Governance, Risk, and Compliance Expert, GTM - V4G
Role Overview
This senior individual contributor role serves as the dedicated GRC subject matter expert for Vanta's government-market deals, partnering with sales leadership from qualification through POC, onsite, and close. You'll advise federal ISVs, defense suppliers, and SLED buyers on FedRAMP, CMMC, NIST 800-53/171, and StateRAMP strategy while mapping requirements to Vanta's platform. Operating with unusual autonomy, you'll triage your own deal book and backstop the broader SME channel on commercial frameworks.
Perks & Benefits
Vanta offers a fully remote role with industry-competitive salary, equity, and comprehensive medical, dental, and vision coverage, plus a remote workspace, internet, and cellphone stipend. Benefits include flexible PTO, 16 weeks paid parental leave, matching 401(k) with immediate vesting, and health and wellness stipends. Travel is roughly once per quarter for onsites and events, and the company emphasizes inclusive culture, virtual team building, and lunch-and-learns.
Full Job Description
At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it.
As one of Vanta’s GTM-facing GRC Subject Matter Experts supporting Vanta for Government (V4G) opportunities, you will be a highly visible, customer-facing leader within Vanta’s Security team, responsible for representing Vanta’s Trust Management Platform to prospects and customers, bringing deep public-sector compliance expertise across FedRAMP, GovRAMP, TX-RAMP, NIST 800-53, CMMC 2.0, and NIST 800-171. You will also have a role in collaborating with internal teams to help drive and implement new V4G product features. This role is specifically involved with Vanta's pre-sales and marketing motions, owning V4G GRC conversations for net-new prospects and the expansion of existing customers' use of the product, as well as supporting marketing efforts by representing Vanta in public-facing conversations and speaking engagements.
If this sounds like you, and you're excited to use your Security, Privacy, and broader Gov-focused GRC experience to help grow and sell our product, we'd love to hear from you.
What you’ll do as a Governance, Risk, and Compliance Expert, GTM - V4G at Vanta:
Use your expert knowledge of compliance frameworks like FedRAMP, GovRAMP, TX-RAMP, NIST 800-53, CMMC 2.0, and NIST 800-171, to advise customers regarding questions about scoping, policy creation, detailed control requirements and security best practices, and recommend implementations within Vanta’s product related to these frameworks.
Partner with Vanta's Sales, Account Management, and Solutions Engineering teams and own public-sector GRC discussions & activities, representing Vanta’s Trust Management Platform to prospects/customers.
Become an expert in V4G product features to translate how they can help optimize prospect/customer public-sector GRC workflows.
Engage with executives and senior staff at prospect and customer organizations to establish relationships with customer security, privacy, and AI teams.
Answer questions from internal and external stakeholders on GRC programs, including program foundation/scaling strategies, framework-specific requirements, third-party risk management, and broader IT, security, privacy, and enterprise risk workflows - and how Vanta's platform supports each.
Develop publicly-available marketing and education content focused on public-sector GRC for prospects, customers, and partners.
Represent Vanta in public-facing activities including speaking on webinars & panels, participating in conferences, networking at Vanta/partner-led events, and other marketing or thought leadership events.
Partner with GTM Enablement teams to design and deliver training for Vanta's Sales and Account Management orgs on GRC and Vanta product disciplines across security, privacy, and AI governance.
Identify customer requirements that expand or improve Vanta’s product across security, privacy, and AI governance, and provide input and feedback for feature development.
Travel roughly twice per quarter (a few days to a week) for customer onsites, POC workshops, team offsites, and other events.
What we're looking for
5+ years of experience US government compliance, with direct experience taking an organization to FedRAMP Ready or Authorized, assessing as a 3PAO, or both.
Working knowledge of federal frameworks such as FedRAMP (all impact levels and the program's active modernization), CMMC 2.0, NIST 800-53 and 800-171, and StateRAMP/state-program dynamics .
Foundational knowledge of baseline security compliance frameworks such as ISO 27001 & SOC 2.
Strong understanding of of SSP and POA&M authorship-level familiarity as well as ConMon operations
Familiarity with cloud infrastructure, version control systems, risk management, vulnerability management, and their related security processes.
Experience with third-party/vendor risk management (TPRM) processes, including due diligence, risk scoring, risk assessments, and ongoing monitoring processes.
Background in broader IT, security, and/or enterprise risk management workflows, including risk scoring, likelihood/impact analysis, and treatment planning.
Excellent communication and facilitation skills, with the ability to deliver high-impact learning experiences and earn credibility with experienced, senior-level sellers.
Strong written and verbal communication skills, comfortable engaging customer-facing stakeholders, including C-level contacts, security & privacy leaders, and legal teams, as well as more public partner and industry audiences.
Comfortable using AI to amplify and strengthen GRC work - demonstrating curiosity, a willingness to learn, and sound judgment in applying AI responsibly to improve efficiency and impact.
Enterprise sales process literacy (e.g., MEDDPICC) preferred, but not required.
Customer Trust or Sales Engineering experience preferred, but not required.
Certifications (e.g., CISA, CISSP, RP, CCA, CCP) and/or formal education preferred, but not required.
What you can expect as a Vanta’n:
Industry-competitive salary and equity
Comprehensive medical, dental, and vision coverage, with 100% of employee-only benefit premiums covered for most medical plans
16 weeks paid Parental Leave for all new parents
Health & wellness stipend
Remote workspace, internet, and cellphone stipend
Commuter benefits for team members who report to the SF and NYC office
Family planning benefits
Matching 401(k) contribution with immediate vesting
Flexible PTO policy, plus 80 hours of Sick Time
11 company-paid holidays
Virtual team building activities, lunch and learns, and other company-wide events!
Offices in SF, NYC, London, Dublin, Tel Aviv, and Sydney
To provide greater transparency to candidates, we share base pay ranges for all US-based job postings regardless of state. We set standard base pay ranges for all roles based on function, level, and country location, benchmarked against similar-stage growth companies. Final offer amounts are determined by multiple factors and may vary based on candidate location, skills, depth of work experience, and relevant licenses/credentials.
#LI-remote
At Vanta, we are committed to hiring diverse talent of different backgrounds and as such, it is important to us to provide an inclusive work environment for all. We do not discriminate on the basis of race, gender identity, age, religion, sexual orientation, veteran or disability status, or any other protected class. As an equal opportunity employer, we encourage and welcome people of all backgrounds to apply.
About Vanta
We started in 2018, in the wake of several high-profile data breaches. Online security was only becoming more important, but we knew firsthand how hard it could be for fast-growing companies to invest the time and manpower it takes to build a solid security foundation. Vanta was inspired by a vision to restore trust in internet businesses by enabling companies to improve and prove their security. From our early days automating security monitoring for compliance standards like SOC 2, HIPAA and ISO 27001 to creating the world's leading Trust Management Platform, our vision remains unchanged.
Now more than ever, making security continuous—not just a point-in-time check— is essential. Thousands of companies rely on Vanta to build, maintain and demonstrate their trust— all in a way that's real-time and transparent.
Referral Instructions
If you are being referred for the role, please contact that person to apply on your behalf.
Similar jobs
Found 6 similar jobs