About the job
At Vanta, we are dedicated to empowering businesses to gain and demonstrate trust. Our vision is rooted in the belief that security must be continuously monitored and validated, enabling companies to enhance their security practices effortlessly. We pride ourselves on our inclusive and talented team, where diverse backgrounds contribute to our innovative solutions.
As we scale and enhance our market presence, we engage with increasingly complex clients with multifaceted security and compliance requirements across various industries. Our GRC Subject Matter Experts are essential in delivering high-quality, scalable guidance and content to support organizations in effectively managing their Governance, Risk, and Compliance (GRC) programs.
In your role as Vanta’s new Senior GRC Subject Matter Expert, you will be pivotal in developing and upholding multi-framework GRC solutions utilized by thousands of clients. You will act as a conduit between Product Management, Engineering, Design, Sales, and Customer Success, ensuring our solutions meet critical security, privacy, and risk frameworks while aligning with the real-world needs of our customers. Your contributions will be instrumental in designing, validating, and enhancing compliance-related content and capabilities, providing strategic insights that will shape Vanta's GRC product roadmap.
Joining Vanta's Security team means being part of a group that offers essential security operations services, influences the software development lifecycle, establishes enterprise-wide security policies, and provides advisory services that allow our business to thrive while managing risk effectively. If you are proactive and enjoy tackling complex challenges that have a meaningful impact on customers, we encourage you to reach out!
Your Responsibilities as a GRC Subject Matter Expert at Vanta:
Develop and maintain compliance frameworks - Spearhead the creation, enhancement, and lifecycle management of controls, evidence requirements, and implementation guidance for standards including SOC 2, ISO/IEC 27001 & 27701, HIPAA, PCI DSS, NIST CSF, NIST SP 800-53, and various regional regulations (e.g., GDPR/CCPA). Craft clear control rationales, acceptance criteria, and customer-facing guidance.
Design crosswalks and mappings (framework-agnostic) - Establish and oversee an internal common-control approach based on industry catalogs (e.g., SCF, UCF, or similar). Maintain bidirectional crosswalks across leading security and privacy regulatory frameworks. Define canonical control IDs, mapping confidence, and evidence data dictionaries.

