Share this article

Meet the Vanta Privacy, Risk, & Compliance Team
Accelerating security solutions for small businesses Tagore offers strategic services to small businesses. | A partnership that can scale Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. | Standing out from competitors Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market. |
As Vanta continues to grow and deliver new capabilities to our leading trust management platform, we’re excited to share more about our own Security, Enterprise Engineering, and Privacy, Risk, & Compliance teams from the teams themselves.
Today, you’ll hear from Matt Cooper, Senior Manager of Vanta’s Privacy, Risk, & Compliance team, and Adam Duman, Information Security and Compliance Manager on the team.
What does the Privacy, Risk, & Compliance team do at Vanta?
The Privacy, Risk, & Compliance team provides internal and external support for Vanta’s customer, auditor, and partner experience in service of the company’s mission to secure the internet. We work in close collaboration with Vanta's Security team to operate our security, privacy, and compliance programs on a daily basis. In addition, we act as Vanta’s subject matter experts in compliance, risk management, and privacy, and also advocate for customers and partners within Vanta’s Product organization.
This means we interface with nearly every element of Vanta’s business to ensure we walk the talk of trust and compliance, deliver on regulatory privacy requirements and processes, and deliver market-leading insights and product solutions for our customers and partners.
How does the team work?
Like Vanta’s Security team, Vanta’s Privacy, Risk & Compliance team embraces Vanta’s remote-first philosophy. We operate across multiple time zones and support Vanta’s global business, which means we’re never far from the action.
Whether it’s a new compliance framework, product feature, or internal initiative, our work is both highly collaborative and highly independent. On the one hand, our work requires close partnership with multiple teams within Vanta. On the other hand, our work also requires a self-starter mindset to identify and drill into the next big thing we need to focus on—before anyone else has seen it.
How is the team structured?
The Privacy, Risk & Compliance team is structured around three main domains (privacy, risk, and compliance) and a host of sub-domains. Our team meets at the start of each week to discuss our goals and our operational and strategic approach for each.
Here’s an overview of the types of work we tackle:
Privacy Operations
Within privacy operations, we deliver on Data Protection Impact Assessment (DPIA) and Transfer Impact Assessment (TIA) requests from customers and partners, and review our internal and external privacy operations. We support Vanta counsel in the review of customer and vendor security and privacy requirements.
In addition, we respond to Subject Access Requests (SAR) under both GDPR and CCPA. We also continuously validate that our website and product are behaving in ways that are in line with regulatory demands, follow best practices defined by the International Association of Privacy Professionals (IAPP), and do the right thing for our customers and website visitors.
Compliance Management
Affectionately dubbed “Vanta on Vanta,” we keep a close eye on Vanta to ensure we continuously maintain the trust we’ve built with our customers, partners and investors. We drive ongoing compliance for our own SOC 2, ISO 27001, GDPR, CCPA/CPRA, and HIPAA support. This includes weekly product check-ins with our primary stakeholders and daily follow-ups for controls in need of attention.
This means we use Vanta ourselves—and have the incredible opportunity to provide direct feedback to Vanta’s own Product and Engineering teams around features, functionality, and ideas. In these types of scenarios, we work the same way as Vanta’s customers. We submit product feedback, and work with our own Customer Success Manager to identify solutions to more effectively use our own product and maximize the value we get from Vanta.
Risk Management
Within Risk Management, we collaborate closely with the Security team. We maintain a robust and thorough risk register that’s shared with our company leadership regularly and incorporated as part of our quarterly and annual planning process. With our backgrounds in privacy, security engineering, cyber threat intelligence, and various other security and privacy domains, we’re able to partner closely with the Security team to identify and address our risks via a comprehensive risk management approach.
Product Support and Development
We’re fortunate to have experience on both sides of the table as assessors and implementers for multiple standards and in multiple environments, which gives us the opportunity to provide unique input and insight on deliverables for Vanta’s Product teams. In collaboration with Product leadership, we triage requested standards and features, help identify the best places for Vanta to improve support for our customers and partners, and deliver foundational elements for these initiatives to support the company’s mission of securing the internet—while making it as easy and simple as possible to achieve and demonstrate trust.
This can take many forms, from referencing source documentation for security and privacy standards and frameworks to partnering closely with our Product team to address valuable feedback from our customers. We also tackle work that may never see the light of day, but nonetheless serves as inputs in our ongoing efforts to continuously improve Vanta’s product.
Rather than maintain the status quo of compliance, we like to reimagine how our world works, and seek out new ways to empower Vanta’s customers and partners alike.
GTM Enablement & Support
Working closely with our Marketing and Enablement teams, we provide training and pre- and post launch support on Vanta’s products. Our goal is to support our Customer Success Managers and Account Executives to provide solutions for customers and partners, whether in direct conversations with Vanta’s customers or in the background by supporting our customer-facing teams.
Where can prospects and customers learn more about Vanta’s privacy, risk, and compliance program?
You can read more about our privacy, risk, and compliance program on Vanta’s website. We also have resources for prospects and customers on our Trust Report and in the Vanta Blog and the Vanta Learning and Communities accessible from the Resources section of our website.
What excites you the most about Vanta’s product and mission?
From our team’s perspective, the easy problems in this space have been solved—and as experienced practitioners, we’ve had the opportunity to see what works and what doesn’t. It’s important to execute well on the fundamentals, like patching systems, providing employee training and support, aligning with business stakeholders, and more. But we’ve also seen and experienced the reality that even though the fundamentals are fundamental for a reason, executing on them can be challenging to navigate in the real world.
What excites us about Vanta is that we have an opportunity to tackle the underlying issues that make these tasks and processes hard in practice—or at least highly manual. Vanta exists to help bridge these gaps, and make those handoffs smoother and more manageable for teams with other work as well.
Any fun facts about the Vanta Privacy, Risk, & Compliance team?
- Our team consists of individuals who have built deep careers as security, privacy & compliance practitioners—and love the space they’ve built their expertise within!
- All members of the team enjoy tiny homes, but agree they wouldn’t want to live in one full time.
Join Vanta’s mission to secure the internet and protect consumer data—learn about our open roles!





FEATURED VANTA RESOURCE
The ultimate guide to scaling your compliance program
Learn how to scale, manage, and optimize alongside your business goals.