# Governance, Risk, and Compliance Expert, GTM - V4G at Vanta

- Company: Vanta
- What the company does: Vanta automates the complex and time-consuming process of SOC 2, HIPAA, ISO 27001, PCI, and GDPR compliance certification. Automate your security monitoring in weeks instead of months. Backed by Sequoia, Y Combinator and Pear VC.
- Company website: https://www.vanta.com/
- Type: Startups
- Level: Mid level
- Location: Remote U.S.
- Work setup: Remote
- Pay: $171K to $201K base salary per year (USD)
- Posted: 2026-09-04
- Apply by: 2026-10-19
- Apply: https://jobs.ashbyhq.com/vanta/2f2ad814-2437-46bc-8829-9413f1840db0
- Page: https://www.1752.vc/careers/jobs/vanta-governance-risk-and-compliance-expert-gtm-v4g/

## About the role

Use your expert knowledge of compliance frameworks like FedRAMP, GovRAMP, TX-RAMP, NIST 800-53, CMMC 2.0, and NIST 800-171, to advise customers regarding questions about scoping, policy creation, detailed control requirements and security best practices, and recommend implementations within Vanta’s product related to these frameworks.

## What they're looking for

- 5+ years of experience US government compliance, with direct experience taking an organization to FedRAMP Ready or Authorized, assessing as a 3PAO, or both
- Working knowledge of federal frameworks such as FedRAMP (all impact levels and the program's active modernization), CMMC 2.0, NIST 800-53 and 800-171, and StateRAMP/state-program dynamics
- Foundational knowledge of baseline security compliance frameworks such as ISO 27001 & SOC 2
- Strong understanding of of SSP and POA&M authorship-level familiarity as well as ConMon operations
- Familiarity with cloud infrastructure, version control systems, risk management, vulnerability management, and their related security processes
- Experience with third-party/vendor risk management (TPRM) processes, including due diligence, risk scoring, risk assessments, and ongoing monitoring processes

Tags: Security
