Senior Speciality Account Executive, Vanta for Government
United States
$278k-$327k/yrRemoteFull Time
Vanta: Automated security compliance and trust management software for businesses.
5+ YOE5+ years selling software solutions (SaaS) to government contractors or government agencies; strong knowledge of FedRAMP, CMMC, NIST frameworks; able to navigate government procurement cycles; authorized to work in the U.S.
Mintlify: AI-powered platform for generating and hosting software documentation.
3+ YOE3+ years GRC/compliance program management with direct audit ownership, hands-on Drata (or Vanta) administration, vendor and auditor management, strong follow-through and automation bias.
Rabbet: Construction finance and loan management software platform.
5+ YOE5+ years in operations or similar; ownership of security/compliance (SOC 2/Vanta) or aptitude to do so; executive support, vendor management, strong organization, discretion, and technical aptitude.
First AdvantageNASDAQ: FA: Provides employment background screening and digital identity verification services.
1+ YOE1+ years compliance/risk experience; familiarity with SOX, SOC 2, ISO 27001, NIST; experience with Trust Center platforms (Drata, Vanta) and control automation; strong communication and analytical skills.
Berlin or Iași or London or New York City or São Paulo
HybridFull Time
Taktile: Platform for automated financial risk and credit decisioning.
4+ YOE4+ years GRC or security compliance at a SaaS company; owned SOC 2 program; Vanta/Drata/Secureframe experience; hands-on scripting against AWS for automated evidence; strong written communication.
Blitzy: Autonomous AI platform for enterprise software development.
Hands-on ownership of SOC 2 Type II or ISO 27001:2022 audits, Vanta or equivalent GRC platform experience, auditor/vendor management, FedRAMP exposure preferred, strong written and judgment skills.
ButterflyMX: Smart video intercom and building access control systems.
3+ YOE3+ years in GRC or risk/compliance; SOC 2 audit experience; Vanta experience; familiarity with NIST/ISO frameworks; strong writing and organizational skills; proven use of AI tooling to automate GRC workflows.
Substack: Platform for independent writers to publish and monetize newsletters.
3+ YOE3–5 years in corporate IT/systems administration; hands-on Okta and Apple-focused MDM experience (Iru/Kandji/Jamf); familiarity with SOC 2 and compliance platforms (Vanta/Drata); strong communication and documentation skills.
Syllo: A legal technology building an AI-powered litigation workspace that helps legal teams manage sensitive data.
5+ YOE5+ years in information security compliance/GRC; hands-on ISO 27001 and SOC 2 experience; Vanta or comparable GRC experience; cloud IAM, logging, and vendor risk management; technical fluency and strong written communication.
Inkit: Software platform for secure document generation and digital signatures.
Proven GRC leadership in B2B SaaS, hands-on Vanta experience, knowledge of SOC 2/ISO/FedRAMP/NIST/DoD IL frameworks, strong cross-functional communication, and ability to build scalable risk and compliance processes.
RISCPoint: Provides cybersecurity compliance, cloud security, and risk management advisory.
3+ YOE3+ years supporting or leading cybersecurity compliance engagements; experience with SOC 1/2, ISO 27001, HITRUST, HIPAA; familiarity with Vanta/Drata and cloud platforms; bachelor’s or master’s degree preferred; industry certifications preferred.
Velera: Integrated fintech and payment processing solutions for credit unions.
8+ YOE8+ years in cyber GRC or related fields, 5+ years in GRC program management, experience implementing GRC tools (Optro,Vanta,Drata,OneTrust), PCI/NIST/SOC audit experience, strong stakeholder and program skills.
Austin or Denver or Indianapolis or Los Angeles or San Francisco or New York or Salt Lake City or Minneapolis or Seattle or Nashville
$135k-$150k/yrRemoteFull Time
Givebutter: Fundraising and CRM platform for nonprofit organizations.
5+ YOE5+ years IT experience; hands-on IT ops (MDM, device and SaaS administration, identity lifecycle), Notion administration, GRC project management with Vanta/Drata, familiarity with SOC 2/ISO 27001/PCI, remote/Mac environment experience.
Vanta, Drata, Notion, Google Workspace, Slack, 1Password, Mobile Device Management (MDM), Claude, Cursor, ChatGPT
Spellbook: AI-powered contract drafting and review software for legal teams.
Experience in compliance/GRC/audit for SaaS or regulated customers; familiarity with SOC 2, FedRAMP, HIPAA, NIST; hands-on audit evidence collection and control documentation; experience with Vanta/Linear; US citizenship and valid US passport or REAL ID.
Morgan & Morgan: Provides legal representation for personal injury and consumer litigation.
4+ YOE4+ years in GRC/IT audit/compliance/information security; hands-on GRC platform experience (Vanta preferred); strong knowledge of ISO 27001, NIST CSF, CIS v8.1; ISC2 or ISACA certification required; experience leading audits and vendor risk assessments.
Ivo: AI-powered contract review and intelligence platform for legal teams.
3+ YOE3–5 years GRC/InfoSec/IT audit experience; hands-on SOC 2 Type II, ISO 27001, CSA STAR, ISO/IEC 42001; experience with Vanta, audits, evidence management, risk assessments, policy maintenance, and strong communication skills.
Clear Capital: AI-driven real estate valuation and property data solutions.
3+ YOE5+ years GRC/risk/compliance experience with Bachelor’s (or 3+ years with Master’s) or equivalent; deep knowledge of NIST, ISO, SOC 2, GLBA/CCPA/GDPR; relevant certifications (CISSP, CISM, CISA, CRISC, AIGP); familiarity with Vanta, Drata, OneTrust, cloud and DevOps; strong analytics and communication.
NIST CSF, NIST RMF, ISO 27001, ISO 27002, ISO 42001, SOC 2, GLBA, CCPA, GDPR, Vanta, Drata, OneTrust, DevOps, cloud computing
Sr. Security Engineer, Corporate Information Security
New York City, New York, United States
$165k-$185k/yrHybridFull Time
Betterment: Automated investment management and retirement planning platform.
6+ YOE6+ years security engineering experience with deep IAM expertise; strong knowledge of authentication protocols, endpoint hardening, vulnerability management, automation (Python/Go), and SOC 2/ISO 27001 compliance.