V

Vanta

Automates evidence collection and audit readiness

Staff Software Engineer - AI and Data Risk

Full-TimeUpdated on 10/1/2026
No salary listed
Senior, Expert
London, UK
HybridLondon-area engineers are expected in the office 2–3 days weekly; UK/Ireland-based engineers elsewhere travel to London roughly quarterly.

About the job

Requirements
  • At least 10 years of industry experience as a software engineer.
  • Served as a technical lead for large projects lasting 6 or more months, including defining roadmaps for complex projects spanning multiple teams and functions.
  • Set technical direction or built systems with impact beyond the immediate team, such as shared infrastructure, cross-team standards, or platform decisions adopted by other teams.
  • Built successful software-as-a-service products for both startup and enterprise users.
  • Have previous startup experience or experience in an environment that prioritizes a bias for action.
  • Upleveled teams of engineers through mentoring and leading by example.
  • Have experience working at rapidly scaling startups and large companies, especially in environments that prioritize a bias for action.
Responsibilities
  • Identify, scope, and lead large technical projects, establishing groundwork for core products to evolve and scale into highly performant, reliable, and customizable systems.
  • Design, develop, and own new product functionality and/or infrastructure using modern frameworks and tools, including TypeScript, React, and Node.js.
  • Make effective tradeoffs that consider business priorities, user experience, and a sustainable technical foundation.
  • Set technical direction that shapes how multiple teams build in privacy and artificial intelligence governance.
  • Help establish and shape engineering practices as the company expands in the UK and Ireland, including interviewing, hiring, and onboarding new teammates.
  • Set a high bar for engineering culture and excellence, multiplying the impact of surrounding teams through mentorship and technical leadership.

About the company

Vanta provides cloud-based software to help organizations prove and maintain security, privacy, compliance, and trust. Its platform automates evidence collection, control monitoring, and audit preparation across frameworks such as SOC 2, ISO 27001, HIPAA, and PCI, and also handles security questionnaires and customer-facing trust centers. It includes modules for risk management, third-party risk management, personnel and access controls, AI governance, and an AI-enabled agent to support compliance workflows, with integrations to existing business tools. The goal is to help organizations continuously demonstrate security and compliance, reduce audit effort, and build trust with customers by embedding governance and risk management into daily operations.

Company Size

1,001-5,000

Company Stage

Series D

Total Funding

$503M

Headquarters

San Francisco, California

Founded

2018

Get referred to Vanta

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • April 2026: Vanta crossed $300 million ARR, growing 63% year over year.
  • August 2026: Sarah Scharf became CMO, sharpening trust branding during AI governance demand.
  • 2026 partnerships with Carahsoft and Cloud Combinator expand federal and AWS distribution.

What critics are saying

  • Drata, Secureframe, and Oneleet compress Vanta's pricing power with clearer pricing and narrower bundles.
  • Vanta still hides enterprise pricing, inviting procurement delays and discount pressure in 2026.
  • If AI trust workflows commoditize, Vanta becomes a feature inside larger GRC suites.

What makes Vanta unique

  • September 2026: Vanta combines 16,000 customers, 400-plus integrations, and auditor-recognized exports.
  • April 2026: Vanta Government Cloud won FedRAMP 20x Moderate authorization for public-sector credibility.
  • Vanta acquired Riskey in 2026, adding continuous AI-powered security reviews.

Help us improve and share your feedback! Did you find this helpful?

Benefits

100% Benefits Coverage

Flexible & Remote Work

Paid Parental Leave

Unlimited PTO

Health & Wellness

401(k)

Growth & Insights and Company News

Headcount

6 month growth

↑ 2%

1 year growth

↑ 5%

2 year growth

↑ 4%
50 States Today
Sep 22nd, 2026
Shadowbear earns SPECTRA Level 1 certification, an insurer-recognized standard for managed security providers.

Shadowbear earns SPECTRA Level 1 certification, an insurer-recognized standard for managed security providers. Independent certification verifies the operations behind the Ashburn firm's Cyber Defense Suite, giving small businesses and insurers an outside reference point Every managed security provider tells you someone is watching your environment around the clock. Almost none of them can hand you an outside inspection that says so." - Ian Garrett, Founder, Shadowbear ASHBURN, VA, UNITED STATES, September 22, 2026 / EINPresswire.com / - Shadowbear, a managed cybersecurity provider for businesses that have no security team of their own, has earned SPECTRA Level 1 certification and been issued a SPECTRA Certificate of Resilience, an independent standard that measures a security provider against what cyber insurers expect rather than against its own marketing. SPECTRA launched its managed service provider resilience certification in June 2025 as a company-level standard, not an individual credential or a self-reported checklist. Its cyber risk advisory board is chaired by Dr. Michael Sulmeyer, former Assistant Secretary of Defense for Cyber Policy. The program certifies providers at four levels: Approved, Level 1, Level 2, and Level 3. SPECTRA describes certified providers as delivering independently verified protection that is trusted by leading cyber insurers. Certification at Level 1 required Shadowbear to submit documented evidence against technical, operational, and financial standards, not only its technology. That included written information security governance, a standard incident response playbook, contract governance covering how client agreements are issued and how deviations are reviewed and approved, staff qualifications, and the operating practices behind its 24/7 managed detection and response service. "Every managed security provider tells you someone is watching your environment around the clock. Almost none of them can hand you an outside inspection that says so," said Ian Garrett, founder of Shadowbear. "The customer gets a second professional opinion they did not have to go find themselves and they get a warranty backing their service." The certification also connects to the insurance side of the problem. Certified providers are listed among SPECTRA's verified partners and can be referred by participating carriers and brokers, and SPECTRA backs certified services with the SpectraCare performance warranty, which refunds the service if it fails to hold up against events such as ransomware or business email compromise. For a business asked at every renewal to prove the controls behind its coverage, a certified provider is one fewer open question on the application. "Buyers of managed security have very little way to check what they are told before they sign," said Edouard von Herberstein, founder and CEO of SPECTRA. "Shadowbear put its governance, incident response, contracts, and service operations in front of an independent review built around what cyber insurers underwrite, and met the Level 1 standard. That is something its clients, and their insurers, can rely on." Shadowbear's Cyber Defense Suite combines 24/7 managed detection and response, security monitoring, endpoint protection, employee phishing training, vulnerability scanning, and patching in a single per-user subscription. The company works mainly with businesses that handle sensitive information and have no dedicated security staff: defense subcontractors meeting NIST SP 800-171 and CMMC obligations, accounting and financial services firms, and other regulated small businesses in Northern Virginia and beyond. Shadowbear was ranked No. 35 on the Washington Business Journal's 2026 list of Cybersecurity Companies in Greater Washington. Businesses can request a free 30-minute Cyber Defense checkup at shadowbear.com/contact. The checkup reviews what a company already pays for, flags overlapping or unused security tools, and identifies the gaps an insurer, auditor, or customer questionnaire would surface. About Shadowbear Shadowbear is a veteran-owned managed cybersecurity provider based in Ashburn, Virginia. Its Cyber Defense Suite gives businesses 24/7 managed detection and response, security monitoring, employee phishing training, and compliance support for frameworks including CMMC, NIST SP 800-171, SOC 2, and ISO 27001, with no internal security team required. Shadowbear is SPECTRA Level 1 certified and a Vanta partner. Learn more at shadowbear.com. About SPECTRA SPECTRA is an independent cyber risk management firm that certifies managed service providers against technical, operational, and financial standards and backs certified services with the SpectraCare performance warranty. Learn more at spectracyber.com. Media contact Ian Garrett, Founder, Shadowbear [email protected] Legal Disclaimer: EIN Presswire provides this news content "as is" without warranty of any kind. 50 States Today do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

DevToolLab
Sep 5th, 2026
Best SOC 2 compliance automation platforms in 2026: Vanta vs Drata vs Secureframe vs Sprinto.

Best SOC 2 compliance automation platforms in 2026: Vanta vs Drata vs Secureframe vs Sprinto. DevToolLab Team September 5, 2026 SOC 2 is the report a US enterprise buyer's procurement team asks for before a contract clears, and most of the work behind it is evidence: proof that MFA is enforced, that access was reviewed last quarter, that the laptop fleet is encrypted, that a policy exists and someone signed it. Compliance automation platforms connect to your cloud accounts, identity provider, HR system and repositories, collect that evidence continuously, and hand an auditor a dashboard instead of a shared drive. Of the eight platforms compared here, exactly one prints a number on its public pricing or plans page: Secureframe's Fundamentals package, "starting at $7,000/year." Everyone else, including both market leaders, routes you to a demo. That opacity sits on top of a very large business. Vanta reported $300 million in annual recurring revenue in April 2026 and raised at a $4.15 billion valuation in July 2025, Drata paid $250 million for the trust-center startup SafeBase in February 2025, and challenger Oneleet raised a $33 million Series A in October 2025 on $9 million of ARR with the pitch that incumbents sell "compliance theater." The category is consolidating and re-pricing at the same time, which is a bad moment to buy blind. What you are actually buying. Three layers hide behind the phrase "compliance automation," and vendors bundle them differently. The first is evidence collection and continuous monitoring: integrations that read your AWS, GitHub, Okta and Rippling configurations and flag a failing control before the auditor does. Every platform here sells this, and the differences are integration count, how many frameworks the controls map to, and how much the AI layer drafts for you. The second is the audit itself. SOC 2 reports are issued by a licensed CPA firm, and most platforms hand you to a partner network. Thoropass is the exception that is the audit firm, and Oneleet bundles the security work (pentest, scanning) that a serious auditor will ask about anyway. The third is trust: a public trust center, questionnaire automation and vendor-risk reviews, which is where the incumbents spent their acquisition money and where the add-on pricing lives. Vanta. Vanta is the market leader by the numbers it publishes about itself: more than 16,000 customers and 1,000 employees per Fortune's April 2026 coverage of the $300 million ARR milestone, and $504 million raised since 2021. The plan ladder is Essentials, Plus, Professional and Enterprise, all "personalized pricing." Essentials is scoped to one compliance framework with the agentic policy generator, automated evidence collection, an auditor API and a Trust Center. Plus adds automated policy onboarding, access management and 25 AI-answered security questionnaires a year. Professional raises that to 144 questionnaires, adds risk management, custom monitoring tests and six customizable reports. Enterprise is a fully custom package. What it does well. Breadth. The auditor network and AI agent are the most complete here, Vanta lists 400+ integrations against Sprinto's 300+, and with 16,000 customers your auditor has almost certainly seen a Vanta export before. What to watch. Every framework beyond the first, every questionnaire block and the security-review add-on is a line item, and none of them has a public price. Budget for the negotiation. Pricing: Essentials, Plus, Professional, Enterprise · all quote-based · questionnaire automation 25 or 144 per year by tier Drata. Drata reached a $2 billion valuation in December 2022 and has spent since then moving upmarket: the $250 million SafeBase acquisition brought a trust center and security-review product in-house, and the homepage now leads with "Enterprise GRC" ahead of compliance automation. There is no plan ladder to read at all. The pricing URL lands on the homepage, which segments buyers into Startup, Growth and Enterprise stages, and every path ends at a "Contact Sales" button with no numbers. The homepage cites a customer that cut SOC 2 audit duration by 75% and cross-mapped controls to other frameworks in two hours, and a G2 rating of 4.8. What it does well. Control mapping across frameworks ("map once, reuse everywhere") and the GRC layer for companies that have outgrown a single SOC 2 report and are managing ISO 27001, HIPAA and PCI at once. What to watch. A startup that needs one Type II report is not the customer the pricing page is written for. Ask what Growth actually includes. Pricing: No published tiers · contact sales Secureframe. Secureframe is the one vendor willing to anchor the conversation. Fundamentals is "starting at $7,000/year" and covers infrastructure monitoring, custom frameworks, controls and tests, and evidence collection. Complete adds third-party risk management, advanced risk management and user access reviews. Defense is built for CMMC, with a SPRS score tracker, System Security Plan and POA&M tooling for teams selling to the US Department of Defense. The company raised $56 million in 2022 and, unusually, its pricing page carries a banner about a CMMC pause and what defense contracts still require. What it does well. A published floor, and the only dedicated CMMC package in this group (Vanta, Drata and Sprinto list CMMC as a supported framework, but none sells SSP and POA&M tooling as a tier), which matters if federal contracts are on your roadmap. What to watch. "Starting at" means the $7,000 covers a small scope; every framework and add-on moves the quote up from there. Pricing: Fundamentals from $7,000/year · Complete and Defense quote-based

wallstreet:online AG
Aug 22nd, 2026
Vanta announces closing of First Tranche of Private Placement and board of Directors Update.

Vanta announces closing of First Tranche of Private Placement and board of Directors Update. VANCOUVER, BC / ACCESS Newswire / August 21, 2026 / Vanta Holdings Inc. (CSE:VNTA)(OTC:VNTXF)(FSE:7BC, WKN:A4205J) ("Vanta" or the "Company"), a consumer health sciences and longevity company focused on preventative wellness and healthspan... VANCOUVER, BC / ACCESS Newswire / August 21, 2026 / Vanta Holdings Inc. (CSE:VNTA)(OTC:VNTXF)(FSE:7BC, WKN:A4205J) ("Vanta" or the "Company"), a consumer health sciences and longevity company focused on preventative wellness and healthspan extension, and parent of the Vanta premium longevity brand, announces that, further to its news release dated May 29, 2026, the Company has closed the first tranche (the "First Tranche") of its previously announced non-brokered private placement (the "Private Placement"), through the issuance of 124,579 units of the Company (each, a "Unit") at a price of $1.00 per Unit, for aggregate gross proceeds of $124,579.42. Each Unit consists of one common share in the capital of the Company (each, a "Share") and one transferable common share purchase warrant (each, a "Warrant"). Each Warrant entitles the holder to acquire one additional Share (each, a "Warrant Share") at an exercise price of $1.25 per Warrant Share, exercisable until August 21, 2028. The securities issued under the Private Placement will be subject to a statutory hold period expiring December 22, 2026. The Private Placement remains ongoing following the closing of the First Tranche. The Company expects to close the remaining portion of the Private Placement, in whole or in part, in one or more additional tranches on or before October 5, 2026, subject to compliance with the policies of the Canadian Securities Exchange. This press release shall not constitute an offer to sell or the solicitation of an offer to buy securities in the United States, nor shall there be any sale of the securities in any jurisdiction in which such offer, solicitation or sale would be unlawful. The securities being offered have not been, nor will they be, registered under the U.S. Securities Act of 1933, as amended (the "1933 Act"), or under any U.S. state securities laws, and may not be offered or sold in the United States absent registration or an applicable exemption from the registration requirements of the 1933 Act and applicable state securities laws. Board of Directors Update The Company also announces, that Mr. Norman John Campbell has resigned from the Company's board of directors, effective August 21, 2026, as he transitions to a new professional opportunity as a partner in an asset management firm and seeks to avoid potential conflicts associated with his new role. The Company extends its sincere appreciation to Mr. Campbell for his longstanding service and contributions to Vanta and wishes him continued success in this next chapter of his career. Following Mr. Campbell's resignation, Vanta's board of directors is comprised of four members, including two independent directors and two non-independent directors. Accesswire Autor folgen Mehr anzeigen We are ACCESS Newswire, a globally trusted Public Relations (PR) and Investor Relations (IR) solutions provider. With a focus on innovation, customer service, and value-driven offerings, ACCESS Newswire empowers brands to connect with their audiences where it matters most. From startups and scale-ups to multi-billion-dollar global brands, we ensure your most important moments make an impact and resonate with your audiences. Verfasst von Letzte Änderung22.08.2026, 04:55

Panoptic Scans
Aug 12th, 2026
Stop treating SOC 2 vulnerability scanning like a checkbox.

Stop treating SOC 2 vulnerability scanning like a checkbox. Stop treating SOC 2 vulnerability scanning like a checkbox written on aug 12, 2026. Posted in how-to. The annual scan is dead. Auditors stopped accepting a single 300-page Nessus PDF years ago. Under CC7.1, SOC 2 vulnerability management requires continuous monitoring. A vulnerability disclosed today affects code you shipped six months ago; finding out about it during your annual audit means you failed the control. You need a defined way to identify newly discovered flaws affecting the packages your software already uses. If your tool alerts the team when a new CVE affects lodash or spring-core, that alert becomes part of your CC7.1 evidence. The process matters more than the specific scanner you buy. Panoptic Scans, LLC. saw a Series B startup fail their Type II audit earlier this year because they had no ticket history showing they actually fixed the critical findings their scanner found. They bought the tool but ignored the alerts. What auditors actually look for in 2026. A strong process includes automated scanning, alert review, severity-based SLAs, ticket history, and reporting. Your tooling can vary, but the evidence must show a repeatable process. * Infrastructure Scanning: Checks the operating system and network layers for open ports, outdated Linux kernels, and missing patches on web servers like Nginx. * Dynamic Application Security Testing (DAST): Crawls your application to inject commands, execute cross-site scripting, and find misconfigurations in HTTP headers. Authenticated scans catch the flaws hiding behind your login screen. * Software Composition Analysis (SCA): Looks at your package.json or requirements.txt files to see if you import libraries with known flaws. * Cloud Security Posture Management (CSPM): Scans your AWS or Azure environments for public S3 buckets and overly permissive IAM roles. You can automate much of this. Hosted Nuclei scans run continuously against your external attack surface. Panoptic Scans integrates directly with Vanta to pull your scan results into your compliance dashboard automatically. You don't have to manually upload CSVs every Friday at 4pm. Set SLAs you can actually meet. SOC 2 does not mandate specific remediation timelines. You define them in your security policy. Common industry practice sets clear deadlines based on severity. | Severity | Expected SLA | Audit Reality | | Critical | 7 to 15 days | Requires immediate Jira ticket and verified fix | | High | 30 days | Must not exceed the SLA window | | Medium | 90 days | Often accepted as risk exceptions if documented | | Low | 180 days | Rarely scrutinized unless ignored entirely | Missing your own documented SLAs is a frequent audit failure. Do not promise 24-hour remediation for high-severity bugs if your engineering team deploys once a week. Set a 30-day SLA. Meet it consistently. Auditors prefer a slow, reliable process over a fast, broken one. Focus on context-aware prioritization that factors in asset criticality and exposure. A critical CVE on an internal testing server matters less than a medium-severity flaw on your public API gateway. Stop fighting your compliance tools. Automate the discovery phase and let the scanners generate the evidence for you.

Associated Press
Aug 12th, 2026
Vanta names Sarah Scharf CMO as trust platform hits $300M ARR

Vanta has appointed Sarah Scharf as chief marketing officer. Scharf joined Vanta in 2020 as its first product marketer and has since led every function within the company's marketing organisation. Reporting directly to CEO Christina Cacioppo, she will oversee product marketing, brand, communications, content, growth, and revenue marketing. During her tenure, Scharf led Vanta's positioning through three category shifts: from automated compliance to trust management to agentic trust. The appointment comes as Vanta surpassed $300 million in annual recurring revenue, reaching the milestone nine months after hitting $200 million. Over 16,000 companies, including Snowflake, GitHub, and Ramp, use Vanta's platform. Before Vanta, Scharf spent seven years at Google in product marketing roles. She holds a degree from Stanford University.