At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, an…
At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it.
Vanta's government motion is expanding across federal and SLED, and this role is the practitioner engine behind it. As a V4G GTM GRC SME you bring deep public-sector compliance expertise — FedRAMP, CMMC, NIST 800-53 and 800-171, StateRAMP and state-program equivalents — directly into deals: scoping a SaaS ISV's path to FedRAMP authorization, helping a defense supplier reason about CMMC level and boundary, and showing state and local buyers how Vanta operationalizes their requirements.
This is a revenue seat, not a policy seat. You'll partner directly with V4G sales leadership on key deals, engage from first qualification through POC, onsite, and close, and serve as the trusted voice a government-market buyer's security team relies on. Because the government motion is a focused team inside a larger SME function, you'll also operate with unusual autonomy — triaging your own deal book, owning your relationship with sales leadership, and backstopping the broader SME channel on commercial frameworks when needed.
- Serve as the dedicated GRC SME for government-market opportunities: federal ISVs pursuing FedRAMP, defense industrial base companies facing CMMC, and SLED buyers and sellers — from discovery and qualification through demos, POCs, workshops, and onsites.
- Advise on authorization strategy: FedRAMP path and impact-level selection, boundary definition, ConMon obligations, SSP/POA&M readiness, 3PAO engagement, agency sponsorship dynamics, and how Vanta's platform supports each phase. Stay current as the FedRAMP program modernizes — your knowledge must be this-year, not last-cycle.
- Map federal and state requirements to Vanta's product: NIST 800-53/171 coverage, continuous monitoring and automated evidence, GovCloud-relevant architecture questions, and custom-framework strategy for state programs.
- Answer field questions at customer-forwardable quality, including reviewing and validating AI-agent-generated answers before they reach customers; use AI tooling daily and help extend it into the government motion.
- Build and deliver public-sector enablement for GTM teams; review government-market marketing content; feed structured product feedback that shapes Vanta's federal roadmap.
- Travel roughly once per quarter (a few days to a week) for customer onsites, workshops, public-sector events, and team offsites.
Domain coverage. We hire T-shaped practitioners. For this role the required spikes are federal compliance and continuous monitoring (ConMon), with conversational, demo-capable coverage across the full pillar set: Governance · Data Governance · Compliance · Risk Management (IT, Security, and Enterprise) · TPRM · Continuous Monitoring · Privacy · Trust · AI Security & Governance. Commercial framework fluency (SOC 2, ISO 27001) remains required - government deals routinely carry both.
What we're looking for
- 5+ years in US government compliance, with direct experience taking an organization to FedRAMP Ready or Authorized, assessing as a 3PAO, or both.
- Current, working command of FedRAMP (all impact levels and the program's active modernization), CMMC 2.0 (including the shift to 800-171 rev. 3 alignment questions), NIST 800-53 and 800-171, and StateRAMP/state-program dynamics; SSP and POA&M authorship-level familiarity; ConMon operations (scan cadence, POA&M management, significant change).
- SLED literacy: how state, local, and education procurement actually buys, and where compliance requirements enter the cycle.
- Commercial framework baseline (SOC 2, ISO 27001) and comfort backs
Neutral 2–4 sentence summary of what working at this company is like, drawn from public reviews and press coverage. Tone, collaboration style, pace, benefits highlights.
At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, an…
At M&G, our purpose is to give everyone real confidence to put their money to work. With a heritage dating back more than 175 years, we have…
At M&G, our purpose is to give everyone real confidence to put their money to work. With a heritage dating back more than 175 years, we have…
Work Location: United Kingdom, remote Engagement Model: Freelancer / Independent Contractor Project Duration: 3 months (with potential exten…
At M&G, our purpose is to give everyone real confidence to put their money to work. With a heritage dating back more than 175 years, we have…
At M&G, our purpose is to give everyone real confidence to put their money to work. With a heritage dating back more than 175 years, we have…