GRC Manager

DaParrot Ltd

Northern (KY)

Hybrid

USD 139,000 - 168,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Mattermost seeks a senior GRC Manager to own and modernize governance, risk, and compliance across federal and commercial markets. You’ll drive automation, AI-enabled workflows, and continuous controls monitoring while coordinating audits and client security artifacts.

You will lead certification readiness (CMMC/NIST/ISO/SOC 2), manage risk and vendor programs, and scale the GRC team in a remote-first environment with strong cross-functional collaboration.

Qualifications

  • Bachelor’s degree in computer science, information security, or related field, or significant GRC experience.
  • Senior-level experience in governance, risk, and compliance with ownership of certification programs.
  • Experience with federal standards including CMMC and NIST (800-171/800-53).
  • Experience with ISO 27001 and SOC 2 Type II.
  • Formal risk management and third-party risk management program experience.
  • Customer security assurance including security questionnaires and trust center content.

Responsibilities

  • Own and modernize Mattermost’s compliance programs across federal and commercial markets.
  • Lead readiness, certification, and surveillance cycles.
  • Operate end-to-end risk management from identification to treatment.
  • Own third-party/vendor risk program including assessments.
  • Apply GRC engineering and automation to replace manual evidence collection.
  • Build AI-native workflows to accelerate recurring compliance work.
  • Maintain control library, SSPs, POA&M, and policies.
  • Coordinate external audits from scoping to remediation.
  • Accelerate deal cycles via customer security questionnaires and trust content.
  • Grow and lead the GRC team as the program scales.

Skills

GRC
CMMC
NIST 800-171/53
ISO 27001
SOC 2 Type II
Vendor Risk
Compliance Automation
Audit Management
Security Assurance

Tools

Vanta
Drata
AI platforms

Job description

# GRC ManagerReview the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.Apply for this job View companyRole snapshotHiring nowRemote from: USASalary: USD 139,254–168,318 / yrDepartment: Legal & ComplianceEmployment: Full TimeExperience: Senior**16 Sep 2026**Published**55**Listing views**5**Application actions**16 Oct 2026**Apply beforeOpportunity details## About this role.AI SummaryMattermost is seeking a senior GRC Manager to own and modernize its governance, risk, and compliance program across federal and commercial markets. The role leads certification readiness, audits, risk management, vendor risk, customer security assurance, and compliance documentation for standards including CMMC, NIST, ISO 27001, and SOC 2 Type II. A major objective is replacing manual evidence gathering with continuous controls monitoring, GRC automation, and AI-enabled workflows. This is a hands-on, high-autonomy program ownership position that is expected to scale into leadership of a GRC team. U.S. citizenship, U.S. location, and eligibility for a government security clearance are required.## Role DNAA quick view of the complexity, pace, ownership and collaboration implied by the job description.### Job Complexity5/5EasyHard### Pace & Pressure5/5RelaxedFast-paced### Autonomy Level5/5GuidedFull ownership### Communication Load5/5IndependentCollaborative**AI insight**This role carries end-to-end accountability for high-stakes federal and commercial compliance programs, including CMMC readiness, audit execution, and customer assurance. It requires deep regulatory expertise, technical cloud-control knowledge, and the ability to drive cross-functional remediation while building scalable automation.## Salary analysisEstimated compensation compared with the broader US market for similar roles.Estimated job medianMarket rate**$153,786**US market range**$135k–$180k**0$198k**AI insight**The disclosed target yearly salary range is USD 139,254 to USD 168,318, with a midpoint of USD 153,786. This is competitive for a senior U.S.-based GRC Manager responsible for federal compliance, CMMC/NIST programs, SOC 2 and ISO 27001, and compliance automation; an estimated broader U.S. market range is USD 135,000 to USD 180,000 annually, depending on location, clearance requirements, certifications, and management scope.## Core skillsSkills and capabilities most closely associated with this opportunity.Governance, Risk & ComplianceCMMCNIST 800-171NIST 800-53ISO 27001SOC 2 Type IIFederal ComplianceRisk ManagementThird-Party Risk ManagementCompliance Automation**Sample interview questions**Mattermost is the leading collaborative workflow platform for defense, intelligence, security, and critical infrastructure. Trusted by the U.S. Department of War and Fortune 500s, our platform runs on-premises and in private clouds, delivering secure messaging, file sharing, workflow automation, audio/screenshare, and project management—all with full data and operational control. Mattermost powers high-stakes workflows across mission planning, real-time, real-world operations, DevSecOps, incident response, and cyber defense—enabling secure collaboration from tactical edge and DDIL environments to enterprise HQ. Teams operate across web, desktop, and mobile, with embedded interoperability for Microsoft Teams, Outlook, and Microsoft 365.To learn more, visit www.mattermost.comMattermost is hiring a **GRC Manager** to own and modernize our governance, risk, and compliance program across both federal and commercial markets.This is a program-ownership role for someone who brings a modern, engineering-led approach to compliance — harnessing GRC engineering and AI to reduce manual effort and scale our programs. You will own Mattermost’s compliance posture end to end, accountable for our federal readiness and commercial certifications, and you will modernize how we run them: automated, continuously monitored, and AI-native.You will do the hands-on compliance work while coordinating across internal stakeholders in engineering, infrastructure, and IT who implement controls, the external auditors who assess them, and the customers whose trust rests on the outcome. As the program scales, you will grow and lead the team behind it.**What You’ll Do*** Own and modernize Mattermost’s compliance programs across federal and commercial markets* Lead readiness, certification, and surveillance cycles across both programs* Operate the risk management program end to end — from identification and assessment through treatment and acceptance* Own the third-party and vendor risk management program, including security assessments and supply chain risk* Apply GRC engineering and automation to replace manual evidence collection with continuous controls monitoring* Build AI-native workflows to accelerate and improve the quality of recurring compliance work* Maintain the control library, system security plans, POA&Ms, and policies* Coordinate external audits from scoping through remediation* Accelerate deal cycles by owning customer security questionnaires, trust center content, and reusable compliance artifacts* Grow and lead the GRC team as the program scales**What We’re Looking For*** Bachelor’s degree in computer science, information security, or related field — or significant professional GRC and compliance experience* Proven senior-level experience in governance, risk, and compliance, security compliance, or IT audit, including direct ownership of a certification or authorization program* Experience with U.S. Federal standards including CMMC and NIST series (800-171 / 800-53)* Experience with ISO 27001 and SOC 2 Type II* Experience operating a formal risk management program* Experience running a third-party and vendor risk management program* Experience owning customer-facing security assurance, including security questionnaires and trust center content* Working knowledge of security controls for cloud environments (AWS, GCP, and/or Azure)* Excellent written and verbal communication skills**Nice to Have*** Professional GRC certifications such as CISA, CRISC, CISM, CISSP, or CIPP* Experience working with AI platforms such as Claude, OpenAI, or Gemini* Experience with compliance automation tooling such as Vanta or Drata, and continuous controls monitoring* Direct experience applying AI or LLM-based workflows to GRC tasks* Proficiency in no-code automation or scripting languages* Past success in critical infrastructure industries including defense, cybersecurity, communications, or manufacturing**How Success Is Measured*** CMMC Level 2 gap assessment and readiness roadmap delivered within first 90 days* SOC 2 Type II and ISO 27001 audit cycles completed on time without slippage* Manual evidence collection replaced with automated, continuously monitored controls* Customer security questionnaires and trust center content maintained to unblock deal cycles* GRC team grown and operating as a scalable, program-driven function**Why Mattermost*** Mission-driven work: Your contributions directly support the organizations and missions that depend on secure, reliable collaboration* Remote-first culture: Work from anywhere with a globally distributed, high-trust team built for autonomy and ownership* Open source at the core: Be part of a vibrant developer community shaping the future of secure collaboration* AI-forward environment: We actively adopt and build AI-enabled workflows — you’ll work with and on cutting-edge tooling* Unique scope: Own the compliance program end to end across both federal and commercial markets at a high-growth Series B company**Compensation**Mattermost takes a market-based approach to pay. Actual compensation may vary based on location, skills, experience, qualifications, and market conditions.**Target Salary Range: $139,254-$168,318****U.S. Eligibility & Compliance**This role requires U.S. citizenship. Candidates must be located in the United States and eligible to obtain and maintain a U.S. government security clearance. For more information visit Security Clearances — United States Department of StateApplicants must meet eligibility requirements for access to export-controlled information as defined by U.S. export control laws, including EAR and ITAR. For more information visit the Bureau of Industry and Security and the Directorate of Defense Trade Controls.Mattermost is an EEO Employer, we are a remote-first, open-source company.We are continually working to expand our hiring in more countries and regions, ensuring compliance with local laws and regulations, which takes time.Mattermost values your unique perspective—we welcome all applicants. We encourage individuals from all backgrounds to apply and are committed to assessing candidates based on their skills and qualifications. We do not tolerate discrimination against staff or applicants based on race, religion, national origin, age, disability, pregnancy status, veteran status, or other personal characteristics.If you require accommodations during the interview process, please let us know—we’re happy to assist.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Manager
GRC Manager

Coinscapture • Northern (KY)

Hybrid
USD 139,000 - 168,000
Remote-first culture
Open source at the core
AI-forward environment
+1
Account Manager - Federal
Account Manager - Federal

DaParrot Ltd • Northern (KY)

Hybrid
USD 100,000 - 130,000
Remote-first
Commission eligible
Senior Account Executive - Federal (Intelligence Community Focus)
Senior Account Executive - Federal (Intelligence Community Focus)

Mattermost • Washington, Baltimore (MD)

Remote
USD 125,000 - 150,000
Senior Technical Account Manager (Federal)
Senior Technical Account Manager (Federal)

your Jared • Northern (KY)

Hybrid
USD 125,000 - 165,000
Staff Full Stack Engineer at Mattermost
Staff Full Stack Engineer at Mattermost

Matcha • Northern (KY)

Hybrid
USD 173,000 - 227,000
Lead Site Reliability Engineer New
Lead Site Reliability Engineer New

Mattermost, Inc. • Northern (KY)

Hybrid
USD 145,000 - 200,000
Senior Manager, AI Engineering
Senior Manager, AI Engineering

DaParrot Ltd • Northern (KY)

Hybrid
USD 240,000 - 280,000
Health insurance
Equity stock options
Unlimited PTO
Staff Full Stack Engineer
Staff Full Stack Engineer

Mattermost • United States

On-site
USD 173,000 - 227,000
GRC Program Manager, US Government Compliance
GRC Program Manager, US Government Compliance

OpenAI • Washington

Hybrid
USD 150,000 - 190,000
Relocation assistance
Hybrid work model (3 days in office)
GRC Engineer
GRC Engineer

RiverPark Ventures • New York (NY)

On-site
USD 130,000 - 170,000
Medical, Dental and Vision plans
401(k) plan with match
Paid holidays
+7