At Vanta, our mission is to help businesses earn and prove trust. As Vanta rapidly grows and moves upmarket, we’re working with increasingly sophisticated customers who have complex security and compliance needs across a wide range of industries and geographies. The GRC Subject Matter Experts play a critical role in delivering high-quality, scalable content and product guidance to help these companies effectively manage their GRC programs.
Requirements
- 5-7+ years in GRC and/or Information Security with hands‑on implementation or assessment across multiple frameworks (e.g., SOC 2, ISO 27001/27001, HIPAA, PCI DSS, NIST CSF/800‑53). Experience with cloud environments and SaaS is strongly preferred. Federal experience (e.g., FedRAMP) is a plus but not required.
- Deep understanding of controls, risks, testing approaches, evidence standards, and program operations (policies, risk registers, issues/POA&M management, vendor risk, continuous monitoring).
- Ability to translate requirements into productizable capabilities; comfort with experimentation and data‑driven prioritization.
- Build leverage with lightweight tools, LLMs, and automation workflows:
- Use AI pair‑programming tools (e.g., GitHub Copilot, Cursor) to accelerate drafting of specs, mappings, queries, and test logic.
- Own simple automations that stitch together Sheets/Airtable, APIs, and webhooks to remove toil (e.g., mapping QA, evidence normalization, exception routing).
- Design AI‑augmented workflows across teams (e.g., LLM‑assisted control guidance, assessor Q&A triage, remediation suggestions) and measure outcomes (precision/recall, time‑to‑evidence, FP/FN rates).
Responsibilities
- Build and maintain compliance frameworks* - Lead the creation, enhancement, and lifecycle management of controls, evidence requirements, and implementation guidance for standards such as SOC 2, ISO/IEC 27001 & 27701, HIPAA, PCI DSS, NIST CSF, NIST SP 800-53, and regional regulations (e.g., GDPR/CCPA). Author clear control rationales, acceptance criteria, and customer-facing guidance.
- Design crosswalks and mappings (framework‑agnostic)* - Create and steward an internal common‑control approach informed by industry catalogs (e.g., SCF, UCF, or similar). Maintain bidirectional crosswalks across industry leading security and privacy regulatory frameworks. Define canonical control IDs, mapping confidence, and evidence data dictionaries; version crosswalks with changelogs and traceability to source authority. Partner with Engineering to operationalize mappings in‑product (integrations, automated tests, exceptions/exemptions, continuous monitoring workflows).
- Elevate content quality and usability* - Define standards for control wording, evidence specificity, testing method, and reviewer guidance. Establish content QA processes, audits, and metrics (e.g., adoption, time-to-evidence, completion rates) to continually improve outcomes.
- Drive end‑to‑end GRC product enablement* - Build modular content, guidance, and templates for risk management (methodologies, scoring, KRIs), issue & corrective action management (POA&M), policy management (lifecycle, attestations), access reviews (SoD, recertification flows), customer trust / Trust Center artifacts, and third‑party risk management (TPRM) (due diligence, monitoring, contract clauses).
- Act as a product advisor across discovery & design* - Partner with PM/Design to support feature discovery (customer interviews, JTBD, task analysis), review UI/UX for control, evidence, and review workflows, run usability tests, and author PRDs/acceptance criteria grounded in auditor and customer needs.
- Author automated tests & continuous monitoring* - Translate controls/compliance knowledge and infrastructure contexts (cloud services, SaaS apps, on‑prem, endpoints, networks, CI/CD) into spec‑level automated tests and detectors in Vanta. Define test logic, data sources/integrations (APIs, logs, configs), edge cases, and acceptance criteria; pair with Engineering to implement, validate, and maintain detectors with versioned mappings to frameworks for continuous monitoring.
- Enable AI‑assisted compliance* - Partner with Engineering/ML to design and ship LLM‑powered guidance and automation. Translate SME knowledge into machine‑readable specs (schemas, ontologies, prompts), define gold‑standard evaluation sets and acceptance criteria, and implement quality/safety guardrails (red‑teaming, refusal policy, privacy controls). Instrument features to monitor accuracy and drift in production.
Other
- Full time
- Remote U.S.
- Bachelor’s degree in Computer Science; advanced degree a plus.
- Excellent written and verbal skills; able to partner effectively with engineers, designers, GTM teams, auditors, and customers.
- Self-motivated and independent* - Able to work autonomously while contributing to team success.