Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Compliance Automation Engineer, GRC image - Rise Careers
Job details

Compliance Automation Engineer, GRC

At Vanta, our mission is to secure the internet and protect consumer data. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. 

Vanta is growing quickly and we're continually moving upmarket, dealing with sophisticated customers with complex security and compliance environments and needs. Our Security team uses our own Security and Privacy GRC experience to meet customer demand to help grow our market share as the industry leader in compliance and security.

As a Compliance Automation Engineer, GRC at Vanta, you will support FedRAMP Authorization efforts on the Vanta Security Team, working closely with cross-functional Engineering and Product teams. Your focus will be managing critical authorization audit readiness and continuous monitoring process, automating evidence collection wherever possible.

If this sounds like you, and you're excited to use your Security and GRC experience to help grow and sell our product, we'd love to hear from you.

Visit our Vanta Engineering Blog to learn more about what our team is working on! 

What you’ll do as a Compliance Automation Engineer, GRC at Vanta:

  • Design and develop automation solutions for evidence collection across infrastructure, endpoints, and SaaS platforms (e.g., AWS, GCP, GitHub, Okta).

  • Build and maintain scripts and APIs to interface with compliance tooling

  • Support recurring internal and external audits (FedRAMP, SOC 2, ISO 27001, HIPAA, etc.) by ensuring automated and reliable control monitoring

  • Automate control testing and reporting pipelines to reduce manual effort and improve accuracy

  • Support internal GRC platforms, dashboards, and metrics to communicate compliance posture and audit findings

  • Work with the compliance team to define technical control requirements and translate them into measurable, testable systems

  • Work with Engineering partners to embed compliance checks into CI/CD pipelines and infrastructure deployment workflows

  • Establish and manage the POAM and Continuous Monitoring processes and run monthly PMO meetings

  • Manage compliance deliverables for public sector stakeholders and manage ongoing updates

  • Leverage AI/ML tools to drive automation and improve efficiency and outcomes for audit and monitoring processes

  • Drive remediation for Security Team gaps and dependencies - this includes investigating and POCing solutions to replace existing tech where needed

  • Drive remediation of FedRMAP authorization gaps

  • Support policy and process implementation for business and engineering processes to support authorization

  • Support the implementation of technical controls within the security and engineering teams

  • Contribute to the development of machine readable reports for Product Team

  • Gather performance metrics and report KPIs to security team leaders

  • Become an expert on the Vanta public sector product offerings and provide regular feedback to product teams

  • Support the team responding to public sector security questionnaires

  • Partner to help improve existing and launch new security and compliance processes, programs, and policies where needed

  • Support audit readiness across Vanta’s compliance frameworks as needed

How to be successful in this role:

  • 3+ years of experience in scripting, automation, or backend engineering roles with a focus on security, infrastructure, or compliance

  • Expertise with public sector security frameworks like FedRAMP and CMMC

  • Experience with other NIST frameworks like NIST CSF, 800-53, 800-171, RMF

  • Ability to write scripts and basic code to automate audit and evidence gathering processes

  • Proficiency in at least one or more common scripting languages like Python, Go, PowerShell, Bash, Ruby, or JavaScript,

  • Experience consuming and building RESTful APIs to integrate various security, IT, and GRC tools

  • Experience querying APIs, building command-line tools, and working with structured data (JSON, CSV, YAML, OSCAL)

  • Ability to query and manipulate data in various datastores to extract compliance-relevant information

  • Familiarity with Cloud Infrastructure, Version Control Systems, Risk Management, Vulnerabilities, and their related security processes

  • Experience in product and program management

  • Experience in building productive relationships and driving collaboration with both technical and non-technical teams

  • Knowledge of audit processes and evidence requirements for cybersecurity frameworks

  • Security compliance management experience within a SaaS environment preferred, but not required

  • Experience working with other security frameworks like SOC2 and ISO27001 preferred but not required

  • Security certifications (e.g. CISA, CISSP, CRISC) and/or formal education strongly preferred, but not required

What you can expect as a Vantan:

  • Industry-competitive compensation

  • 100% covered medical, dental, and vision benefits with dependents coverage

  • 16 weeks fully-paid parental Leave for all new parents

  • Health & wellness and remote workplace stipends

  • Family planning benefits through Carrot Fertility

  • 401(k) matching

  • Flexible work hours and location

  • Open PTO policy

  • 11 paid holidays in the US

  • Offices in SF, NYC, London, Dublin, and Sydney

To provide greater transparency to candidates, we share base pay ranges for all US-based job postings regardless of state. We set standard base pay ranges for all roles based on function, level, and country location, benchmarked against similar-stage growth companies. Final offer amounts are determined by multiple factors and may vary based on candidate location, skills, depth of work experience, and relevant licenses/credentials.

#LI-remote

At Vanta, we are committed to hiring diverse talent of different backgrounds and as such, it is important to us to provide an inclusive work environment for all. We do not discriminate on the basis of race, gender identity, age, religion, sexual orientation, veteran or disability status, or any other protected class. As an equal opportunity employer, we encourage and welcome people of all backgrounds to apply.

About Vanta

We started in 2018, in the wake of several high-profile data breaches. Online security was only becoming more important, but we knew firsthand how hard it could be for fast-growing companies to invest the time and manpower it takes to build a solid security foundation. Vanta was inspired by a vision to restore trust in internet businesses by enabling companies to improve and prove their security.From our early days automating security monitoring for compliance standards like SOC 2, HIPAA and ISO 27001 to creating the world's leading Trust Management Platform, our vision remains unchanged. 

Now more than ever, making security continuous—not just a point-in-time check— is essential. Thousands of companies rely on Vanta to build, maintain and demonstrate their trust— all in a way that's real-time and transparent.

Vanta Glassdoor Company Review
4.3 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
Vanta DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Vanta
Vanta CEO photo
Christina Cacioppo
Approve of CEO

Average salary estimate

$125000 / YEARLY (est.)
min
max
$110000K
$140000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

Similar Jobs
Photo of the Rise User
Inclusive & Diverse
Growth & Learning
Customer-Centric
Collaboration over Competition
Medical Insurance
Maternity Leave
Flex-Friendly
401K Matching

Lead the Program Definition team at Vanta as a Senior Product Manager, driving product strategy and execution to enhance security and compliance management tools for growing enterprises.

Photo of the Rise User
Posted 6 days ago
Inclusive & Diverse
Growth & Learning
Customer-Centric
Collaboration over Competition
Medical Insurance
Maternity Leave
Flex-Friendly
401K Matching

Vanta is seeking a skilled Backend Senior Software Engineer to lead development of scalable test infrastructure and drive innovation in security compliance automation.

Photo of the Rise User
Posted 3 days ago

Experienced Cybersecurity Senior Engineer needed at Truist to lead mainframe security initiatives and develop advanced IT security solutions.

Photo of the Rise User
Posted 12 days ago
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony

Join NerdWallet as a Senior Infrastructure Security Engineer and help secure sensitive financial information while working remotely.

Photo of the Rise User
Protective Hybrid Work From Home
Posted 12 days ago

Join Protective as a Lead IT Architect and play a crucial role in developing systems that safeguard millions against life's uncertainties.

Posted 12 days ago

Take the next step in your career as an ISSE with VSO, contributing to significant cybersecurity initiatives at Edwards AFB.

Photo of the Rise User
Posted 12 days ago

Join Peraton as a Senior Malware Analyst where you'll play a critical role in enhancing cybersecurity strategies and responses for government missions.

ngc Hybrid United States-Minnesota-Unknown City
Posted 4 days ago

Northrop Grumman seeks a Principal QMS Software Development Analyst skilled in database management and application maintenance to support critical quality management systems.

Posted 4 days ago

The University of Chicago seeks an Application Support Analyst to manage and support Alumni Relations development systems, including Salesforce and other technology tools, in a hybrid work environment.

Photo of the Rise User
Posted 5 days ago

DMI is hiring an Infrastructure Operation Manager to lead infrastructure operations for a high-profile government project at The Pentagon.

Photo of the Rise User

Join Notre Dame as a Library Application Management and Integration Specialist to drive innovation in library system integration.

Become a key player in enhancing cyber defense strategies at MUFG as a CyberSecurity Threat Detection & Response Engineer.

Photo of the Rise User
Posted 13 days ago

Join Cyderes as a Senior Security Analyst and help protect enterprise clients from advanced cyber threats with your expertise in security operations.

Yexgo Hybrid Denver, Colorado, United States
Posted 7 days ago

This role engages a skilled IT Support Specialist to deliver technical assistance and maintain robust IT operations within a Denver-based company.

Photo of the Rise User

Join Montana State University as a Net Sys/Comm Analyst III to lead and support advanced network services and telecommunications.

Vanta is the leading trust management platform that helps simplify & centralize security for organizations of all sizes.

305 jobs
MATCH
Calculating your matching score...
BADGES
Badge ChangemakerBadge Future MakerBadge Innovator
CULTURE VALUES
Inclusive & Diverse
Growth & Learning
Customer-Centric
Collaboration over Competition
BENEFITS & PERKS
Medical Insurance
Maternity Leave
Flex-Friendly
401K Matching
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
June 25, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!