Governance, Risk, and Compliance Expert, GTM - V4G
Vanta · Remote U.S. · 2026-09-04
About this role
At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it.
As one of Vanta’s GTM-facing GRC Subject Matter Experts supporting Vanta for Government (V4G) opportunities, you will be a highly visible, customer-facing leader within Vanta’s Security team, responsible for representing Vanta’s Trust Management Platform to prospects and customers, bringing deep public-sector compliance expertise across FedRAMP, GovRAMP, TX-RAMP, NIST 800-53, CMMC 2.0, and NIST 800-171. You will also have a role in collaborating with internal teams to help drive and implement new V4G product features. This role is specifically involved with Vanta's pre-sales and marketing motions, owning V4G GRC conversations for net-new prospects and the expansion of existing customers' use of the product, as well as supporting marketing efforts by representing Vanta in public-facing conversations and speaking engagements.
If this sounds like you, and you're excited to use your Security, Privacy, and broader Gov-focused GRC experience to help grow and sell our product, we'd love to hear from you.
What you’ll do as a Governance, Risk, and Compliance Expert, GTM - V4G at Vanta:
- Use your expert knowledge of compliance frameworks like FedRAMP, GovRAMP, TX-RAMP, NIST 800-53, CMMC 2.0, and NIST 800-171, to advise customers regarding questions about scoping, policy creation, detailed control requirements and security best practices, and recommend implementations within Vanta’s product related to these frameworks.
- Partner with Vanta's Sales, Account Management, and Solutions Engineering teams and own public-sector GRC discussions & activities, representing Vanta’s Trust Management Platform to prospects/customers.
- Become an expert in V4G product features to translate how they can help optimize prospect/customer public-sector GRC workflows.
- Engage with executives and senior staff at prospect and customer organizations to establish relationships with customer security, privacy, and AI teams.
- Answer questions from internal and external stakeholders on GRC programs, including program foundation/scaling strategies, framework-specific requirements, third-party risk management, and broader IT, security, privacy, and enterprise risk workflows - and how Vanta's platform supports each.
- Develop publicly-available marketing and education content focused on public-sector GRC for prospects, customers, and partners.
- Represent Vanta in public-facing activities including speaking on webinars & panels, participating in conferences, networking at Vanta/partner-led events, and other marketing or thought leadership events.
- Partner with GTM Enablement teams to design and deliver training for Vanta's Sales and Account Management orgs on GRC and Vanta product disciplines across security, privacy, and AI governance.
- Identify customer requirements that expand or improve Vanta’s product across security, privacy, and AI governance, and provide input and feedback for feature development.
- Travel roughly twice per quarter (a few days to a week) for customer onsites, POC workshops, team offsites, and other events.
What we're looking for
- 5+ years of experience US government compliance, with direct experience taking an organization to FedRAMP Ready or Authorized, assessing as a 3PAO, or both.
- Working knowledge of federal frameworks such as FedRAMP (all impact levels and the program's active modernization), CMMC 2.0, NIST 800-53 and 800-171, and StateRAMP/state-program dynamics .
- Foundational knowledge of baseline security compliance frameworks such as ISO 27001 & SOC 2.
- Strong understanding of of SSP and POA&M authorship-level familiarity as well as ConMon operations
- Familiarity with cloud infrastructure, version control systems, risk management, vulnerability management, and their related security processes.
- Experience with third-party/vendor risk management (TPRM) processes, including due diligence, risk scoring, risk assessments, and ongoing monitoring processes.
- Background in broader IT, security, and/or enterprise risk management workflows, including risk scoring, likelihood/impact analysis, and treatment planning.
- Excellent communication and facilitation skills, with the ability to deliver high-impact learning experiences and earn credibility with experienced, senior-level sellers.
- Strong written and verbal communication skills, comfortable engaging customer-facing stakeholders, including C-level contacts, security & privacy leaders, and legal teams, as well as more public partner and industry audiences.
- Comfortable using AI to amplify and strengthen GRC work - demonstrating curiosity, a willingness to learn, and sound judgment in applying AI responsibly to improve efficiency and impact.
- Enterprise sales process literacy (e.g., MEDDPICC) preferred, but not required.
- Customer Trust or Sales Engineering experience preferred, but not required.
- Certifications (e.g., CISA, CISSP, RP, CCA, CCP) and/or formal education preferred, but not required.
What you can expect as a Vanta’n:
- Industry-competitive salary and equity
- Comprehensive medical, dental, and vision coverage, with 100% of employee-only benefit premiums covered for most medical plans
- 16 weeks paid Parental Leave for all new parents
- Health & wellness stipend
- Remote workspace, internet, and cellphone stipend
- Commuter benefits for team members who report to the SF and NYC office
- Family planning benefits
- Matching 401(k) contribution with immediate vesting
- Flexible PTO policy, plus 80 hours of Sick Time
- 11 company-paid holidays
- Virtual team building activities, lunch and learns, and…
Similar jobs
- Governance, Risk, and Compliance Expert, GTM, Pre-SalesVanta · Remote U.S.
Your next role is already in here.
Search live openings from thousands of employers, save the ones worth a second look, and let JobBob keep watch for the rest.