Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Product GRC SME, Vanta for Government image - Rise Careers
Job details

Product GRC SME, Vanta for Government

At Vanta, our mission is to secure the internet and protect consumer data. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. 

As Vanta rapidly grows and moves upmarket, we’re working with increasingly sophisticated customers who have complex security and compliance needs, especially within the federal government sector. The GRC Subject Matter Experts play a critical role in delivering high-quality, scalable content to help these companies effectively manage their GRC programs.

As Vanta’s newest GRC Subject Matter Expert, you’ll be responsible for developing GRC solutions that support our growing list of global federal and public sector customers, with a critical focus on FedRAMP authorization and continuous monitoring. Acting as a bridge between Product Management, customers, and compliance stakeholders, you’ll ensure that our solutions align with key federal security and privacy frameworks. You’ll play a pivotal role in designing, maintaining, and improving compliance-related content while providing strategic input to shape Vanta’s overall GRC product roadmap, with a particular emphasis on our Vanta for Government (V4G) offering.

You’ll join Vanta’s Security organization, which provides essential security operational services, is directly involved in the software development process, sets policies and standards regarding enterprise-wide security requirements, and offers advisory services to enable our business to thrive while effectively managing risk. If you’re someone who has high initiative and enjoys problem solving while having impact at a high-growth company, we would love to hear from you!

You’ll be part of Vanta’s Security organization that directly influences product development, facilitates the creation of automated GRC solutions for customers, and provides expert advisory services to Vantans at large. If you love solving complex problems, thrive in a fast-paced environment, and want to make a real impact at a high-growth company, we’d love to hear from you!

What you’ll do as a GRC SME at Vanta

  • Develop New Federal Compliance Frameworks, with a FedRAMP Focus – Lead building new security, privacy, and risk management frameworks for end-users, , with a strong focus on FedRAMP (all baselines - Low, Moderate, High), CMMC, and NIST 800-53. This includes developing content to support the creation and maintenance of FedRAMP Authorization Packages (e.g., System Security Plans (SSPs), Plan of Action & Milestones (POA&Ms), Security Assessment Reports (SARs)).

  • Optimize GRC Content for V4G – Map evidence requirements, improve control descriptions, write policies, risk scenarios, implementation guidance to enhance clarity and usability for federal compliance, with a particular emphasis on streamlining processes for FedRAMP authorization and continuous monitoring within the V4G platform. Help to develop AI features to support these efforts.

  • Analyze Feedback – Identify and resolve issues with control mappings, evidence requirements, and framework content based on input from federal agencies, authorized third-party assessment organizations (3PAOs), and government auditors. Act as a subject matter expert during engagements related to FedRAMP assessments and audits.

  • Collaborate Across Teams for Federal Solutions – Work with software engineers, product designers, and customer-facing teams to ensure that GRC content is appropriately integrated into Vanta’s platform and meets end-user needs and V4G requirements, especially those pertaining to FedRAMP.

  • Partner with Product for Federal Innovation – Work closely with our Product team to advise on the development of new GRC features in the platform, driving innovation for Vanta for Government (V4G) and enhancing our capabilities for FedRAMP readiness and ongoing compliance.

How to be successful in this role:

  • 5-7+ years of experience in GRC and/or Information Security with significant direct experience focusing on federal government compliance programs, particularly FedRAMP authorization processes and continuous monitoring. Experience working for or with a Cloud Service Provider (CSP) pursuing FedRAMP, a 3PAO, or a federal agency is a strong plus.

  • Strong comprehension, communication, and collaboration skills – Ability to grasp core GRC concepts, apply them effectively across tasks, and clearly communicate findings to GRC Content Engineers, Product Managers, and non-technical stakeholders within the federal ecosystem, including government officials and 3PAOs.

  • Deep technical understanding of federal security and compliance, especially FedRAMP – Familiarity with industry frameworks such asFedRAMP (all baselines), CMMC (all levels), NIST 800-53, FIPS, and DFARS. Expert-level knowledge of FedRAMP requirements, documentation standards, and the JAB/Agency authorization process is highly desirable. Having a technical background (e.g., Federal Security Engineer, ISSO, Auditor, ATO specialist, or FedRAMP Assessor) is a plus, but not required.

  • Attention to detail and analytical mindset – Comfortable working with federal cybersecurity frameworks, detailed control mappings, and specific evidence requirements with precision and consistency, particularly within the rigorous context of FedRAMP.

  • Proficiency in MS Excel/Google Sheets – Ability to organize large data-sets, use lookup functions, and create pivot tables.

  • Self-motivated and independent – Able to work autonomously while contributing to team success.

  • Helpful and resourceful – Willing & excited to support cross-functional teams and improve compliance content.

  • Adaptable in a fast-paced environment – Skilled at managing change, solving problems proactively, and taking initiative.

  • Security certifications or formal education preferred – Certifications like CAP, CISA, CISSP-ISSEP, Certified CMMC Professional (CCP), or FedRAMP Provisional Assessor are a plus but not required.

What you can expect as a Vantan:

  • Industry-competitive compensation

  • 100% covered medical, dental, and vision benefits with dependents coverage

  • 16 weeks fully-paid parental Leave for all new parents

  • Health & wellness and remote workplace stipends

  • Family planning benefits through Carrot Fertility

  • 401(k) matching

  • Flexible work hours and location

  • Open PTO policy

  • 11 paid holidays in the US

  • Offices in SF, NYC, London, Dublin, and Sydney

To provide greater transparency to candidates, we share base pay ranges for all US-based job postings regardless of state. We set standard base pay ranges for all roles based on function, level, and country location, benchmarked against similar-stage growth companies. Final offer amounts are determined by multiple factors and may vary based on candidate location, skills, depth of work experience, and relevant licenses/credentials.

#LI-remote

At Vanta, we are committed to hiring diverse talent of different backgrounds and as such, it is important to us to provide an inclusive work environment for all. We do not discriminate on the basis of race, gender identity, age, religion, sexual orientation, veteran or disability status, or any other protected class. As an equal opportunity employer, we encourage and welcome people of all backgrounds to apply.

About Vanta

We started in 2018, in the wake of several high-profile data breaches. Online security was only becoming more important, but we knew firsthand how hard it could be for fast-growing companies to invest the time and manpower it takes to build a solid security foundation. Vanta was inspired by a vision to restore trust in internet businesses by enabling companies to improve and prove their security.From our early days automating security monitoring for compliance standards like SOC 2, HIPAA and ISO 27001 to creating the world's leading Trust Management Platform, our vision remains unchanged. 

Now more than ever, making security continuous—not just a point-in-time check— is essential. Thousands of companies rely on Vanta to build, maintain and demonstrate their trust— all in a way that's real-time and transparent.

Vanta Glassdoor Company Review
4.3 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
Vanta DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Vanta
Vanta CEO photo
Christina Cacioppo
Approve of CEO

Average salary estimate

$130000 / YEARLY (est.)
min
max
$110000K
$150000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

Similar Jobs
Photo of the Rise User
Vanta Hybrid No location specified
Posted 6 days ago
Inclusive & Diverse
Growth & Learning
Customer-Centric
Collaboration over Competition
Medical Insurance
Maternity Leave
Flex-Friendly
401K Matching

Lead Vanta’s public sector compliance efforts by applying deep GRC expertise to support customers and influence product development in a fully remote GTM SME role.

Photo of the Rise User
Vanta Hybrid No location specified
Posted 3 days ago
Inclusive & Diverse
Growth & Learning
Customer-Centric
Collaboration over Competition
Medical Insurance
Maternity Leave
Flex-Friendly
401K Matching

Lead Vanta's SEO strategy to increase organic traffic, brand visibility, and contribute to pipeline growth in a remote, innovative security-focused company.

Photo of the Rise User
TrustArc Hybrid No location specified
Posted 2 days ago

Lead global privacy compliance and client management for TrustArc’s certification programs in a fully remote role requiring Mandarin fluency.

Photo of the Rise User
City of New York Hybrid New York City, NY
Posted 10 days ago

Join the Kings County District Attorney’s Office as a Paralegal to support innovative prosecutorial strategies in Brooklyn.

Photo of the Rise User
SpaceX Hybrid Washington, DC
Posted yesterday
Mission Driven
Social Impact Driven
Passion for Exploration
Reward & Recognition

An experienced Contracts Manager is sought by SpaceX to manage government and commercial contract compliance and administration in Washington, DC.

Photo of the Rise User
American Express Hybrid New York, New York, United States
Posted 2 days ago
Inclusive & Diverse
Empathetic
Collaboration over Competition
Growth & Learning
Transparent & Candid
Medical Insurance
Dental Insurance
Mental Health Resources
Life insurance
Disability Insurance
Child Care stipend
Employee Resource Groups
Learning & Development

Lead the Global Financial Crimes Compliance control environment at American Express, driving risk management and compliance initiatives within a dynamic, global financial institution.

Photo of the Rise User
MGM Resorts International Hybrid Office - US, Las Vegas, NV 71 East Harmon Ave
Posted 4 days ago

Lead MGM Resorts' Financial Investigations team to ensure adherence to AML laws and protect casino operations integrity.

Photo of the Rise User
Posted 9 hours ago
Inclusive & Diverse
Empathetic
Collaboration over Competition
Growth & Learning
Transparent & Candid
Medical Insurance
Dental Insurance
Mental Health Resources
Life insurance
Disability Insurance
Child Care stipend
Employee Resource Groups
Learning & Development

American Express is looking for an Analyst to enhance and support governance of its U.S. AML Program, driving compliance and policy management.

Photo of the Rise User
Posted yesterday
Inclusive & Diverse
Empathetic
Collaboration over Competition
Growth & Learning
Transparent & Candid
Medical Insurance
Dental Insurance
Mental Health Resources
Life insurance
Disability Insurance
Child Care stipend
Employee Resource Groups
Learning & Development

Analyst wanted to support U.S. AML governance within American Express, ensuring compliance and effective risk management.

Photo of the Rise User
DLR Group Hybrid Overland Park, Kansas, United States
Posted 7 days ago

Senior Counsel needed at DLR Group to manage legal strategies and contract negotiations across global design and construction projects.

Sia Hybrid Salesforce Tower, 415 Mission St, San Francisco, CA 94105, USA
Posted 10 days ago

Join Sia as a Senior Consultant where you’ll lead project management efforts in legal and compliance, navigating critical regulatory challenges for our clients.

Photo of the Rise User

RRD is seeking a detail-oriented Legal Document Specialist to support legal document processing in a hybrid full-time role based in Phoenix, AZ.

Photo of the Rise User

Elevance Health is seeking a Corporate Tax Counsel - Mergers & Acquisitions Tax Counsel to provide expert legal and tax guidance on high-impact business transactions within the healthcare sector.

Photo of the Rise User

Serve as a supervising attorney within New York City's Ethics and Compliance Division, managing legal teams and advising on government ethics and compliance issues.

Photo of the Rise User
Posted 8 days ago

Experienced compliance professional needed to assist a Massachusetts-based bank in maintaining regulatory adherence and managing risk programs.

Vanta is the leading trust management platform that helps simplify & centralize security for organizations of all sizes.

306 jobs
MATCH
Calculating your matching score...
BADGES
Badge ChangemakerBadge Future MakerBadge Innovator
CULTURE VALUES
Inclusive & Diverse
Growth & Learning
Customer-Centric
Collaboration over Competition
BENEFITS & PERKS
Medical Insurance
Maternity Leave
Flex-Friendly
401K Matching
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
June 26, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!