远程工作雷达

主题专家,GTM GRC - V4G

Subject Matter Expert, GTM GRC - V4G

开发工程全球可投
公司Vanta
薪资$171,000 - $201,000
工作地点Remote U.S.
地域资格全球可投
时区要求无特别要求
用工类型FullTime
发布时间11 天前
数据来源Ashby
前往企业招聘页投递 →
全球可投:该职位未限制候选人所在地区。仍需注意薪资可能按地区折算,以及实际签约方式(正式雇佣 / 独立合同)。

在 Vanta,我们的使命是帮助企业在赢得信任的同时证明信任。我们相信安全应该持续监控和验证,我们赋能企业更好地实践安全并轻松证明其安全性。Vanta 有一支善良且才华横溢的团队,虽然一些成员有之前的安全经验,但许多人在没有相关经验的情况下也已在 Vanta 取得成功。

Vanta 的政府业务正在联邦和 SLED 市场快速扩展,这个职位是该业务的核心推动者。作为 V4G GTM GRC 专家,你将把深厚的公共部门合规专业知识——FedRAMP、CMMC、NIST 800-53 和 800-171、StateRAMP 和州级计划等——直接带入交易中:规划 SaaS ISV 的 FedRAMP 授权路径,帮助国防供应商分析 CMMC 等级和边界,并向州和地方买家展示 Vanta 如何实现他们的要求。

这是一个收入岗位,而非政策岗位。你将与 V4G 销售领导直接合作处理关键交易,从首次评估到 POC、现场和成交全程参与,并成为政府市场买家安全团队所依赖的可信声音。由于政府业务是 SME 功能内部的一个专注团队,你还将拥有不同寻常的自主权——自行管理自己的交易清单,负责与销售领导的关系,并在需要时为更广泛的 SME 渠道提供商业框架支持。

作为 Vanta 的 GRC 专家(GTM GRC - V4G),你将:

- 成为政府市场机会的专职 GRC 专家:针对联邦 ISV 的 FedRAMP 追求、面对 CMMC 的国防工业基础公司以及 SLED 买家和卖家——从发现和评估到演示、POC、研讨会和现场考察。

- 提供授权策略建议:FedRAMP 路径和影响级别选择、边界定义、持续监控义务、SSP/POA&M 准备情况、3PAO 合作、机构赞助动态,以及 Vanta 平台如何支持每个阶段。保持对 FedRAMP 计划现代化的最新了解——你的知识必须是今年的,而不是上一周期的。

- 将联邦和州的要求映射到 Vanta 的产品中:NIST 800-53/171 的覆盖范围、持续监控和自动化证据、与 GovCloud 相关的架构问题,以及州级计划的定制框架策略。

- 回答客户可接受质量的问题,包括在答案到达客户前审查和验证 AI 代理生成的内容;每天使用 AI 工具,并帮助将其扩展到政府业务中。

- 构建并交付项目

查看英文原文

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it.

Vanta's government motion is expanding across federal and SLED, and this role is the practitioner engine behind it. As a V4G GTM GRC SME you bring deep public-sector compliance expertise — FedRAMP, CMMC, NIST 800-53 and 800-171, StateRAMP and state-program equivalents — directly into deals: scoping a SaaS ISV's path to FedRAMP authorization, helping a defense supplier reason about CMMC level and boundary, and showing state and local buyers how Vanta operationalizes their requirements.

This is a revenue seat, not a policy seat. You'll partner directly with V4G sales leadership on key deals, engage from first qualification through POC, onsite, and close, and serve as the trusted voice a government-market buyer's security team relies on. Because the government motion is a focused team inside a larger SME function, you'll also operate with unusual autonomy — triaging your own deal book, owning your relationship with sales leadership, and backstopping the broader SME channel on commercial frameworks when needed.

What you’ll do as a Subject Matter Expert, GTM GRC - V4G at Vanta:

- Serve as the dedicated GRC SME for government-market opportunities: federal ISVs pursuing FedRAMP, defense industrial base companies facing CMMC, and SLED buyers and sellers — from discovery and qualification through demos, POCs, workshops, and onsites.

- Advise on authorization strategy: FedRAMP path and impact-level selection, boundary definition, ConMon obligations, SSP/POA&M readiness, 3PAO engagement, agency sponsorship dynamics, and how Vanta's platform supports each phase. Stay current as the FedRAMP program modernizes — your knowledge must be this-year, not last-cycle.

- Map federal and state requirements to Vanta's product: NIST 800-53/171 coverage, continuous monitoring and automated evidence, GovCloud-relevant architecture questions, and custom-framework strategy for state programs.

- Answer field questions at customer-forwardable quality, including reviewing and validating AI-agent-generated answers before they reach customers; use AI tooling daily and help extend it into the government motion.

- Build and deliver public-sector enablement for GTM teams; review government-market marketing content; feed structured product feedback that shapes Vanta's federal roadmap.

- Travel roughly once per quarter (a few days to a week) for customer onsites, workshops, public-sector events, and team offsites.

Domain coverage. We hire T-shaped practitioners. For this role the required spikes are federal compliance and continuous monitoring (ConMon), with conversational, demo-capable coverage across the full pillar set: Governance · Data Governance · Compliance · Risk Management (IT, Security, and Enterprise) · TPRM · Continuous Monitoring · Privacy · Trust · AI Security & Governance. Commercial framework fluency (SOC 2, ISO 27001) remains required - government deals routinely carry both.

What we're looking for

- 5+ years in US government compliance, with direct experience taking an organization to FedRAMP Ready or Authorized, assessing as a 3PAO, or both.

- Current, working command of FedRAMP (all impact levels and the program's active modernization), CMMC 2.0 (including the shift to 800-171 rev. 3 alignment questions), NIST 800-53 and 800-171, and StateRAMP/state-program dynamics; SSP and POA&M authorship-level familiarity; ConMon operations (scan cadence, POA&M management, significant change).

- SLED literacy: how state, local, and education procurement actually buys, and where compliance requirements enter the cycle.

- Commercial framework baseline (SOC 2, ISO 27001) and comfort backstopping general GRC questions.

- Self-directed operator: you can run a book, triage competing high-priority deals, and manage a leadership relationship without a daily manager cadence.

- Production-quality writing, demonstrated AI fluency in your own work, teaching ability, and sales-process literacy — the same bar as every Revenue SME.

- Certifications (CISSP, CISA/CISM, CCP/CCA, FedRAMP-relevant training) are welcome signals, not gates. US citizenship or equivalent status may be required for certain customer engagements.

What you can expect as a Vanta’n:

- Industry-competitive salary and equity

- Comprehensive medical, dental, and vision coverage, with 100% of employee-only benefit premiums covered for most medical plans

- 16 weeks paid Parental Leave for all new parents

- Health & wellness stipend

- Remote workspace, internet, and cellphone stipend

- Commuter benefits for team members who report to the SF and NYC office

- Family planning benefits

- Matching 401(k) contribution with immediate vesting

- Flexible PTO policy, plus 80 hours of Sick Time

- 11 company-paid holidays

- Virtual team building activities, lunch and learns, and other company-wide events!

- Offices in SF, NYC, London, Dublin, Tel Aviv, and Sydney

To provide greater transparency to candidates, we share base pay ranges for all US-based job postings regardless of state. We set standard base pay ranges for all roles based on function, level, and country location, benchmarked against similar-stage growth companies. Final offer amounts are determined by multiple factors and may vary based on candidate location, skills, depth of work experience, and relevant licenses/credentials.

#LI-remote

At Vanta, we are committed to hiring diverse talent of different backgrounds and as such, it is important to us to provide an inclusive work environment for all. We do not discriminate on the basis of race, gender identity, age, religion, sexual orientation, veteran or disability status, or any other protected class. As an equal opportunity employer, we encourage and welcome people of all backgrounds to apply.

About Vanta

We started in 2018, in the wake of several high-profile data breaches. Online security was only becoming more important, but we knew firsthand how hard it could be for fast-growing companies to invest the time and manpower it takes to build a solid security foundation. Vanta was inspired by a vision to restore trust in internet businesses by enabling companies to improve and prove their security. From our early days automating security monitoring for compliance standards like SOC 2, HIPAA and ISO 27001 to creating the world's leading Trust Management Platform, our vision remains unchanged.

Now more than ever, making security continuous—not just a point-in-time check— is essential. Thousands of companies rely on Vanta to build, maintain and demonstrate their trust— all in a way that's real-time and transparent.

Referral Instructions

If you are being referred for the role, please contact that person to apply on your behalf.

本页面信息整理自 Ashby,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

← 返回全部职位