Manager, Grc Subject Matter Experts, Product

Vanta Vanta · Enterprise · U.S. · Remote · Security

Manager for a team of GRC Subject Matter Experts focused on Vanta's compliance frameworks and content. The role involves leading the team, owning the framework release process, and partnering with Product and Engineering. A key aspect is championing AI-assisted compliance, coaching SMEs on translating domain knowledge into machine-readable specs, evaluation sets, and guardrails, and partnering with Engineering and ML to ship LLM-powered guidance and automation.

What you'd actually do

  1. Hire, mentor, and develop a team of SMEs covering commercial frameworks, government frameworks, test authoring, framework quality uplift, and framework maintenance — planning for current and future capacity needs, setting the bar for technical depth and content quality, and preparing high performers for broader scope
  2. Build a stable, motivated team environment with clear operating rhythms, delegating effectively to grow ownership and capability, and partnering with your leader and People Business Partner to spot and address team health issues early
  3. Connect the team's roadmap and content priorities to Vanta's broader product and company strategy, anticipating near-term shifts in customer needs, regulatory landscape, and product direction, and adjusting focus to keep the team aligned
  4. Create open feedback loops within the team and adapt how you communicate priorities, decisions, and risks across different audiences — from individual contributors to engineering, GTM partners, customers, and executives
  5. Lead the team through change with steadiness while holding yourself and them accountable for commitments — communicating progress and risks proactively, addressing misses directly, and creating an environment where mistakes are treated as learning opportunities rather than blame

Skills

Required

  • GRC expertise
  • people development
  • program management
  • understanding of commercial and government frameworks (SOC 2, ISO 27001/27701, HIPAA, PCI DSS, NIST, FedRAMP)
  • experience with framework release processes
  • ability to translate domain knowledge into machine-readable specs
  • experience with AI-assisted compliance concepts
  • experience with LLM-powered guidance and automation

Nice to have

  • experience in product management
  • experience in engineering partnerships
  • experience in design partnerships
  • experience with risk management, issue and corrective action management, policy management, access reviews, Trust Center, and third-party risk management

What the JD emphasized

  • deep GRC expertise
  • track record of developing people
  • program instincts to drive a high-volume content and product release engine
  • 7+ years of GRC and/or Information Security exper

Other signals

  • AI-assisted compliance
  • LLM-powered guidance and automation
  • machine-readable specs
  • evaluation sets
  • guardrails