SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Vanta is hiring a Subject Matter Expert (GTM GRC) to serve as the dedicated governance, risk, and compliance (GRC) expert embedded within deal teams. You'll partner with Strategic and Enterprise Account Executives from discovery through close and expansion, acting as the trusted practitioner that buyers' CISOs and GRC leads rely on.
Key responsibilities include: joining discovery and qualification calls to scope compliance programs; advising prospects on multi-framework strategy, control architecture, and audit sequencing; answering field questions at customer-forwardable quality (including validating AI-agent-generated responses); designing and delivering enablement for GTM teams through live sessions, bootcamps, and async curriculum; owning monthly alignment cadences with sales managers; feeding structured product feedback to Product partners; and traveling roughly quarterly for customer onsites, workshops, and events.
You'll operate within Vanta's AI-first approach, using AI agents daily as a quality gate on their output and ideally building tooling yourself. Domain coverage spans nine pillars: Governance, Data Governance, Compliance, Risk Management (IT, Security, Enterprise), Third-Party Risk Management, Continuous Monitoring, Privacy, Trust, and AI Security & Governance. You should be T-shaped: deep in 2-3 pillars, conversant and demo-capable across all nine.
Success requires 5+ years of hands-on GRC experience with buyer-side depth (building or running multi-framework compliance programs like SOC 2, ISO 27001/27017/27018/27701, HIPAA/HITRUST, PCI DSS 4.0, GDPR, NIST CSF 2.0). You need working fluency in at least one emerging area (AI governance, GRC engineering/continuous monitoring, or enterprise risk) and genuine curiosity about the rest. You must demonstrate customer-facing range—credible with skeptical CISOs, first-time founders, and procurement teams. Production-quality writing is essential. You should have demonstrated AI fluency, using LLM tooling in compliance work today, judging AI output against authoritative sources, and wanting to build with it. Teaching ability—training, presenting, publishing, or enabling others—is required. Sales-process literacy (MEDDPICC or similar), audit-process depth, and judgment to hold scope boundaries under deal pressure round out the profile. Certifications (CISSP, CISA/CISM, ISO 27001 LA/LI, CIPP/CIPT, AI-governance credentials) are welcome signals, not gates.