Job Openings Vanta GRC Consulting Services — SOC 2 & ISO 27001

About the job Vanta GRC Consulting Services — SOC 2 & ISO 27001

Request for qualifications from independent compliance consulting businesses.

About goCloudOffice®

goCloudOffice® is a modern, AI-driven IT consulting company. Founded in 2003 and based in Silicon Valley, we serve customers nationwide across the United States. Our customers are small businesses of 5 to 50 people, in industries that include biotechnology, law and professional services. They own their business applications, and we run their IT with senior engineering judgment and AI-augmented support that has been in daily production since summer 2024.

The engagement

Engagement: governance, risk and compliance (GRC) services on the Vanta platform for two goCloudOffice® customers, in two tracks:

  • Track 1: Vanta program set-up. A life-sciences company in the San Francisco Bay Area: Vanta program set-up toward ISO/IEC 27001 and ISO/IEC 27701, with IT general controls.
  • Track 2: Vanta program maintenance. A software-as-a-service company: ongoing Vanta maintenance for SOC 2 Type 2 and US state privacy obligations.

This is a business-to-business engagement under one master services agreement between goCloudOffice® and your business, with a statement of work for each customer; your business invoices for the services it delivers. Each customer accepts your business in writing as a disclosed subcontractor. Where a customer's supplier terms call for a direct contract, that customer contracts with your business directly and goCloudOffice® coordinates the program.

Engagement contact: the goCloudOffice® account lead. The provider directs its own work and personnel.

Scope of services

  • Vanta tenant configuration and framework mapping. Framework activation and scoping, control mapping across frameworks, custom controls, and a clean in-scope inventory of people, devices, vendors and systems.
  • Integrations and automated tests. Connecting and maintaining integrations, triaging failing tests to their root cause, and recording justified exceptions with an owner and an expiry date.
  • Policies. Drafting information-security and privacy policies and procedures that fit each customer and satisfy each framework, for approval by a customer officer, with acceptance tracked in Vanta.
  • Control ownership and evidence. A named customer owner and cadence for every control, and evidence collected inside each customer's tenant, complete, dated and ready for sampling.
  • Risk register and vendor management. Risk assessment and treatment, and security reviews of each customer's vendors.
  • Access reviews. Periodic user access reviews, run with each system owner and recorded as evidence.
  • Audit readiness and auditor liaison. Readiness assessments, auditor requests and walkthroughs, and management's SOC 2 system description and assertion, prepared for the customer's officers to sign, in coordination with each customer's independent audit firm or certification body.
  • ISO/IEC 27001 and ISO/IEC 27701 build. Scope, the Statement of Applicability, risk assessment and treatment, ISMS and PIMS documentation, control implementation support, management-review inputs, and Stage 1 and Stage 2 readiness.
  • IT general controls. Design and remediation of access, change-management, IT operations and system-development controls over financially relevant systems, ready for testing by the customer's Sarbanes-Oxley function and for its external auditor's review (Sarbanes-Oxley readiness).
  • SOC 2 Type 2 observation-period hygiene. Controls operated on cadence, and evidence captured as it happens, throughout each observation period.
  • US Data Privacy framework mapping. The obligations of the CCPA/CPRA and other US state privacy laws, mapped to controls and evidence through Vanta's US Data Privacy framework.
  • Monthly compliance reporting. A concise monthly report to each customer and to goCloudOffice®: posture, open items, owners and upcoming audit dates.
  • AI-assisted delivery. AI tools used as a daily part of the work, with every output verified before it reaches a customer's compliance program.

Audit independence. The provider builds each program and prepares each customer for its auditors, and the assurance work stays in independent hands:

  • the ISO/IEC 27001 and ISO/IEC 27701 internal audit of any scope the provider built is performed by an independent, qualified auditor who took no part in the build;
  • the customer's independent CPA firm is the SOC 2 service auditor;
  • testing of the IT general controls the provider designs rests with the customer's Sarbanes-Oxley testing function and, where it relies on them, its external auditor;
  • Vanta's auditor access belongs to each customer's audit firm;
  • each customer keeps at least two of its own Vanta administrators, and a customer officer owns and approves every policy.

Identity and records. The provider works under its own firm name throughout and completes the customer's personnel onboarding controls. Each customer issues the provider's personnel a named Vanta user on the provider's own domain, with the least access the work requires and multi-factor authentication, recorded as an external vendor user. Auditors and certification bodies meet the provider as "[Firm], the GRC consultancy engaged through goCloudOffice®". Policies name a customer officer as owner and approver, and the provider as drafter under its firm name. Evidence stays inside each customer's tenant, and every record created for a customer is that customer's record.

Services must meet each customer's security, access and confidentiality policies and the service levels in the statement of work. Customer data and evidence, including any AI processing, are handled in the United States, in tools each customer approves.

Before any access to the customer's systems or information, the provider and each person it assigns sign the customer's confidentiality agreement and acknowledge the customer's insider-trading policy; the customer may designate them as covered persons subject to its trading blackout and pre-clearance rules, and these obligations continue after the engagement ends.

The provider uses its own equipment and business identity; goCloudOffice® grants only the proprietary system access the services require.

The provider coordinates with the goCloudOffice® account lead on timing and hand-offs, and with goCloudOffice®'s IT services on evidence and remediation for the systems goCloudOffice® operates for each customer.

Attestation and certification decisions rest with each customer's independent audit firm and accredited certification body, and legal interpretation rests with each customer's counsel.

What your business brings (required qualifications)

1. An independently established compliance consulting business. Your business:

  • operates under its own business name, including in customer systems and in correspondence with auditors;
  • regularly contracts with other businesses and advertises its services to the public;
  • holds the business licenses and registrations its work requires;
  • carries professional liability (technology errors-and-omissions) insurance of USD 1M per claim and USD 2M aggregate, cyber insurance of USD 1M, general liability insurance of USD 1M where a statement of work includes on-site sessions, and workers' compensation where the business has W-2 personnel;
  • provides its own equipment;
  • is independent of the audit firm and the certification body of each customer it serves;
  • keeps implementation and internal audit in separate hands for every client.

Preferred structure: A corporation, or an LLC taxed as an S-corporation, whose own W-2 personnel perform the services is preferred. Sole proprietorships and single-member LLCs are also considered.

2. Typically seven or more years of hands-on governance, risk and compliance (GRC) experience, building and operating security and privacy compliance programs through independent audits.

3. Deep, hands-on Vanta expertise across the whole platform: framework set-up and scoping, control mapping and custom controls, integrations and automated tests, policies and documents, personnel and access reviews, vendor risk management and the risk register, and the audit workspace shared with auditors.

4. ISO/IEC 27001:2022 and ISO/IEC 27701 implementation: ISMS and PIMS scoping, risk assessment and treatment, the Statement of Applicability, documentation, control implementation, preparation for an impartial internal audit and management review, and readiness for Stage 1 and Stage 2 certification audits.

5. SOC 2 Type 2 program operation: mapping controls to the Trust Services Criteria, operating controls and capturing evidence across the observation period, preparing populations and samples, answering auditor requests, and preparing management's system description (including subservice organizations and complementary controls) and assertion for the customer's officers.

6. IT general controls (ITGC): designing and remediating access, change-management, IT operations and system-development controls over financially relevant systems, including complementary user-entity controls under service organizations' SOC 1 reports and controls over information produced by the entity, with control attributes and evidence documented to the standard the customer's testers and external auditor rely on.

7. US privacy compliance mapping: translating the CCPA/CPRA and other US state privacy laws into controls and evidence (privacy notices, consumer-rights requests, opt-out of sale or sharing, data inventory, retention and service-provider terms), through Vanta's US Data Privacy framework or an equivalent control set.

8. Policy authoring: clear, right-sized information-security and privacy policies and procedures that match how each customer actually operates and satisfy each framework's requirements.

9. AI-assisted GRC work. Providers should demonstrate at least one year of AI-assisted service delivery in their practice (for example, AI-assisted policy drafting, evidence triage or control mapping). We look for:

  • Tools: any mainstream assistant, such as ChatGPT, Claude, Gemini or Microsoft 365 Copilot, and the AI features built into GRC platforms.
  • A clear method for checking AI output: verifying every control reference against the text of the standard or framework, checking every policy statement against how the customer actually operates, keeping evidence authentic and drawn from the source system, and keeping customer data inside the AI tools each customer approves, processed in the United States.

10. Clear communication with customer leadership, control owners and auditors: plain-language guidance that helps control owners succeed, concise written reports, and well-evidenced answers to auditor requests.

Where a qualification names years, equivalent depth gained in fewer years counts; tell us how.

Also valuable (preferred qualifications)

  • A. Relevant certifications held by the personnel who would perform the services, such as ISO/IEC 27001 Lead Implementer or Lead Auditor, ISO/IEC 27701 Lead Implementer, CISA, CISSP, CIPP/US, or Vanta's own product certifications.
  • B. Experience supporting biotechnology or life-sciences companies, where confidentiality, documented change and SOX-aligned controls matter.
  • C. Experience maintaining SOC 2 and privacy programs for software-as-a-service platforms that hold large volumes of consumer personal information.
  • D. Experience as the day-to-day counterpart to the auditors through an ISO/IEC 27001 certification audit and a SOC 2 Type 2 examination.
  • E. Working knowledge of the Vanta API, or of other GRC platforms such as Drata or Secureframe, including migration between platforms.
  • F. More than one qualified person in your business who can perform the services, for coverage continuity.
  • G. Availability for occasional on-site working sessions at customer sites in the San Francisco Bay Area, within availability windows set in the statement of work.

Rate, scope and term

  • Budgeted rate: USD 140 per hour. Providers propose their own rates and commercial terms, and fixed-price proposals per milestone are welcome.
  • Track 1 scope: fixed-fee framework milestones, each with acceptance criteria (scope and Statement of Applicability; risk assessment and treatment plan; the policy set drafted for customer approval; the ISO/IEC 27701 PIMS mapping; control implementation support; the Stage 1 readiness pack), with Stage 2 audit support by the hour.
  • Track 2 scope: a fixed monthly block of service hours against a named checklist, with additional hours on prior authorization.
  • Service hours: scheduled by the provider within customer availability windows; scope may expand by statement of work.
  • Delivery: remote, performed from within the United States (customer data and evidence are handled only in the United States), with occasional on-site working sessions at customer sites in the San Francisco Bay Area within availability windows agreed in the statement of work.
  • Term: Track 1 runs to its milestones; Track 2 runs 12 months, renewable, on 30 days' notice.
  • Outcomes: each statement of work warrants professional workmanship to the standard of a competent GRC practitioner; certification decisions and audit opinions rest with the certification body and the CPA firm.

How to respond

Submit your business's qualifications: a capability statement, résumés of the personnel who would perform the services, and answers to the response questions. The questions cover business details, licenses and insurance, who performs the services and the credentials they hold, other clients (count and industries; no names), your Vanta partner status and the number of Vanta tenants your business administers, the audit firms and certification bodies your business has worked with, how your business separates implementation from internal audit, equipment, availability windows, the AI tools your business uses on client evidence and where they process data, United States data handling, your proposed rate and terms, and one example of AI-assisted GRC work. Please send résumés without photographs, dates of birth, government identification numbers or home addresses, and share the notice below with the personnel whose résumés you submit. The qualification process is clear and quick:

1. A review of your response against the posted qualifications.
2. A 25-minute introductory qualification call about how your business runs.
3. A technical qualification call: a set of Vanta scenarios and a practical policy exercise, using the AI assistant of your choice or one we provide. Every scenario uses synthetic material.
4. A conversation about the two customer engagements, under a mutual NDA.
5. Two references from current GRC clients.
6. A final decision by goCloudOffice®'s founder.

Every respondent receives an answer. Reasonable accommodations and other adjustments to any step are available on request; the notice below explains how to reach us.

AI-assistance and privacy notice

This notice covers the businesses that respond to this request for qualifications and the personnel they name. goCloudOffice, Inc. may use AI-assisted tools — Manatal, the platform that hosts our request page, and AI models from Anthropic — to organize and summarize responses against the qualifications posted here and to draft our replies. People, not tools, make every selection decision, and a person reads every response before any decision is made. We keep response records for four years and never sell or share them. You may decline AI assistance, ask for human re-review of any step, or request an accommodation for a qualification call through our contact form at https://www.gocloudoffice.com/contact/; doing so will not affect how we evaluate your response. Our full privacy notice for respondents, including California privacy rights, is at https://www.gocloudoffice.com/legal/respondent-privacy-notice/.

Equal opportunity

goCloudOffice® selects providers on the posted qualifications alone. It welcomes responses from every qualified business, and considers them without regard to the race, color, religion or creed, sex, pregnancy, gender identity or expression, sexual orientation, national origin, ancestry, age, physical or mental disability, medical condition, genetic information, marital status, military or veteran status, or reproductive health decision-making of the business's owners or personnel, or any other characteristic protected by law.