand federal compliance market reach and credibility[news]

What critics are saying

  • Only 800 of 80,000 target DIB contractors achieved CMMC certification by January 2026, signaling slow adoption[4]
  • Competitors Drata and Vanta offer superior integrations and aggressive pricing undercutting Secureframe's SMB market[negative]
  • NIST AI Risk Management Framework mandates specialized AI compliance audits beyond Secureframe's generalist platform focus[negative]

What makes Secureframe unique

  • AI-powered platform reduces CMMC certification timelines from 12-18 months to 4-8 weeks[1][2]
  • Deploys secure CUI enclaves in under 30 minutes versus traditional eight to ten week deployments[2]
  • Secureframe Defense automates System Security Plans, policies, and continuous monitoring for DIB organizations[1]

Help us improve and share your feedback! Did you find this helpful?

Benefits

Work anywhere in the US & Canada - We're a remote-first company with team members coast to coast. The office is wherever home and WIFI are.

Paid family leave - We encourage all parents to spend time with their children whether or not they are the primary caregiver.

Comprehensive health coverage - We care about our team’s well being — like, a lot. That's why we offer premium health, dental, and vision.

Unlimited vacation - We encourage our team to take the time they need to rest and recharge. (Just don’t forget to share a few vacation snaps on Slack!)

Team activities & offsites - We value having fun and spending time as a team. Regular company activities, meetups, and offsites help us stay connected.

Career development - From online classes and certifications to in-person training, we offer resources for ongoing personal and career growth.

Growth & Insights and Company News

Headcount

6 month growth

-1%

1 year growth

-2%

2 year growth

-3%
Scadable
Jul 12th, 2026
Vanta, Drata, Secureframe, and Oneleet: how the fix-first model is different.

Vanta, Drata, Secureframe, and Oneleet: how the fix-first model is different. An honest comparison of Vanta, Drata, Secureframe, and Oneleet. Each is genuinely good at what it does. None of them remediate findings, which is the one real gap Scadable is built to close. Vanta, Drata, Secureframe, and Oneleet are all real, well-built products, each genuinely good at parts of the compliance workflow. Vanta and Drata lead the category on breadth of frameworks and integrations, with large customer bases and mature self-serve motions. Secureframe competes at the same tier. Oneleet is the closest thing to a consolidated platform, combining AI risk review, code scanning, and pentest bundling. What none of the four do, by their own public product descriptions, is fix what they find. They identify a gap and hand it to a human to close. Scadable identifies the gap and closes it. That is not a knock on any of them. It is the honest shape of the category today, and it is worth naming plainly before making the one comparison that actually matters. What is Vanta actually good at? Vanta is the category leader by customer count, citing more than 16,000 customers and a dense wall of named logos across software companies. Its homepage leads with "trust," positions itself as an "Agentic Trust Platform," and backs that up with quantified time-saved metrics like thousands of hours saved annually and a large share of security questionnaires automated. Vanta's real strength is scale: broad framework coverage (SOC 2, ISO 27001, ISO 42001, GDPR, HIPAA, PCI DSS, FedRAMP, and more), a large integration catalog, and a self-serve-to-enterprise motion that has clearly worked for thousands of companies. If your need is broad, mature, self-serve coverage across many frameworks today, Vanta is a legitimate answer to that need. What is Drata actually good at? Drata sits at near feature parity with Vanta and uses almost identical language to describe itself, down to calling itself an "Agentic Trust Management Platform." It cites more than 8,500 customers and a 4.8 rating on G2, with its own metrics around audit-prep time reduction and hours saved annually. Like Vanta, Drata's strength is breadth: the same wide framework badge wall, a comparable integration footprint, and a product built for teams that want one dashboard covering everything from evidence collection to auditor-facing documentation. Drata's agentic layer automates evidence gathering and the paperwork that goes with it, which is a real and useful thing to automate well. What is Secureframe actually good at? Secureframe competes in the same tier as Vanta and Drata: evidence collection, continuous control monitoring, and audit-readiness workflows aimed at the same buyer. It is a known, credible option in this category for teams evaluating compliance automation platforms, and belongs in the same conversation as the other three. Its specific product depth is closer to Vanta and Drata's shape than to Oneleet's, built around the same evidence-and-monitoring core loop common to this category. What is Oneleet actually good at? Oneleet is the closest structural comparison to how Scadable is built: a single consolidated platform rather than a dashboard stitched to a separate audit process, combining AI-driven risk assessment, a code scanner, and pentest bundling in one place. It has real traction, a 4.9 rating on G2, more than 1,000 teams, and a $33 million Series A per public reporting. Oneleet's own homepage is also the most candid in the category about where its product stops: it describes its AI as reviewing evidence against control requirements and flagging issues. That is an honest, accurate description of what the tool does, and it is worth taking at face value rather than reading past it. Vanta, Drata, Secureframe, and Oneleet at a glance. | / | Genuine strength | Shared limitation | Scadable's approach | | Vanta | Largest customer base and logo density, deepest framework and integration breadth | Ends at a flagged gap list; remediation is manual | Identifies the gap and closes it | | Drata | Near-parity breadth with Vanta, strong G2 rating, mature agentic evidence automation | Automates the paperwork around a finding, not the fix | Writes the fix, not just the report | | Secureframe | Established, credible player in the same evidence-and-monitoring tier | Same category-wide pattern: evidence collection ends at a human handoff | Closes the finding inside the same pipeline that surfaced it | | Oneleet | Consolidated platform combining AI risk review, code scanning, and pentest referral | Own copy states it flags issues rather than fixing them | Reviews, fixes, and files, not just flags | What is the one real difference? Every one of these four platforms, by its own public positioning, ends at a list. Vanta and Drata's product loops are evidence collection, continuous monitoring, and questionnaire automation, all of which conclude with an open item for someone on your team to go close, in a pull request, a config change, or a Jira ticket outside the platform. Oneleet says this about itself directly: its AI reviews evidence against control requirements and flags issues. Flagging is genuinely useful. It is also, by every one of these four vendors' own description of their own product, where the automation stops. Scadable's product loop does not stop there. It identifies what needs to change, whether that is a missing control for SOC 2, a documentation gap under ISO 27001, or an actively exploited component across a device fleet under the Cyber Resilience Act, and then it writes the control, implements the configuration change, and closes the gap. The finding does not sit in a queue waiting for a human to get to it. That is the difference stated as plainly as it can be: they identify and flag, Scadable identifies and fixes. How does Scadable make sure its evidence can be trusted? Separately from the fix-versus-flag distinction, Scadable treats evidence integrity as a standing principle, not a feature. Every document and every approval Scadable generates lives in its own object storage, hashed, versioned, and write-once-read-many locked once finalized. Every document and approval carries a verification link. Nothing in that pipeline is a Google Doc that can be quietly edited after the fact. This matters because the entire value of compliance evidence is that it holds up to scrutiny months or years later, in front of an auditor or a regulator, exactly as it looked the day it was produced. Evidence that can be silently changed after the fact does not earn that trust, so Scadable's system is built so it cannot be. Frequently asked questions. What is the main difference between Scadable and Vanta, Drata, Secureframe, or Oneleet? All four collect evidence, monitor controls, and flag gaps for a human to close. Scadable closes the gap itself, writing the control, implementing the fix, and filing the report, not just producing a list of what is still open. Is Scadable a Vanta alternative? Scadable is a fix-first alternative for teams that want findings closed, not just flagged. If your priority is broad self-serve multi-framework coverage today across a large integration catalog, Vanta may genuinely be the better fit. If your priority is getting findings remediated, that is what Scadable is built around. Is Oneleet a good product? Yes. Oneleet is a well-built, consolidated platform bundling AI risk assessment, code scanning, and pentest referral, with real traction including a G2 rating of 4.9 and over 1,000 teams. Its own homepage copy describes its AI as reviewing evidence against control requirements and flagging issues, which is the same evidence-and-flag pattern shared across this category. Do Vanta, Drata, Secureframe, and Oneleet fix compliance and security findings automatically? No. All four are evidence-collection, monitoring, and questionnaire-automation platforms. Their product loops end with a list of open findings for a human to remediate, in a ticket, a pull request, or a spreadsheet, outside the platform itself. How does Scadable keep evidence trustworthy? Every document and approval Scadable generates lives in hashed, versioned, WORM-locked storage with a verification link. Once a piece of evidence is finalized it cannot be quietly edited, which matters because compliance evidence only has value if it holds up to scrutiny. Should I switch from Vanta or Drata to Scadable? That depends on what you actually need. If broad multi-framework self-serve coverage across a large number of integrations is your priority today, Vanta or Drata may be the right tool. If your findings keep piling up faster than your team can close them, Scadable is built specifically for that gap. Last reviewed: July 12, 2026. Where Scadable fits. Scadable is not trying to out-feature Vanta, Drata, Secureframe, or Oneleet on framework breadth or integration count. Breadth is table stakes at this point, any well-resourced team can build a wide badge wall and a long integrations list, and all four of these platforms already have. The differentiation is what happens after a gap is found: Scadable writes the fix and closes it, and every piece of evidence it produces is hashed, versioned, and verifiable on its own. If what you need today is broad, self-serve, multi-framework coverage across a mature integration catalog, one of the four platforms above may honestly be the right tool for that job. If what you need is for the findings to actually get closed instead of accumulating in a queue, that is what Scadable does. Book a call to see the fix-first model against your own stack.

Help Net Security
Apr 8th, 2026
Secureframe expands Comply with User Access Reviews for automated governance.

Secureframe expands Comply with User Access Reviews for automated governance. Secureframe has announced the launch of User Access Reviews, a new capability within Secureframe Comply. Access reviews are the primary mechanism organizations use to validate that the right people have the appropriate access, but the process has historically been manual, fragmented, and difficult to audit. Most teams still conduct access reviews using exported spreadsheets and email threads, creating accountability gaps and leaving security incidents waiting to happen. User Access Reviews eliminates that risk. The new capability replaces the manual, error-prone process with a structured, automated workflow so teams can assign reviewers, evaluate permissions, document decisions, and track remediation from a single platform, with a complete audit trail built in. "Access reviews are one of the most important security controls organizations have, but they're still often managed through spreadsheets and email threads," said Shrav Mehta, Founder and CEO of Secureframe. "User Access Reviews gives teams a simple way to evaluate access, document decisions, and ensure follow-through without turning the process into a coordination headache." Recent findings from Secureframe's 2026 Cybersecurity & Compliance Benchmark Report show that nearly one quarter of security and compliance leaders cite audit preparation as their single biggest challenge in 2026, with teams spending about eight hours per week on manual compliance tasks like evidence collection and documentation. Secureframe's User Access Reviews addresses all three dimensions of a mature access program in a single, streamlined dashboard: establishing governance frameworks that define who should have access and why, surfacing misplaced or outdated permissions before they become a liability, and generating defensible audit evidence on demand. Key capabilities: * Centralized review management. Pull user data from integrated systems or via CSV upload, scope reviews by application, assign reviewers, and complete the entire process within a single platform. * Accountable, access decisions. Reviewers confirm ownership and make explicit account-level decisions to maintain, modify, revoke, or mark access out of scope. Follow-up tasks can be created directly within the review workflow and sync with connected ticketing tools. * Automated scheduling and reminders. Configure recurring review cycles, designate reviewers per system, and rely on automated reminders and status indicators to keep reviews on track without manual follow-up. * Audit-ready documentation. Every review captures reviewer identity, decisions made, and remediation actions taken. Exportable summaries provide structured documentation that can be shared during audits, eliminating the need to reconstruct evidence from emails or spreadsheets. Security and privacy investment is accelerating: 99% of organizations report tangible benefits from their privacy programs, and 38% spent $5 million or more in the past year alone. Yet resources remain stretched. Meanwhile, 80% of AI leaders cite cybersecurity as the single greatest barrier to their AI strategy, and data leaks tied to generative AI are the top security concern heading into 2026. Secureframe Comply helps organizations turn these pressures into an advantage by pairing User Access Reviews with a comprehensive GRC automation platform that: * Supports compliance with leading security and privacy frameworks, including SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, NIST, and custom frameworks, so teams can manage access reviews in the same system they use to manage controls, evidence, and policies. * Continuously monitors for misconfigurations and failing controls, flagging issues in real time and providing tailored remediation guidance to help organizations maintain a strong security posture between audits. * Automates vendor risk management, employee training, and evidence collection, including AI-assisted policy development through Comply AI for Policies, giving teams more time to focus on higher-value work like tightening access to sensitive systems. "I saw how easy it was to use and how easy it would be to have a central location where we would keep all policies and documents. Secureframe would take care of pulling evidence from our cloud environment, authentication, and HR systems. Before Secureframe, our compliance team had to obtain evidence manually from each third party system," said Jair Basso, VP of Security, Wealth.com. More about

SiliconANGLE Media
Mar 10th, 2026
Secureframe unveils new platform to cut defense cyber certification timelines to weeks

Secureframe unveils new platform to cut defense cyber certification timelines to weeks. Compliance automation platform provider Secureframe Inc. today announced the launch of Secureframe Defense, an artificial intelligence-powered, end-to-end platform that helps defense industrial base contractors achieve and maintain Cybersecurity Maturity Model Certification compliance. Secureframe Defense is designed to deliver secure infrastructure deployment, AI-built System Security Plans, policies and comprehensive monitoring that DIB organizations need to achieve and maintain the certification faster, without unnecessary cost or complexity. CMMC is a U.S. Department of Defense framework that requires defense contractors and subcontractors to implement specific cybersecurity controls to protect controlled unclassified information, or CUI. The DOD estimates nearly 80,000 organizations will ultimately require CMMC Level 2 certification, yet fewer than 800 organizations have achieved certification as of January. Gaining the certification is not cheap, however. Many DIB organizations spend more than a year and $100,000 to $300,000 or more preparing for CMMC Level 2 certification. That's where Secureframe Defense steps in. "Secureframe Defense reflects everything we learned going through our own CMMC Level 2 assessment and the feedback we received from our partner Certified Third-Party Assessment Organizations about the real problems organizations face," said founder and Chief Executive Shrav Mehta. "Our AI-powered platform can take organizations with zero infrastructure to assessment-ready in less than eight weeks." Secureframe Defense guides organizations through three critical stages. Stage one is the deployment of secure CUI environments, with organizations now able to deploy a compliant enclave for handling CUI in under 30 minutes. The platform automatically configures environments such as Google Workspace or Microsoft GCC High with required CMMC controls, provisions Azure virtual desktops and applies secure device management baselines. Stage two involves AI-driven documentation and program management, in which Secureframe's Defense Navigator translates CMMC requirements into guided workflows. An AI engine generates tailored system security plans and policies, manages risk assessments and vendor reviews, assigns policies and delivers continuous control monitoring. The third stage includes certification support and ongoing compliance, with an audit module that automatically compiles documentation and evidence artifacts. According to Secureframe, the new offering reduces overall certification timelines from 12 to 18 months down to four to eight weeks, cutting readiness time significantly compared wit manual processes or point solutions. Secureframe is a venture capital-backed startup that has raised $79 million over three rounds, including a round of $18 million in March 2021. Investors in the company include Accomplice VC, Kleiner Perkins Caufield & Byers, Optum Ventures, Kaiser Foundation Health Plan Inc., Gradient Ventures, Soma Capital Management, Flexport Inc., Gaingels and Impatient Ventures. Image: Secureframe. A message from John Furrier, co-founder of SiliconANGLE: Support its mission to keep content open and free by engaging with theCUBE community. Join theCUBE's Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities. * 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more * 11.4k+ theCUBE alumni - Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network. About SiliconANGLE Media SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios - with flagship locations in Silicon Valley and the New York Stock Exchange - SiliconANGLE Media operates at the intersection of media, technology and AI. Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Its new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.

Secureframe
Jul 31st, 2025
Introducing the FedRAMP Hub: 15+ Free Resources to Simplify Authorization

That's why Secureframe, Inc. is excited to announce its new FedRAMP Hub, a collection of 15+ free resources that covers everything you need to know about this cloud security standard in one place.

VentureBeat
Jun 10th, 2025
Zencoder Just Launched An Ai That Can Replace Days Of Qa Work In Two Hours

Join the event trusted by enterprise leaders for nearly two decades. VB Transform brings together the people building real enterprise AI strategy. Learn more. Zencoder, the artificial intelligence coding startup founded by serial entrepreneur Andrew Filev, announced today the public beta launch of Zentester, an AI-powered agent designed to automate end-to-end software testing. This critical but often sluggish step can delay product releases by days or weeks.The new tool represents Zencoder’s latest attempt to distinguish itself in the increasingly crowded AI coding assistant market, where companies are racing to automate not just code generation but entire software development workflows. Unlike existing AI coding tools that focus primarily on writing code, Zentester targets the verification phase — ensuring software works as intended before it reaches customers.“Verification is the missing link in scaling AI-driven development from experimentation to production,” said Filev in an exclusive interview with VentureBeat. The CEO, who previously founded project management company Wrike and sold it to Citrix for $2.25 billion in 2021, added: “Zentester doesn’t just generate tests—it gives developers the confidence to ship by validating that their AI-generated or human-written code does what it’s supposed to do.”The announcement comes as the AI coding market undergoes rapid consolidation