Meet the vanta privacy, risk & compliance team.
BlogSecurity
June 8, 2023

Meet the Vanta Privacy, Risk, & Compliance Team

Written by
Matt Cooper
Privacy, Risk & Commpliance
Adam Duman
Information Security & Compliance Manager
Reviewed by
No items found.

Accelerating security solutions for small businesses 

Tagore offers strategic services to small businesses. 

A partnership that can scale 

Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate.

Standing out from competitors

Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

As Vanta continues to grow and deliver new capabilities to our leading trust management platform, we’re excited to share more about our own Security, Enterprise Engineering, and Privacy, Risk, & Compliance teams from the teams themselves. 

Today, you’ll hear from Matt Cooper, Senior Manager of Vanta’s Privacy, Risk, & Compliance team, and Adam Duman, Information Security and Compliance Manager on the team.

What does the Privacy, Risk, & Compliance team do at Vanta?

The Privacy, Risk, & Compliance team provides internal and external support for Vanta’s customer, auditor, and partner experience in service of the company’s mission to secure the internet. We work in close collaboration with Vanta's Security team to operate our security, privacy, and compliance programs on a daily basis. In addition, we act as Vanta’s subject matter experts in compliance, risk management, and privacy, and also advocate for customers and partners within Vanta’s Product organization.

This means we interface with nearly every element of Vanta’s business to ensure we walk the talk of trust and compliance, deliver on regulatory privacy requirements and processes, and deliver market-leading insights and product solutions for our customers and partners. 

How does the team work?

Like Vanta’s Security team, Vanta’s Privacy, Risk & Compliance team embraces Vanta’s remote-first philosophy. We operate across multiple time zones and support Vanta’s global business, which means we’re never far from the action.

Whether it’s a new compliance framework, product feature, or internal initiative, our work is both highly collaborative and highly independent. On the one hand, our work requires close partnership with multiple teams within Vanta. On the other hand, our work also requires a self-starter mindset to identify and drill into the next big thing we need to focus on—before anyone else has seen it. 

How is the team structured?

The Privacy, Risk & Compliance team is structured around three main domains (privacy, risk, and compliance) and a host of sub-domains. Our team meets at the start of each week to discuss our goals and our operational and strategic approach for each. 

Here’s an overview of the types of work we tackle:


Privacy Operations

Within privacy operations, we deliver on Data Protection Impact Assessment (DPIA) and Transfer Impact Assessment (TIA) requests from customers and partners, and review our internal and external privacy operations. We support Vanta counsel in the review of customer and vendor security and privacy requirements. 

In addition, we respond to Subject Access Requests (SAR) under both GDPR and CCPA. We also continuously validate that our website and product are behaving in ways that are in line with regulatory demands, follow best practices defined by the International Association of Privacy Professionals (IAPP), and do the right thing for our customers and website visitors.

Compliance Management

Affectionately dubbed “Vanta on Vanta,” we keep a close eye on Vanta to ensure we continuously maintain the trust we’ve built with our customers, partners and investors. We drive ongoing compliance for our own SOC 2, ISO 27001, GDPR, CCPA/CPRA, and HIPAA support. This includes weekly product check-ins with our primary stakeholders and daily follow-ups for controls in need of attention. 

This means we use Vanta ourselves—and have the incredible opportunity to provide direct feedback to Vanta’s own Product and Engineering teams around features, functionality, and ideas. In these types of scenarios, we work the same way as Vanta’s customers. We submit product feedback, and work with our own Customer Success Manager to identify solutions to more effectively use our own product and maximize the value we get from Vanta.

Risk Management

Within Risk Management, we collaborate closely with the Security team. We maintain a robust and thorough risk register that’s shared with our company leadership regularly and incorporated as part of our quarterly and annual planning process. With our backgrounds in privacy, security engineering, cyber threat intelligence, and various other security and privacy domains, we’re able to partner closely with the Security team to identify and address our risks via a comprehensive risk management approach.

Product Support and Development

We’re fortunate to have experience on both sides of the table as assessors and implementers for multiple standards and in multiple environments, which gives us the opportunity to provide unique input and insight on deliverables for Vanta’s Product teams. In collaboration with Product leadership, we triage requested standards and features, help identify the best places for Vanta to improve support for our customers and partners, and deliver foundational elements for these initiatives to support the company’s mission of securing the internet—while making it as easy and simple as possible to achieve and demonstrate trust.  

This can take many forms, from referencing source documentation for security and privacy standards and frameworks to partnering closely with our Product team to address valuable feedback from our customers. We also tackle work that may never see the light of day, but nonetheless serves as inputs in our ongoing efforts to continuously improve Vanta’s product.

Rather than maintain the status quo of compliance, we like to reimagine how our world works, and seek out new ways to empower Vanta’s customers and partners alike.

GTM Enablement & Support

Working closely with our Marketing and Enablement teams, we provide training and pre- and post launch support on Vanta’s products. Our goal is to support our Customer Success Managers and Account Executives to provide solutions for customers and partners, whether in direct conversations with Vanta’s customers or in the background by supporting our customer-facing teams.

Where can prospects and customers learn more about Vanta’s privacy, risk, and compliance program?

You can read more about our privacy, risk, and compliance program on Vanta’s website. We also have resources for prospects and customers on our Trust Report and in the Vanta Blog and the Vanta Learning and Communities accessible from the Resources section of our website. 

What excites you the most about Vanta’s product and mission?

From our team’s perspective, the easy problems in this space have been solved—and as experienced practitioners, we’ve had the opportunity to see what works and what doesn’t. It’s important to execute well on the fundamentals, like patching systems, providing employee training and support, aligning with business stakeholders, and more. But we’ve also seen and experienced the reality that even though the fundamentals are fundamental for a reason, executing on them can be challenging to navigate in the real world.

What excites us about Vanta is that we have an opportunity to tackle the underlying issues that make these tasks and processes hard in practice—or at least highly manual. Vanta exists to help bridge these gaps, and make those handoffs smoother and more manageable for teams with other work as well.

Any fun facts about the Vanta Privacy, Risk, & Compliance team?

  • Our team consists of individuals who have built deep careers as security, privacy & compliance practitioners—and love the space they’ve built their expertise within!
  • All members of the team enjoy tiny homes, but agree they wouldn’t want to live in one full time. 

Join Vanta’s mission to secure the internet and protect consumer data—learn about our open roles!

Access Review Stage Content / Functionality
Across all stages
  • Easily create and save a new access review at a point in time
  • View detailed audit evidence of historical access reviews
Setup access review procedures
  • Define a global access review procedure that stakeholders can follow, ensuring consistency and mitigation of human error in reviews
  • Set your access review frequency (monthly, quarterly, etc.) and working period/deadlines
Consolidate account access data from systems
  • Integrate systems using dozens of pre-built integrations, or “connectors”. System account and HRIS data is pulled into Vanta.
  • Upcoming integrations include Zoom and Intercom (account access), and Personio (HRIS)
  • Upload access files from non-integrated systems
  • View and select systems in-scope for the review
Review, approve, and deny user access
  • Select the appropriate systems reviewer and due date
  • Get automatic notifications and reminders to systems reviewer of deadlines
  • Automatic flagging of “risky” employee accounts that have been terminated or switched departments
  • Intuitive interface to see all accounts with access, account accept/deny buttons, and notes section
  • Track progress of individual systems access reviews and see accounts that need to be removed or have access modified
  • Bulk sort, filter, and alter accounts based on account roles and employee title
Assign remediation tasks to system owners
  • Built-in remediation workflow for reviewers to request access changes and for admin to view and manage requests
  • Optional task tracker integration to create tickets for any access changes and provide visibility to the status of tickets and remediation
Verify changes to access
  • Focused view of accounts flagged for access changes for easy tracking and management
  • Automated evidence of remediation completion displayed for integrated systems
  • Manual evidence of remediation can be uploaded for non-integrated systems
Report and re-evaluate results
  • Auditor can log into Vanta to see history of all completed access reviews
  • Internals can see status of reviews in progress and also historical review detail
FEATURED VANTA RESOURCE

The ultimate guide to scaling your compliance program

Learn how to scale, manage, and optimize alongside your business goals.