Oh My JobFind Jobs
Company
  • About Us
  • Blog
  • Contact
Tools
  • Paycheck Calculator
Legal
  • Terms of Service
  • Privacy Policy
  • California Privacy Rights
For Employers
Post a Job

Senior Manager, GRC Subject Matter Experts, Product

Vanta
Vanta
Remote U.S.
May 20, 2026
230K – $311K • Offers Equity • This role is also eligible for medical benefits, 401(k) plan, and other company perk programs.
FullTime

Job Description

About the Role

Vanta's GRC Subject Matter Experts, Product team serves as the compliance authority behind every framework, test, and piece of GRC content shipped in the platform. As Senior Manager of this team, you'll lead the end-to-end lifecycle of frameworks and compliance content—from SOC 2 and ISO 27001/27701 through HIPAA, PCI DSS, NIST, FedRAMP, and emerging regulations—while partnering directly with Product, Engineering, and Design to shape how the platform evolves.

About the Role

You'll manage a team spanning commercial frameworks, government frameworks, test authoring, framework quality uplift, and framework maintenance. You'll own the framework release process, govern content quality standards, and drive program management across new launches, updates, and customer escalations. This role combines deep GRC expertise with leadership discipline to operate a high-volume content and product release engine.

Responsibilities

  • Hire, mentor, and develop GRC subject matter experts across commercial and government frameworks, test authoring, quality uplift, and maintenance—setting technical depth and content quality standards while preparing high performers for expanded scope
  • Build a stable team environment with clear operating rhythms, effective delegation, and early intervention on team health issues in partnership with your People Business Partner
  • Connect the team's roadmap to Vanta's product and company strategy, anticipating shifts in customer needs, regulatory landscape, and product direction, and adjusting focus accordingly
  • Own and govern the framework release process end-to-end with Product and Engineering—defining the playbook for scoping, building, reviewing, and shipping new frameworks, framework updates, automated tests, crosswalks, and content
  • Drive program management for GRC content including framework launches, updates, customer escalations, content and test requests, and input on pricing and licensing
  • Break down ambiguous competing priorities across framework launches, updates, test authoring, and quality uplift into clear decisions, balancing customer demand, market opportunity, and engineering capacity
  • Lead the quality uplift effort for commercial frameworks, ensuring consistent standards for control wording, evidence specificity, and testing methods across Vanta's full library
  • Set direction for work on crosswalks and mappings across frameworks, including canonical control IDs and evidence data dictionaries, and partner with Engineering to operationalize them in-product
  • Steer the team's contribution to the broader GRC product surface—risk management, issue and corrective action management, policy management, access reviews, Trust Center, and third-party risk management
  • Partner with Product Management and Design to ensure SMEs are effective product advisors across discovery, PRD authoring, UI/UX review, and usability testing
  • Champion AI-assisted compliance on the team—coaching SMEs to translate domain knowledge into machine-readable specs and evaluation sets, and partnering with Engineering and ML to ship LLM-powered guidance and automation
  • Partner with Sales, Customer Success, and Product Marketing on framework portfolio representation and contribute to pricing, packaging, and licensing conversations
  • Serve as a senior escalation point for customer issues related to framework content, scoping, and interpretation
  • Track team performance and report KPIs to security and product leadership, including framework release velocity, content quality, adoption, time-to-evidence, and customer impact
  • Create open feedback loops across the team and adapt communication of priorities, decisions, and risks to different audiences
  • Lead the team through change with accountability, communicating progress and risks proactively and treating mistakes as learning opportunities

Requirements

  • 10+ years of GRC and/or Information Security experience with hands-on implementation or assessment across multiple frameworks (SOC 2, ISO 27001/27701, HIPAA, PCI DSS, NIST CSF/800-53); cloud environments and SaaS experience strongly preferred
  • 5+ years managing technical or subject matter expert teams, with a track record of developing people and building a culture of quality and accountability
  • Experience owning or heavily contributing to programs spanning Product, Engineering, and GTM—ideally including content lifecycle, framework release, or compliance product work
  • Strong program management instincts—comfortable defining process, driving prioritization, and holding cross-functional partners accountable to release plans and quality bars
  • Deep GRC craft including controls, risks, testing approaches, evidence standards, and program operations (policies, risk registers, POA&M, vendor risk, continuous monitoring)
  • Product mindset—able to coach teams on translating customer and regulatory needs into productizable capabilities and comfortable using data to prioritize
  • Technical and automation fluency with AI-augmented tools—comfortable using AI pair-programming and LLM tools to accelerate drafting of specs, mappings, and test logic, and able to establish safe-use guidelines and evaluation practices
  • Analytical and detail-oriented with strong skills in precise control wording, mapping accuracy, and evidence specificity; comfortable working with spreadsheets and large data sets
  • Excellent written and verbal communication; able to partner effectively with engineers, designers, GTM teams, auditors, and customers, and represent work to executives
  • Self-motivated and adaptable in fast-paced environments with a track record of leading teams through change
  • Open to using AI to amplify skills and strengthen work, demonstrating curiosity and sound judgment in applying AI responsibly
  • Federal experience (FedRAMP, CMMC, StateRAMP) a plus but not required
  • Privacy regulation experience (GDPR/CCPA) and audit/assessor background a plus but not required
  • Certifications preferred but not required—one or more of: CISA, CISSP, CCSK/CCSK+, ISO 27001 Lead Implementer/Lead Auditor, CIPM/CIPT, PCI-ISA/QSA

Benefits

  • Industry-competitive salary and equity
  • Comprehensive medical, dental, and vision coverage with 100% of employee-only benefit premiums covered for most medical plans
  • 16 weeks paid parental leave for all new parents
  • Health & wellness stipend
  • Remote workspace, internet, and cellphone stipend
  • Commuter benefits for team members in SF and NYC offices
  • Family planning benefits
  • Matching 401(k) contribution with immediate vesting
  • Flexible PTO policy plus 80 hours of sick time
  • 11 company-paid holidays
  • Virtual team building activities, lunch and learns, and company-wide events

Vanta on Oh My Job

13 open positions right now. Average salary across all roles: $128–$151.

Apply now
Share: