Vanta

Compliance Automation Engineer, GRC

United States

$139,000 – $164,000Compensation
Junior (1 to 2 years)Experience Level
Full TimeJob Type
UnknownVisa
Cybersecurity, Information Security, Compliance & Risk ManagementIndustries

Compliance Automation Engineer, GRC

Salary: $139K - $164K Location Type: Remote Employment Type: Full-Time

Position Overview

At Vanta, our mission is to secure the internet and protect consumer data. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. Vanta is growing quickly and we're continually moving upmarket, dealing with sophisticated customers with complex security and compliance environments and needs. Our Security team uses our own Security and Privacy GRC experience to meet customer demand to help grow our market share as the industry leader in compliance and security.

As a Compliance Automation Engineer, GRC at Vanta, you will support FedRAMP Authorization efforts on the Vanta Security Team, working closely with cross-functional Engineering and Product teams. Your focus will be managing critical authorization audit readiness and continuous monitoring processes, automating evidence collection wherever possible.

If this sounds like you, and you're excited to use your Security and GRC experience to help grow and sell our product, we'd love to hear from you.

Visit our Vanta Engineering Blog to learn more about what our team is working on!

Responsibilities

  • Design and develop automation solutions for evidence collection across infrastructure, endpoints, and SaaS platforms (e.g., AWS, GCP, GitHub, Okta).
  • Build and maintain scripts and APIs to interface with compliance tooling.
  • Support recurring internal and external audits (FedRAMP, SOC 2, ISO 27001, HIPAA, etc.) by ensuring automated and reliable control monitoring.
  • Automate control testing and reporting pipelines to reduce manual effort and improve accuracy.
  • Support internal GRC platforms, dashboards, and metrics to communicate compliance posture and audit findings.
  • Work with the compliance team to define technical control requirements and translate them into measurable, testable systems.
  • Work with Engineering partners to embed compliance checks into CI/CD pipelines and infrastructure deployment workflows.
  • Establish and manage the POAM and Continuous Monitoring processes and run monthly PMO meetings.
  • Manage compliance deliverables for public sector stakeholders and manage ongoing updates.
  • Leverage AI/ML tools to drive automation and improve efficiency and outcomes for audit and monitoring processes.
  • Drive remediation for Security Team gaps and dependencies - this includes investigating and POCing solutions to replace existing tech where needed.
  • Drive remediation of FedRAMP authorization gaps.
  • Support policy and process implementation for business and engineering processes to support authorization.
  • Support the implementation of technical controls within the security and engineering teams.
  • Contribute to the development of machine-readable reports for Product Team.
  • Gather performance metrics and report KPIs to security team leaders.
  • Become an expert on the Vanta public sector product offerings and provide regular feedback to product teams.
  • Support the team responding to public sector security questionnaires.
  • Partner to help improve existing and launch new security and compliance processes, programs, and policies where needed.
  • Support audit readiness across Vanta’s compliance frameworks as needed.

Requirements

  • Experience: 3+ years of experience in scripting, automation, or backend engineering roles with a focus on security, infrastructure, or compliance.
  • Public Sector Frameworks: Expertise with public sector security frameworks like FedRAMP and CMMC.
  • NIST Frameworks: Experience with other NIST frameworks like NIST CSF, 800-53, 800-171, RMF.
  • Scripting & Automation: Ability to write scripts and basic code to automate audit and evidence gathering processes.
  • Programming Languages: Proficiency in at least one or more common scripting languages like Python, Go, PowerShell, Bash, Ruby, or JavaScript.
  • API Experience: Experience consuming and building RESTful APIs to integrate various security, IT, and GRC tools.

Company Information

At Vanta, our mission is to secure the internet and protect consumer data. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. Vanta is growing quickly and we're continually moving upmarket, dealing with sophisticated customers with complex security and compliance environments and needs. Our Security team uses our own Security and Privacy GRC experience to meet customer demand to help grow our market share as the industry leader in compliance and security.

Skills

Automation scripting
APIs
AWS
GCP
GitHub
Okta
Compliance tooling
Audit support
Control testing
Monitoring
Security and GRC

Vanta

Automates SOC 2 compliance for businesses

About Vanta

Vanta simplifies the process of obtaining and maintaining SOC 2 certification, which is essential for organizations that manage sensitive customer data. The company offers a software-as-a-service (SaaS) platform that automates numerous checks to ensure that security controls are effective and compliant with industry standards. This automation helps small to medium-sized enterprises (SMEs) and tech companies monitor risks and vulnerabilities continuously, significantly reducing the time and cost associated with achieving SOC 2 compliance. Vanta's subscription-based model provides clients with a more efficient and cost-effective way to maintain compliance compared to traditional methods. The goal of Vanta is to transform the compliance process, allowing organizations to focus on their core operations while enhancing their security posture.

San Francisco, CaliforniaHeadquarters
2018Year Founded
$343.4MTotal Funding
SERIES_CCompany Stage
Enterprise Software, CybersecurityIndustries
501-1,000Employees

Benefits

100% Benefits Coverage
Flexible & Remote Work
Paid Parental Leave
Unlimited PTO
Health & Wellness
401(k)

Risks

Emerging competitors like ComplyCube could challenge Vanta's market position.
Healthcare data breaches may increase demand for more robust security measures.
Reliance on partnerships like HITRUST poses risks if standards evolve significantly.

Differentiation

Vanta automates up to 90% of audit preparation, reducing compliance costs significantly.
The platform offers real-time insights, enhancing trust and streamlining security reviews.
Vanta's HITRUST e1 solution automates 80% of requirements, ensuring continuous compliance.

Upsides

Vanta secured $150M in Series C funding, boosting its growth potential.
Partnership with HITRUST enhances Vanta's credibility in the healthcare sector.
Rising demand for automated compliance solutions supports Vanta's market expansion.

Land your dream remote job 3x faster with AI