GRC Manager

Mattermost

United States

On-site

USD 120,000 - 190,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Mattermost is hiring a GRC Manager to own and modernize our governance, risk, and compliance program across federal and commercial markets. You will lead the program end to end, ensuring readiness, certifications, and continuous monitoring with an engineering-led, AI-native approach.

In this hands‑on role you will coordinate across security, IT, and engineering teams, manage external audits, and scale the function as the business grows, driving trust and compliance excellence.

Qualifications

  • Bachelor's degree in computer science, information security, or related field.
  • Proven senior-level experience in governance, risk, and compliance with ownership of a certification program.
  • Experience with U.S. Federal standards including CMMC and NIST 800-171/800-53.
  • Experience with ISO 27001 and SOC 2 Type II.
  • Experience operating a formal risk management program.
  • Experience running a third-party and vendor risk management program.
  • Experience owning customer security assurances (security questionnaires, trust center content).
  • Knowledge of security controls for cloud environments (AWS, GCP, Azure).
  • Excellent written and verbal communication skills.

Responsibilities

  • Own and modernize federal and commercial GRC programs.
  • Lead readiness, certification, and surveillance cycles.
  • Run the end-to-end risk management process.
  • Oversee third‑party and vendor risk management.
  • Apply automation and AI to evidence collection.
  • Build AI-native workflows to speed compliance work.
  • Maintain control libraries, SSPs, POA&Ms, and policies.
  • Coordinate external audits from scoping to remediation.
  • Manage customer security questionnaires and trust content.
  • Grow and lead the GRC team as programs scale.

Skills

GRC leadership
Governance
Risk management
Compliance
Security audits
Communication skills

Education

Bachelor's degree in CS/InfoSec or related field

Tools

Vanta
Drata
Claude/OpenAI/Gemini

Job description

Mattermost is the leading collaborative workflow platform for defense, intelligence, security, and critical infrastructure. Trusted by the U.S. Department of War and Fortune 500s, our platform runs on-premises and in private clouds, delivering secure messaging, file sharing, workflow automation, audio/screenshare, and project management—all with full data and operational control. Mattermost powers high-stakes workflows across mission planning, real-time, real-world operations, DevSecOps, incident response, and cyber defense—enabling secure collaboration from tactical edge and DDIL environments to enterprise HQ. Teams operate across web, desktop, and mobile, with embedded interoperability for Microsoft Teams, Outlook, and Microsoft 365.

Mattermost is hiring aGRC Manager to own and modernize our governance, risk, and compliance program across both federal and commercial markets.

This is a program-ownership role for someone who brings a modern, engineering-led approach to compliance — harnessing GRC engineering and AI to reduce manual effort and scale our programs. You will own Mattermost's compliance posture end to end, accountable for our federal readiness and commercial certifications, and you will modernize how we run them: automated, continuously monitored, and AI-native.

You will do the hands‑on compliance work while coordinating across internal stakeholders in engineering, infrastructure, and IT who implement controls, the external auditors who assess them, and the customers whose trust rests on the outcome. As the program scales, you will grow and lead the team behind it.

What You'll Do
  • Own and modernize Mattermost's compliance programs across federal and commercial markets
  • Lead readiness, certification, and surveillance cycles across both programs
  • Operate the risk management program end to end — from identification and assessment through treatment and acceptance
  • Own the third‑party and vendor risk management program, including security assessments and supply chain risk
  • Apply GRC engineering and automation to replace manual evidence collection with continuous controls monitoring
  • Build AI-native workflows to accelerate and improve the quality of recurring compliance work
  • Maintain the control library, system security plans, POA&Ms, and policies
  • Coordinate external audits from scoping through remediation
  • Accelerate deal cycles by owning customer security questionnaires, trust center content, and reusable compliance artifacts
  • Grow and lead the GRC team as the program scales
What We're Looking For
  • Bachelor's degree in computer science, information security, or related field — or significant professional GRC and compliance experience
  • Proven senior‑level experience in governance, risk, and compliance, security compliance, or IT audit, including direct ownership of a certification or authorization program
  • Experience with U.S. Federal standards including CMMC and NIST series (800‑171 / 800‑53)
  • Experience with ISO 27001 and SOC 2 Type II
  • Experience operating a formal risk management program
  • Experience running a third‑party and vendor risk management program
  • Experience owning customer‑facing security assurance, including security questionnaires and trust center content
  • Working knowledge of security controls for cloud environments (AWS, GCP, and/or Azure)
  • Excellent written and verbal communication skills
Nice to Have
  • Professional GRC certifications such as CISA, CRISC, CISM, CISSP, or CIPP
  • Experience working with AI platforms such as Claude, OpenAI, or Gemini
  • Experience with compliance automation tooling such as Vanta or Drata, and continuous controls monitoring
  • Direct experience applying AI or LLM‑based workflows to GRC tasks
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

GRC Manager
GRC Manager

Coinscapture • Northern (KY)

Hybrid
USD 139,000 - 168,000
Remote-first culture
Open source at the core
AI-forward environment
+1
GRC Manager: AI-Driven Federal & Commercial Compliance
GRC Manager: AI-Driven Federal & Commercial Compliance

Mattermost • United States

On-site
USD 120,000 - 190,000
Senior GRC Leader: AI-Driven Compliance & Risk
Senior GRC Leader: AI-Driven Compliance & Risk

DaParrot Ltd • Northern (KY)

Hybrid
USD 139,000 - 168,000
GRC Director: Federal & Commercial AI-Driven Compliance
GRC Director: Federal & Commercial AI-Driven Compliance

Mattermost • United States

On-site
USD 139,000 - 168,000
GRC Manager
GRC Manager

DaParrot Ltd • Northern (KY)

On-site
USD 139,000 - 168,000
GRC Manager
GRC Manager

Glocomms • San Francisco (CA)

On-site
USD 120,000 - 180,000
Full Health Benefits
Equity participation
Relocation Support
+1
Security Engineer, GRC
Security Engineer, GRC

Candid Health • San Francisco (CA)

On-site
USD 140,000 - 200,000
Senior Program Manager, IT Governance and Compliance
Senior Program Manager, IT Governance and Compliance

True Anomaly, Inc. • Denver (CO), Long Beach (CA), Washington

On-site
USD 135,000 - 215,000
Health insurance
Dental insurance
Vision insurance
+5
Global Security Governance, Risk & Compliance Manager (Remote)
Global Security Governance, Risk & Compliance Manager (Remote)

Barnes Aerospace • United States

Remote
USD 140,000 - 190,000
GRC Program Manager (FedRAMP & Compliance)
GRC Program Manager (FedRAMP & Compliance)

Port.io • Boston (MA)

On-site
USD 120,000 - 150,000