Governance, Risk, and Compliance Expert, GTM - V4G

Vanta · Remote U.S. · $171K – $201K · Operations

Posted 2026-09-07

Apply for this role →

As one of Vanta’s GTM-facing GRC Subject Matter Experts supporting Vanta for Government (V4G) opportunities, you will be a highly visible, customer-facing leader within Vanta’s Security team, responsible for representing Vanta’s Trust Management Platform to prospects and customers, bringing deep public-sector compliance expertise across FedRAMP, GovRAMP, TX-RAMP, NIST 800-53, CMMC 2.0, and NIST 800-171. You will also have a role in collaborating with internal teams to help drive and implement new V4G product features. This role is specifically involved with Vanta's pre-sales and marketing motions, owning V4G GRC conversations for net-new prospects and the expansion of existing customers' use of the product, as well as supporting marketing efforts by representing Vanta in public-facing conversations and speaking engagements.

If this sounds like you, and you're excited to use your Security, Privacy, and broader Gov-focused GRC experience to help grow and sell our product, we'd love to hear from you.

What you’ll do as a Governance, Risk, and Compliance Expert, GTM - V4G at Vanta:

- Use your expert knowledge of compliance frameworks like FedRAMP, GovRAMP, TX-RAMP, NIST 800-53, CMMC 2.0, and NIST 800-171, to advise customers regarding questions about scoping, policy creation, detailed control requirements and security best practices, and recommend implementations within Vanta’s product related to these frameworks.

- Partner with Vanta's Sales, Account Management, and Solutions Engineering teams and own public-sector GRC discussions & activities, representing Vanta’s Trust Management Platform to prospects/customers.

- Become an expert in V4G product features to translate how they can help optimize prospect/customer public-sector GRC workflows.

- Engage with executives and senior staff at prospect and customer organizations to establish relationships with customer security, privacy, and AI teams.

- Answer questions from internal and external stakeholders on GRC programs, including program foundation/scaling strategies, framework-specific requirements, third-party risk management, and broader IT, security, privacy, and enterprise risk workflows - and how Vanta's platform supports each.

- Develop publicly-available marketing and education content focused on public-sector GRC for prospects, customers, and partners.

- Represent Vanta in public-facing activities including speaking on webinars & panels, participating in conferences, networking at Vanta/partner-led events, and other marketing or thought leadership events.

- Partner with GTM Enablement teams to design and deliver training for Vanta's Sales and Account Management orgs on GRC and Vanta product disciplines across security, privacy, and AI governance.

- Identify customer requirements that expand or improve Vanta’s product across security, privacy, and AI governance, and provide input and feedback for feature development.

- Travel roughly twice per quarter (a few days to a week) for customer onsites, POC workshops, team offsites, and other events.

What we're looking for

- 5+ years of experience US government compliance, with direct experience taking an organization to FedRAMP Ready or Authorized, assessing as a 3PAO, or both.

- Working knowledge of federal frameworks such as FedRAMP (all impact levels and the program's active modernization), CMMC 2.0, NIST 800-53 and 800-171, and StateRAMP/state-program dynamics .

- Foundational knowledge of baseline security compliance frameworks such as ISO 27001 & SOC 2.

- Strong understanding of of SSP and POA&M authorship-level familiarity as well as ConMon operations

- Familiarity with cloud infrastructure, version control systems, risk management, vulnerability management, and their related security processes.

- Experience with third-party/vendor risk management (TPRM) processes, including due diligence, risk scoring, risk assessments, and ongoing monitoring processes.

- Background in broader IT, security, and/or enterprise risk management workflows, including risk scoring, likelihood/impact analysis, and treatment planning.

- Excellent communication and facilitation skills, with the ability to deliver high-impact learning experiences and earn credibility with experienced, senior-level sellers.

- Strong written and verbal communication skills, comfortable engaging customer-facing stakeholders, including C-level contacts, security & privacy leaders, and legal teams, as well as more public partner and industry audiences.

- Comfortable using AI to amplify and strengthen GRC work - demonstrating curiosity, a willingness to learn, and sound judgment in applying AI responsibly to improve efficiency and impact.

- Enterprise sales process literacy (e.g., MEDDPICC) preferred, but not required.

- Customer Trust or Sales Engineering experience preferred, but not required.

- Certifications (e.g., CISA, CISSP, RP, CCA, CCP) and/or formal education preferred, but not required.

What you can expect as a Vanta’n:

- Industry-competitive salary and equity

- Comprehensive medical, dental, and vision coverage, with 100% of employee-only benefit premiums covered for most medical plans

- 16 weeks paid Parental Leave for all new parents

- Health & wellness stipend

- Remote workspace, internet, and cellphone stipend

- Commuter benefits for team members who report to the SF and NYC office

- Family planning benefits

- Matching 401(k) contribution with immediate vesting

- Flexible PTO policy, plus 80 hours of Sick Time

- 11 company-paid holidays

- Virtual team building activities, lunch and learns, and other company-wide events!

- Offices in SF, NYC, London, Dublin, Tel Aviv, and Sydney

To provide greater transparency to candidates, we share base pay ranges for all US-based job postings regardless of state. We set standard base pay ranges for all roles based on function, level, and country location, benchmarked against similar-stage growth companies. Final offer amounts are determined by multiple factors and may vary based on candidate location, skills, depth of work experience, and relevant licenses/credentials.

#LI-remote

Apply for this role →

← Back to all jobs