SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Vanta is seeking a Subject Matter Expert in Governance, Risk, and Compliance (GRC) to serve as a dedicated practitioner embedded within Strategic and Enterprise Account Executive teams. This is a customer-facing revenue role, not a back-office compliance function.
You will operate as a named member of deal teams under a pod model, paired with Account Executives and Sales Engineers from first discovery through POC, onsite visits, close, and expansion. You'll be the trusted practitioner in the room with buyers' CISOs and GRC leads, and the internal expert that AEs, SEs, and marketing teams build around.
Key responsibilities include: joining discovery and qualification calls at early deal stages; scoping compliance programs across Vanta's platform; supporting demos, POCs, workshops, and customer onsites covering Compliance, Third-Party Risk Management, Risk Management, and Trust/Questionnaire Automation; advising prospects on program architecture including multi-framework strategy, shared controls, and audit sequencing; answering field questions at customer-forwardable quality, including reviewing AI-agent-generated answers; designing and delivering enablement through live sessions, bootcamp scenarios, mock customer roleplay, and async curriculum; owning monthly alignment cadences with sales managers; feeding structured product feedback to Product and PM partners; and traveling roughly quarterly for customer onsites, POC workshops, team offsites, and events.
You'll operate in an AI-first environment, using AI agents daily as a quality gate on their output and ideally building tooling of your own. Domain coverage spans nine pillars: Governance, Data Governance, Compliance, Risk Management (IT, Security, Enterprise), Third-Party Risk Management, Continuous Monitoring, Privacy, Trust, and AI Security & Governance. You should be T-shaped: deep in two to three pillars, conversant and demo-capable across all nine.
Required qualifications: 5+ years of hands-on GRC experience with buyer-side depth, having built, run, or transformed multi-framework compliance programs (SOC 2, ISO 27001/27017/27018/27701, HIPAA/HITRUST, PCI DSS 4.0, GDPR, NIST CSF 2.0); working fluency in at least one emerging area (AI governance, GRC engineering/continuous monitoring, enterprise risk); customer-facing range credible with skeptical CISOs, first-time founders, and procurement teams; production-quality writing; demonstrated AI fluency using LLM tooling in compliance work; teaching ability with experience training, presenting, or enabling others; and sales-process literacy with audit-process depth. Certifications (CISSP, CISA/CISM, ISO 27001 LA/LI, CIPP/CIPT, AI-governance credentials) are welcome signals but not required.