Oh My JobFind Jobs
Company
  • About Us
  • Blog
  • Contact
Tools
  • Paycheck Calculator
Legal
  • Terms of Service
  • Privacy Policy
  • California Privacy Rights
For Employers
Post a Job

Product GRC SME

Vanta
Vanta
Remote U.S.
Dec 16, 2025
171K – $201K • Offers Equity • This role is also eligible for medical benefits, 401(k) plan, and other company perk programs.
FullTime

Job Description

About the Role

Vanta is seeking a Product GRC Subject Matter Expert to develop and maintain multi-framework governance, risk, and compliance (GRC) solutions used by thousands of customers. You'll serve as a bridge between Product Management, Engineering, Design, Sales, and Customer Success, ensuring Vanta's GRC capabilities align with security, privacy, and risk frameworks while meeting real-world customer needs. This remote U.S. position offers the opportunity to shape Vanta's GRC product roadmap while delivering strategic compliance guidance to increasingly sophisticated enterprise customers.

About the Role

Vanta's mission is to help businesses earn and prove trust through continuous security monitoring and verification. The Security organization provides essential operational services, integrates security into the software development lifecycle, establishes enterprise-wide security policies, and offers advisory services to enable business growth while effectively managing risk.

Responsibilities

  • Build and maintain compliance frameworks: Lead creation, enhancement, and lifecycle management of controls, evidence requirements, and implementation guidance for SOC 2, ISO/IEC 27001 & 27701, HIPAA, PCI DSS, NIST CSF, NIST SP 800-53, and regional regulations (GDPR/CCPA). Author clear control rationales, acceptance criteria, and customer-facing guidance.
  • Design framework crosswalks and mappings: Create and maintain an internal common-control approach using industry catalogs. Develop bidirectional crosswalks across leading security and privacy frameworks. Define canonical control IDs, mapping confidence levels, and evidence data dictionaries; version crosswalks with changelogs and traceability to source authorities. Partner with Engineering to operationalize mappings in-product through integrations, automated tests, exceptions, and continuous monitoring workflows.
  • Elevate content quality and usability: Establish standards for control wording, evidence specificity, testing methods, and reviewer guidance. Build content QA processes and audits, measuring outcomes through adoption rates, time-to-evidence, and completion metrics.
  • Drive end-to-end GRC product enablement: Create modular content, guidance, and templates for risk management (methodologies, scoring, KRIs), issue and corrective action management (POA&M), policy lifecycle and attestations, access reviews (SoD and recertification), trust center artifacts, and third-party risk management (TPRM).
  • Act as product advisor across discovery and design: Partner with Product and Design on feature discovery (customer interviews, JTBD, task analysis), review workflows for controls and evidence, conduct usability testing, and author PRDs grounded in auditor and customer requirements.
  • Author automated tests and continuous monitoring: Translate controls and compliance knowledge into specification-level automated tests and detectors. Define test logic, data sources/integrations (APIs, logs, configs), edge cases, and acceptance criteria; collaborate with Engineering to implement, validate, and maintain detectors with versioned framework mappings.
  • Partner on product roadmap strategy: Translate customer and market needs into GRC requirements, propose experiments, and validate solutions. Influence prioritization using data and field insights; own a backlog for framework and content improvements.
  • Enable AI-assisted compliance: Partner with Engineering and ML teams to design and ship LLM-powered guidance and automation. Translate SME knowledge into machine-readable specs (schemas, ontologies, prompts), define evaluation sets and acceptance criteria, and implement quality and safety guardrails. Monitor accuracy and drift in production.
  • Synthesize feedback loops: Analyze input from customers, auditors, assessors, partners, and internal teams to identify gaps, resolve issues, and deliver iterative updates safely and quickly.

Requirements

  • 5-7+ years in GRC and/or Information Security with hands-on implementation or assessment across multiple frameworks (SOC 2, ISO 27001/27701, HIPAA, PCI DSS, NIST CSF/800-53)
  • Deep understanding of controls, risks, testing approaches, evidence standards, and program operations (policies, risk registers, issues/POA&M, vendor risk, continuous monitoring)
  • Experience with cloud environments and SaaS strongly preferred; Federal experience (e.g., FedRAMP) a plus
  • Ability to translate requirements into productizable capabilities with comfort in experimentation and data-driven prioritization
  • Technical aptitude to build leverage with lightweight tools, LLMs, and automation workflows (e.g., AI pair-programming tools, Sheets/Airtable automations, APIs, webhooks)
  • Skill designing AI-augmented workflows and establishing safe-use guidelines for prompts and agents with reusable patterns
  • Highly analytical and detail-oriented with strong spreadsheet and data analysis skills (lookups, pivots, large data sets)
  • Excellent written and verbal communication skills; able to partner effectively with engineers, designers, GTM teams, auditors, and customers
  • Self-motivated, independent, and resourceful; comfortable managing change and taking initiative in a fast-paced environment
  • Willingness to use AI to amplify skills and strengthen work, demonstrating curiosity and sound judgment in responsible AI application
  • Preferred: Bachelor's degree in Computer Science; advanced degree a plus. Experience with privacy regulations (GDPR/CCPA), risk quantification (FAIR), audit/assessor background, or B2B SaaS content/enablement. Certifications: CISA, CISSP, CCSK/CCSK+, ISO 27001 Lead Implementer/Lead Auditor, CIPM/CIPT, or PCI-ISA/QSA

Benefits

  • Industry-competitive salary and equity
  • Comprehensive medical, dental, and vision coverage with 100% of employee-only benefit premiums covered for most medical plans
  • 16 weeks paid parental leave for all new parents
  • Health and wellness stipend
  • Remote workspace, internet, and cellphone stipend
  • Commuter benefits for team members in SF and NYC offices
  • Family planning benefits
  • Matching 401(k) contribution with immediate vesting
  • Flexible PTO policy plus 80 hours of sick time annually
  • 11 company-paid holidays
  • Virtual team building activities, lunch and learns, and company-wide events
  • Offices in SF, NYC, London, Dublin, Tel Aviv, and Sydney

Vanta on Oh My Job

13 open positions right now. Average salary across all roles: $128–$151.

Apply now
Share: