Vanta
Compliance Automation Engineer, GRC
Job Summary
The role involves designing and developing automation solutions for evidence collection, supporting various security frameworks and compliance standards such as FedRAMP, SOC 2, and ISO 27001. The candidate will automate control testing, monitor compliance posture, and support audit readiness for public sector requirements. Strong scripting skills, experience with security frameworks, and API integration are essential. The position emphasizes collaboration with engineering and product teams to embed compliance into workflows and improve security processes.
Required Skills
Benefits
Job Description
At Vanta, our mission is to help businesses earn and prove trust.We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it.
Vanta is growing quickly and we're continually moving upmarket, dealing with sophisticated customers with complex security and compliance environments and needs. Our Security team uses our own Security and Privacy GRC experience to meet customer demand to help grow our market share as the industry leader in compliance and security.
As a Compliance Automation Engineer, GRC at Vanta, you will support FedRAMP Authorization efforts on the Vanta Security Team, working closely with cross-functional Engineering and Product teams. Your focus will be managing critical authorization audit readiness and continuous monitoring process, automating evidence collection wherever possible.
If this sounds like you, and you're excited to use your Security and GRC experience to help grow and sell our product, we'd love to hear from you.
Visit ourVanta Engineering Blog to learn more about what our team is working on!
What you’ll do as a Compliance Automation Engineer, GRC at Vanta:
Design and develop automation solutions for evidence collection across infrastructure, endpoints, and SaaS platforms (e.g., AWS, GCP, GitHub, Okta).
Build and maintain scripts and APIs to interface with compliance tooling
Support recurring internal and external audits (FedRAMP, SOC 2, ISO 27001, HIPAA, etc.) by ensuring automated and reliable control monitoring
Automate control testing and reporting pipelines to reduce manual effort and improve accuracy
Support internal GRC platforms, dashboards, and metrics to communicate compliance posture and audit findings
Work with the compliance team to define technical control requirements and translate them into measurable, testable systems
Work with Engineering partners to embed compliance checks into CI/CD pipelines and infrastructure deployment workflows
Establish and manage the POAM and Continuous Monitoring processes and run monthly PMO meetings
Manage compliance deliverables for public sector stakeholders and manage ongoing updates
Leverage AI/ML tools to drive automation and improve efficiency and outcomes for audit and monitoring processes
Drive remediation for Security Team gaps and dependencies - this includes investigating and POCing solutions to replace existing tech where needed
Drive remediation of FedRMAP authorization gaps
Support policy and process implementation for business and engineering processes to support authorization
Support the implementation of technical controls within the security and engineering teams
Contribute to the development of machine readable reports for Product Team
Gather performance metrics and report KPIs to security team leaders
Become an expert on the Vanta public sector product offerings and provide regular feedback to product teams
Support the team responding to public sector security questionnaires
Partner to help improve existing and launch new security and compliance processes, programs, and policies where needed
Support audit readiness across Vanta’s compliance frameworks as needed
How to be successful in this role:
3+ years of experience in scripting, automation, or backend engineering roles with a focus on security, infrastructure, or compliance
Expertise with public sector security frameworks like FedRAMP and CMMC
Experience with other NIST frameworks like NIST CSF, 800-53, 800-171, RMF
Ability to write scripts and basic code to automate audit and evidence gathering processes
Proficiency in at least one or more common scripting languages like Python, Go, PowerShell, Bash, Ruby, or JavaScript,
Experience consuming and building RESTful APIs to integrate various security, IT, and GRC tools
Experience querying APIs, building command-line tools, and working with structured data (JSON, CSV, YAML, OSCAL)
Ability to query and manipulate data in various datastores to extract compliance-relevant information
Familiarity with Cloud Infrastructure, Version Control Systems, Risk Management, Vulnerabilities, and their related security processes
Experience in product and program management
Experience in building productive relationships and driving collaboration with both technical and non-technical teams
Knowledge of audit processes and evidence requirements for cybersecurity frameworks
Security compliance management experience within a SaaS environment preferred, but not required
Experience working with other security frameworks like SOC2 and ISO27001 preferred but not required
Security certifications (e.g. CISA, CISSP, CRISC) and/or formal education strongly preferred, but not required
What you can expect as a Vantan:
Industry-competitive compensation
100% covered medical, dental, and vision benefits with dependents coverage
16 weeks fully-paid parental Leave for all new parents
Health & wellness and remote workplace stipends
Family planning benefits through Carrot Fertility
401(k) matching
Flexible work hours and location
Open PTO policy
11 paid holidays in the US
Offices in SF, NYC, London, Dublin, and Sydney
To provide greater transparency to candidates, we share base pay ranges for all US-based job postings regardless of state. We set standard base pay ranges for all roles based on function, level, and country location, benchmarked against similar-stage growth companies. Final offer amounts are determined by multiple factors and may vary based on candidate location, skills, depth of work experience, and relevant licenses/credentials.
#LI-remote
At Vanta, we are committed to hiring diverse talent of different backgrounds and as such, it is important to us to provide an inclusive work environment for all. We do not discriminate on the basis of race, gender identity, age, religion, sexual orientation, veteran or disability status, or any other protected class. As an equal opportunity employer, we encourage and welcome people of all backgrounds to apply.
About Vanta
We started in 2018, in the wake of several high-profile data breaches. Online security was only becoming more important, but we knew firsthand how hard it could be for fast-growing companies to invest the time and manpower it takes to build a solid security foundation. Vanta was inspired by a vision to restore trust in internet businesses by enabling companies to improve and prove their security. From our early days automating security monitoring for compliance standards like SOC 2, HIPAA and ISO 27001 to creating the world's leading Trust Management Platform, our vision remains unchanged.
Now more than ever, making security continuous—not just a point-in-time check— is essential. Thousands of companies rely on Vanta to build, maintain and demonstrate their trust— all in a way that's real-time and transparent.
Vanta
Vanta automates the complex and time-consuming process of SOC 2, HIPAA, ISO 27001, PCI, and GDPR compliance certification. Automate your security monitoring in weeks instead of months.
See more jobsSafe Remote Job Search Tips
Verify Employer Thoroughly
Research the company's identity thoroughly before applying. Check for a professional website with contacts, active social media, and LinkedIn profiles. Verify details across platforms and look for reviews on Glassdoor or Trustpilot to confirm legitimacy.
Never Pay to Get a Job
Legitimate employers never require payment for applications, training, background checks, or equipment. Always reject upfront payment requests or demands for bank details, even if they claim it's for purchasing necessary work gear on your behalf.
Safeguard Your Personal Information
Protect sensitive data like SSN, bank details, or ID copies. Share this only after accepting a formal, written job offer. Ensure it's submitted via a secure company system or portal, never through insecure channels like standard email attachments.
Scrutinize Communication & Interviews
Watch for communication red flags: poor grammar, generic emails (@gmail), vague details, or undue pressure. Be highly suspicious of interviews held only via text or chat apps; legitimate companies typically use video or phone calls.
Beware of Unrealistic Offers
If an offer's salary or benefits seem unrealistically high for the work involved, be cautious. Research standard pay for similar roles. Offers that appear 'too good to be true' are often scams designed to lure you into providing information or payment.
Insist on a Formal Contract
Always secure and review a formal, written job offer or employment contract before starting work or sharing final personal details. Ensure it clearly defines your role, compensation, key terms, and conditions to avoid misunderstandings or scams.