Manager, GRC Subject Matter Experts, Product

Reposted 18 Hours Ago
Hiring Remotely in U.S.
Remote
230K-311K Annually
Senior level
Software
The Role
Lead the GRC Subject Matter Experts team, managing framework lifecycle, product integration, and team development while ensuring quality and alignment with company strategy.
Summary Generated by Built In

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. 

As Vanta rapidly grows and moves upmarket, we're working with increasingly sophisticated customers who have complex security and compliance needs across a wide range of industries and geographies. The GRC Subject Matter Experts, Product team sits at the heart of how Vanta meets that demand — they are the GRC authorities behind every framework, test, and piece of compliance content the platform ships, and they partner directly with Product, Engineering, and Design to shape the GRC Frameworks part of the product.

As the Manager of the GRC Product Subject Matter Experts team at Vanta, you will lead the team responsible for the lifecycle, quality, and product integration of Vanta's frameworks, tests, and broader GRC content. Your team spans commercial frameworks, government frameworks, test authoring, framework quality uplift, and framework maintenance, and their work touches everything from SOC 2, ISO 27001/27701, HIPAA, PCI DSS, and NIST to FedRAMP and emerging regulations. You will manage and develop this team while also owning and governing the end-to-end framework release process in partnership with Product and Engineering.

You'll join Vanta's Security organization, which provides essential security operational services, is directly involved in the software development process, sets policies and standards regarding enterprise-wide security requirements, and offers advisory services to enable our business to thrive while effectively managing risk.

If you're someone with deep GRC expertise, a track record of developing people, and the program instincts to drive a high-volume content and product release engine, we'd love to hear from you.

What you’ll do as a Manager of GRC Subject Matter Experts, Product at Vanta:

  • Hire, mentor, and develop a team of SMEs covering commercial frameworks, government frameworks, test authoring, framework quality uplift, and framework maintenance — planning for current and future capacity needs, setting the bar for technical depth and content quality, and preparing high performers for broader scope

  • Build a stable, motivated team environment with clear operating rhythms, delegating effectively to grow ownership and capability, and partnering with your leader and People Business Partner to spot and address team health issues early

  • Connect the team's roadmap and content priorities to Vanta's broader product and company strategy, anticipating near-term shifts in customer needs, regulatory landscape, and product direction, and adjusting focus to keep the team aligned

  • Create open feedback loops within the team and adapt how you communicate priorities, decisions, and risks across different audiences — from individual contributors to engineering, GTM partners, customers, and executives

  • Lead the team through change with steadiness while holding yourself and them accountable for commitments — communicating progress and risks proactively, addressing misses directly, and creating an environment where mistakes are treated as learning opportunities rather than blame

  • Own and govern Vanta's framework release process end-to-end, partnering with Product and Engineering to define the playbook for how new frameworks, framework updates, automated tests, crosswalks, and content are scoped, built, reviewed, and shipped

  • Drive the program management work that surrounds GRC content — including new framework launches, framework updates, update notes, customer escalations, content and test requests, PMM material reviews, and licensing and pricing input

  • Track team performance and report KPIs and metrics to security and product leadership, including framework release velocity, content quality, adoption, time-to-evidence, and customer impact

  • Break down ambiguous and competing priorities — across framework launches, framework updates, test authoring, and quality uplift — into clear, actionable decisions, balancing customer demand, market opportunity, and engineering capacity, and escalating complex tradeoffs with context and a recommended path forward

  • Lead the quality uplift effort for older commercial frameworks, ensuring Vanta's full library meets a consistent and modern standard for control wording, evidence specificity, and testing method

  • Set direction for the team's work on crosswalks and mappings across security and privacy frameworks, including canonical control IDs, mapping confidence, and evidence data dictionaries, and partner with Engineering to operationalize them in-product

  • Steer the team's contribution to the broader GRC product surface — risk management, issue and corrective action management (POA&M), policy management, access reviews, Trust Center, and third-party risk management

  • Partner with Product Management and Design to ensure SMEs are effective product advisors across discovery, PRD authoring, UI/UX review, and usability testing

  • Champion AI-assisted compliance on the team — coaching SMEs to translate domain knowledge into machine-readable specs, evaluation sets, and guardrails, and partnering with Engineering and ML to ship LLM-powered guidance and automation

  • Partner with Sales, Customer Success, and Product Marketing to represent the framework portfolio externally and contribute to pricing, packaging, and licensing conversations (including frameworks such as HITRUST)

  • Serve as a senior escalation point for customer issues related to framework content, scoping, and interpretation

  • Provide input and feedback on the development of GRC product features that depend on the team's content and expertise

How to be successful in this role:

  • 7+ years of GRC and/or Information Security experience, with hands-on implementation or assessment across multiple frameworks (e.g., SOC 2, ISO 27001/27701, HIPAA, PCI DSS, NIST CSF/800-53); experience with cloud environments and SaaS strongly preferred

  • 2+ years of experience managing technical or subject matter expert teams, with a passion for developing people and building a culture of quality and accountability

  • Experience owning or heavily contributing to programs that span Product, Engineering, and GTM — ideally including content lifecycle, framework release, or compliance product work

  • Strong program management instincts: comfortable defining process, driving prioritization, and holding cross-functional partners accountable to release plans and quality bars

  • Deep GRC craft — controls, risks, testing approaches, evidence standards, and program operations (policies, risk registers, POA&M, vendor risk, continuous monitoring)

  • Product mindset — able to coach the team on translating customer and regulatory needs into productizable capabilities, with comfort using data to prioritize

  • Technical and automation fluency (AI-augmented) — comfortable using AI pair-programming and LLM tools to accelerate drafting of specs, mappings, and test logic, and able to set safe-use guidelines, evaluation practices, and reusable patterns for the team

  • Analytical and detail-oriented — skilled at precise control wording, mapping accuracy, and evidence specificity; comfortable working with spreadsheets and large data sets

  • Excellent written and verbal communication; able to partner effectively with engineers, designers, GTM teams, auditors, and customers, and to represent the team's work to executives

  • Self-motivated and adaptable in a fast-paced environment, with a track record of leading teams through change

  • Federal experience (e.g., FedRAMP, CMMC, StateRAMP) a plus but not required

  • Privacy regulation experience (GDPR/CCPA), audit/assessor background experience a plus

  • Certifications preferred but not required — one or more of: CISA, CISSP, CCSK/CCSK+, ISO 27001 Lead Implementer/Lead Auditor, CIPM/CIPT, PCI-ISA/QSA

  • Open to using AI to amplify their skills and strengthen their work - demonstrating curiosity, a willingness to learn, and sound judgment in applying AI responsibly to improve efficiency and impact.

What you can expect as a Vanta’n:

  • Industry-competitive salary and equity

  • Comprehensive medical, dental, and vision coverage, with 100% of employee-only benefit premiums covered for most medical plans

  • 16 weeks paid Parental Leave for all new parents

  • Health & wellness stipend

  • Remote workspace, internet, and cellphone stipend

  • Commuter benefits for team members who report to the SF and NYC office

  • Family planning benefits

  • Matching 401(k) contribution with immediate vesting

  • Flexible PTO policy, plus 80 hours of Sick Time

  • 11 company-paid holidays

  • Virtual team building activities, lunch and learns, and other company-wide events!

  • Offices in SF, NYC, London, Dublin, Tel Aviv, and Sydney

To provide greater transparency to candidates, we share base pay ranges for all US-based job postings regardless of state. We set standard base pay ranges for all roles based on function, level, and country location, benchmarked against similar-stage growth companies. Final offer amounts are determined by multiple factors and may vary based on candidate location, skills, depth of work experience, and relevant licenses/credentials.

#LI-remote

At Vanta, we are committed to hiring diverse talent of different backgrounds and as such, it is important to us to provide an inclusive work environment for all. We do not discriminate on the basis of race, gender identity, age, religion, sexual orientation, veteran or disability status, or any other protected class. As an equal opportunity employer, we encourage and welcome people of all backgrounds to apply.

About Vanta

We started in 2018, in the wake of several high-profile data breaches. Online security was only becoming more important, but we knew firsthand how hard it could be for fast-growing companies to invest the time and manpower it takes to build a solid security foundation. Vanta was inspired by a vision to restore trust in internet businesses by enabling companies to improve and prove their security. From our early days automating security monitoring for compliance standards like SOC 2, HIPAA and ISO 27001 to creating the world's leading Trust Management Platform, our vision remains unchanged. 

Now more than ever, making security continuous—not just a point-in-time check— is essential. Thousands of companies rely on Vanta to build, maintain and demonstrate their trust— all in a way that's real-time and transparent.

Referral Instructions

If you are being referred for the role, please contact that person to apply on your behalf.

 
 
 

Skills Required

  • 7+ years of GRC and/or Information Security experience
  • 2+ years of experience managing technical or subject matter expert teams
  • Experience owning or heavily contributing to programs spanning Product, Engineering, and GTM
  • Strong program management instincts
  • Deep GRC craft knowledge
  • Product mindset for translating needs into product capabilities
  • Technical and automation fluency
  • Analytical and detail-oriented skills
  • Excellent written and verbal communication skills
  • Self-motivated and adaptable in a fast-paced environment
  • Federal experience a plus
  • Privacy regulation experience a plus
  • Certifications preferred

Vanta Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Vanta and has not been reviewed or approved by Vanta.

  • Healthcare Strength Health coverage is described as comprehensive, with employer-covered premiums for many employee-only plan options alongside dental, vision, and mental-health support. Plan designs are portrayed as robust with low-to-no premium options available on some offerings.
  • Parental & Family Support Paid parental leave for all parents is highlighted as fully paid and substantial in length. Family-related support is consistently presented as a core part of the package.
  • Flexible Benefits Remote-first flexibility and multiple stipends (wellness, phone/internet, home office, and commuter in hub locations) are emphasized as standard components. Flexible schedules further support differing employee needs across locations.

Vanta Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Francisco, CA
361 Employees
Year Founded: 2016

What We Do

Our mission at Vanta is to be a layer of trust on top of cloud services, to secure the internet, increase trust in software companies, and keep consumer data safe. Think of us as your automated security and compliance expert.

Similar Jobs

Optum Logo Optum

Senior Data Engineer

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office or Remote
La Crosse, WI, USA
160000 Employees
92K-164K Annually

Optum Logo Optum

Medical Claims Review Medical Director - Surgeon - Remote

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office or Remote
Eden Prairie, MN, USA
160000 Employees
249K-373K Annually

Optum Logo Optum

Sales Executive

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office or Remote
Eden Prairie, MN, USA
160000 Employees
90K-195K Annually

Optum Logo Optum

Senior Director, RCM Product Growth - Remote

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office or Remote
Washington, DC, USA
160000 Employees
159K-273K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account