Vanta · 3 days ago
Senior Director, GRC Engineering
Vanta is a company focused on helping businesses earn and prove trust through continuous security monitoring and verification. As a Senior Director of GRC Engineering, you will lead the Governance, Risk, and Compliance efforts, ensuring compliance with certifications and driving innovative security strategies within the organization.
Artificial Intelligence (AI)ComplianceCyber SecurityInternetSoftware
Responsibilities
Oversee the work of our governance, risk, and compliance functions that include Vendor Risk Management, Risk Management, Policy Management, Training and Awareness, and Customer Trust
Ensure ongoing compliance to our SOC II and ISO certifications
Drive the next evolution of our program to meet FedRAMP Authorization (Moderate 20x and Moderate Rev 5)
Lead and grow a team of the best security professionals in the world, with a view of security that is forward thinking, human-centric, and trust-based
Drive concepts of GRC Engineering throughout your organization and lean into automated compliance strategies to show ongoing commitment to security
Shape the next evolution of internal GRC strategy internally and be an active voice externally
Provide, both individually and through your teams, expert feedback to Vanta’s Engineering, Product and Design teams on our product offerings and serve as a strong customer voice in product development
Represent Vanta’s products, vision, and voice as a trusted security thought leader in public security forums
Participate within the CISO leadership team and collaborate extensively with other leaders within the Security Engineering and Operations teams
Track the team’s performance and report goals and objectives to leaders outside of the security team
Partner with the Vanta's Sales and Customer Success teams to represent Vanta’s Trust Management Platform to prospects and customers
Become an expert on the security features available for customers to deploy within Vanta, including best practices for implementation
Serve as Vanta customer zero by testing and implementing all Vanta capabilities within our own GRC program
Coordinate with cross-functional teams to provide customers with meaningful updates on features and programs
Qualification
Required
10+ years of experience working in the Governance, Risk, and Compliance industry
Strong leadership experience and an ability to lead a team from a foundation of transparency and trust
Experience working with security and privacy frameworks, including SOC II, ISO 27001, ISO 27701, and FedRAMP
Demonstrable expertise in SOC II, ISO 27001, NIST 800-53 at minimum
Experience managing a large team of people (10+)
Experience working and interfacing with C-level customer contacts
Technical expertise to understand and explain security and GRC concepts
Familiarity with Cloud Infrastructure, Risk Management, Policy Management, Security Training and Awareness, Vendor Risk Management, Vulnerabilities Management, and their related security processes
Experience in building productive relationships and driving collaboration with both technical and non-technical teams
Knowledge of the audit process and experience owning SOC2, ISO, and FedRAMP audits
Preferred
Security compliance management experience within a SaaS environment preferred, but not required
Professional customer facing experience preferred, but not required
Security certifications (e.g. CISA, CISSP) and/or formal education strongly preferred, but not required
Benefits
100% covered medical, dental, and vision benefits with dependents coverage
16 weeks fully-paid parental Leave for all new parents
Health & wellness and remote workplace stipends
Family planning benefits through Carrot Fertility
401(k) matching
Flexible work hours and location
Open PTO policy
11 paid holidays in the US
Company
Vanta
Vanta is a trust management platform that automates compliance and risk management.
H1B Sponsorship
Vanta has a track record of offering H1B sponsorships. Please note that this does not
guarantee sponsorship for this specific role. Below presents additional info for your
reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2025 (23)
2024 (6)
2023 (4)
2022 (10)
2021 (3)
Funding
Current Stage
Late StageTotal Funding
$503MKey Investors
Wellington ManagementSequoia CapitalCrowdStrike
2025-07-23Series D· $150M
2024-07-24Series C· $150M
2023-05-10Series B
Recent News
2025-12-20
Business Wire
2025-11-18
Company data provided by crunchbase