400 karma · joined October 29, 2010
Thanks for the feedback. What we should probably do is take the credential, start scanning, and then nag them with a failing test about overly-permissive roles. Our own role is an easy check because we know what to expect, but there's other best practices here we can check for (and in some cases do, though not 100% comprehensively across all clouds.)
The Trust Reports contain programmatically-validated information (basically: Vanta's code says the control was in place continuously.)
There's (obviously) pros and cons of trusting a software provider (like Vanta) to validate technical configuration compared to trusting a human auditor to do the same.
Our bet with Trust Reports is that for some cases, having software do the checking and validation continuously is better than having a human auditor do it once a year.
We work with companies doing B2B sales and looking for help with compliance certifications like ISO 27001 and SOC 2. Some folks come to us early but most come with a deal on the line — which is to say, this is a process you can start “just in time” if you must.
From what I’ve seen, saying “no I won’t go through your security review process” is an (obvious) dealbreaker, but there’s a lot of ways to get through that process: ISO cert, SOC 2, the promise to get either of those certs by your go-live/implementation date, security questionnaire hell, etc.
As mentioned previously, ISO is preferred by European companies; SOC 2 is more likely to be mandated by American companies, and you’re likely to get pretty far, even in Europe, on just a SOC 2. If I had to construct the situation that’s most likely to be deal-breaking, it’d be an old-school European company that’s operating off a rigid flow chart: “if no ISO 27001 cert, go back to start. Do not pass Go. Do not collect $200.”
A few folks have mentioned cost (dollar and organizational) — ymmv and/but the cost of obtaining ISO 27001 certification varies with the number of employees, say $10-20k for smaller companies. Implementing ISO 27001 and an ISMS can be blitzed by small teams in a few weeks but probably will take a couple of months to a year for larger organizations.
(And we’d love to help if you decide to pursue this at Vanta etc etc)
Very much agree with you about SOC 2 == obvious best practices if done reasonably!
That’s one of the “secrets” of SOC 2: if you speak some compliance, you can make most of the SOC 2 work for you, implementing best practices, getting the rest of the org to prioritize them, etc. (This is what we like about SOC 2 at Vanta: it can turn meaningful, difficult-to-measure security work into high-pri sales collateral.)
If you don’t speak compliance and have a SOC 2 consultant who doesn’t speak engineering, you’re more likely to end up with absurd arguments and bookkeeping (“but you have to use a WAF there’s just no other way!” etc.)
Vanta is security-in-a-box for technology companies, covering everything from laptops to infrastructure, and using a suite of simple, effective, and easy-to-deploy tools. We're in closed beta, have a backlog of customers to engage, and since we began onboarding users, we've had no customer churn. Help us secure the internet, increase trust in software companies, and keep consumer data safe.
To learn more about who we are, our engineering culture, and whether this is the right place for you, read our Key Values profile: https://www.keyvalues.com/vanta
Here are our open roles:
- Generalist Software Engineer: https://vanta.com/jobs?ref=keyvalues
- Technical Project Manager: https://vanta.com/jobs?ref=keyvalues
- Customer Success Manager: https://vanta.com/jobs?ref=keyvalues
- Operations Manager: https://vanta.com/jobs?ref=keyvalues
Tech Stack: Node.js, TypeScript, React, GraphQL, Docker, Terraform, Go, AWS
Hi! Christina, a Vanta founder here.
Vanta is security-in-a-box for technology companies, covering everything from laptops to infrastructure, and using a suite of simple, effective, and easy-to-deploy tools. We're in closed beta, onboard new teams every week, and work with software companies you'd recognize.
Help us secure the internet, increase trust in software companies, and keep consumer data safe.
To learn more about who we are, our engineering culture, and whether this is the right place for you, read our Key Values profile: https://www.keyvalues.com/vanta
Here are our open roles:
- Generalist Software Engineer: https://vanta.com/jobs?ref=keyvalues
- Product Support Engineer (remote okay): https://vanta.com/jobs/support
- Strategic Account Executive (first sales person!): https://vanta.com/jobs/sales
You can apply by emailing us! founders@vanta.com
Tech Stack: Node.js, TypeScript, React, GraphQL, Docker, Terraform, Go, AWS
Hi! Christina, a Vanta founder here.
Vanta is security-in-a-box for technology companies, covering everything from laptops to infrastructure, and using a suite of simple, effective, and easy-to-deploy tools. We're in closed beta, onboard a new team every week, and work with software companies you'd recognize.
Help us secure the internet, increase trust in software companies, and keep consumer data safe.
To learn more about who we are, our engineering culture, and whether this is the right place for you, read our Key Values profile: https://www.keyvalues.com/vanta
Here are our open roles:
- Generalist Software Engineer: https://vanta.com/jobs?ref=keyvalues - Product Support Engineer (remote okay): https://vanta.com/jobs/support - Strategic Account Executive (first sales person!): https://vanta.com/jobs/sales
You can apply by emailing us! founders@vanta.com
Tech Stack: Node.js, TypeScript, React, GraphQL, Docker, Terraform, Go, AWS
Hi! Vanta founder here.
Vanta is security-in-a-box for technology companies, covering everything from laptops to infrastructure, and using a suite of simple, effective, and easy-to-deploy tools. We're in closed beta, onboard a new team every week, and work with software companies you'd recognize.
Help us secure the internet, increase trust in software companies, and keep consumer data safe!
To learn more about who we are, our engineering culture, and whether this is the right place for you, read our Key Values profile: https://www.keyvalues.com/vanta
Here are our open roles:
- Generalist Software Engineer (onsite only): https://vanta.com/jobs?ref=keyvalues
- Support Engineer (remote okay): https://vanta.com/jobs/support
You can apply by emailing us! founders@vanta.com
Tech Stack: Node.js, TypeScript, React, GraphQL, Docker, Terraform, Go, AWS
============= Intro =============
Hi! Vanta founder here.At Vanta, our goal is to secure the internet, increase trust in software companies, and grow internet businesses.
Here's more about our company:
https://vanta.com/jobs https://www.keyvalues.com/vanta
We're in private beta, growing quickly, and working with software companies you'd recognize.
Our office is in downtown San Francisco, in the Mechanics Institute – a lovely old building outside the Montgomery BART stop.
============= Engineering =============
We're looking for full-stack / generalist software engineers. Our stack is Typescript, Go (Golang), GraphQL, React, etc.; we also use and contribute to open source projects like Osquery. ============= User Support =============
We're looking for a technical support person to work closely with our users and the rest of the team, learning the intricacies of how we build products, secure internet businesses, and keep users happy.If you're a strong writer and interested in technical systems, we'd love to hear from you!
============= Apply =============
Email us at "founders@vanta.com"Vanta is security-in-a-box for technology companies, covering everything from laptops to infrastructure, and using a suite of simple, effective, and easy-to-deploy tools.
We're in closed beta, we're growing revenues, and we've yet to have any customer churn.
We were part of YC’s W18 batch.
## Generalist software engineers
We're looking for experienced software engineers who can take ownership and drive development of large product areas. Joining Vanta means seeing everything, helping to build the team, and shaping Vanta's culture from the earliest stages.
## Why join Vanta?
If you’re interested in starting a startup eventually, you'll get to see a startup get built from the ground up at Vanta.
## Our stack
Typescript (node and React), Docker, Terraform, Go (Golang). We also use (and admire) lots of open-source security tooling like Osquery and BeyondCorp.
## More info
More about us at https://vanta.com/jobs
## Applying
Email us! founders@vanta.com
Vanta is security-in-a-box for technology companies, covering everything from laptops to infrastructure, and using a suite of simple, effective, and easy-to-deploy tools.
We're in closed beta, we've a backlog of customers to engage, and since we began onboarding users, we've had no customer churn.
We were part of YC’s W18 batch.
## Generalist software engineers
We're looking for experienced software engineers who can take ownership and drive development of large product areas. Joining Vanta means seeing everything, helping to build the team, and shaping Vanta's culture from the earliest stages.
## Why join Vanta?
If you’re interested in starting a startup eventually, you'll get to see a startup get built from the ground up at Vanta.
## Our stack
Go, Typescript (node and React), Docker, Terraform. We also use (and admire) lots of open-source security tooling like Osquery and BeyondCorp.
## More info
More about us at https://vanta.com/jobs
## Applying
Email founders@vanta.com
Help us secure the internet, increase trust in software companies, and keep consumer data safe.
Vanta is security-in-a-box for technology companies, covering everything from laptops to infrastructure, and using a suite of simple, effective, and easy-to-deploy tools.
i see the AP test as a bit of a hack; while it'd be nice to teach everyone all of the codes, i found teaching high schoolers AP CS a more manageable place to start.
the software demoed in the video is still fragile, so it's not fully public yet. let me know if you're interested in poking at it though (c@christinacacioppo.com)
i suspect you're right about needing to hand-write code -- especially if you're used to things like code snippets and autocomplete. i suppose i feel about hand-writing code the way i feel about understanding compilerish: you'll probably have to do it at some point, and it's a skill worth practicing, but i don't think it should come first.
their prior programming experience varied, though there's certainly bias in who would sign up for coding tutoring (free or paid.)
all were comfortable using computers, and they'd seen code before. about half had gone through a Girls Who Code summer program (http://girlswhocode.com/programs/), which is designed, i think, to overview technologies more than drill concepts. they all had computers had home (about 50-50 windows/mac) with new-ish chrome or safari.
i only had one student take the multiple choice questions; he would have gotten a 3 or 4 on that part. he's coming off SAT prep and is good at taking standardized tests; he was weakest on the test's particulars ("how many bytes in an int?") i spent very little time on those sorts of questions; my view is that a motivated student who can understands how computers think will learn those particulars if s/he wants a 5. and for those who don't, there's google and stackoverflow.
i asked students to answer old free-response questions in the editor that's shown in the fizzbuzz video. that worked really well; with the help of the compiler, they were able to ace those questions. (i know you don't get a compiler on test day, but it seems silly to cripple them when learning.)
sometimes i tutored in person; other times, i did so over google hangout. either way, i was working one-on-one with a student, and it was painfully clear when s/he was confused, whether it was over a CS concept or a tool i'd introduced. tutoring also meant it was my responsibility to "fix it", and i think that explains a lot of why i cut 160 classroom hours to 20 tutoring hours.
it's all pretty simple: they're quicktime screencasts, converted to mp4s, and played with videojs. i just took off the player's chrome and rigged it to start/stop onmouseover/onmouseout.