Mattermost logo
Mattermost·Verified

GRC Manager - Mattermost

Remote-firstFull-timeSenior$139K - $168KUTC-8–-4US#grc#compliance#nist

About the Role

Mattermost is seeking a GRC Manager to own and modernize our governance, risk, and compliance program across federal and commercial markets. This is a program-ownership role for someone who brings a modern, engineering-led approach to compliance—harnessing GRC engineering and AI to reduce manual effort and scale our programs.

You will own Mattermost's compliance posture end-to-end, accountable for federal readiness and commercial certifications, while coordinating across engineering, infrastructure, and IT stakeholders.

What You'll Do

  • Program Ownership: Lead readiness, certification, and surveillance cycles across federal and commercial markets.
  • Risk Management: Operate the risk management program from identification and assessment through treatment and acceptance.
  • Vendor Risk: Own third-party and vendor risk management, including security assessments and supply chain risk.
  • Automation: Apply GRC engineering to replace manual evidence collection with continuous controls monitoring and build AI-native workflows.
  • Documentation: Maintain the control library, system security plans, POA&Ms, and policies.
  • Audit Coordination: Manage external audits from scoping through remediation.
  • Sales Enablement: Accelerate deal cycles by owning customer security questionnaires, trust center content, and reusable compliance artifacts.
  • Leadership: Grow and lead the GRC team as the program scales.

What We're Looking For

  • Bachelor's degree in CS, Information Security, or equivalent experience.
  • Proven senior-level experience in GRC, security compliance, or IT audit.
  • Deep experience with U.S. Federal standards (CMMC, NIST 800-171/800-53).
  • Experience with ISO 27001 and SOC 2 Type II.
  • Experience operating formal risk management and third-party risk programs.
  • Working knowledge of cloud security controls (AWS, GCP, or Azure).
  • Excellent written and verbal communication skills.

Nice to Have

  • Professional certifications: CISA, CRISC, CISM, CISSP, or CIPP.
  • Experience with AI platforms (Claude, OpenAI, Gemini) and LLM-based GRC workflows.
  • Proficiency in compliance automation tools (Vanta, Drata) or no-code/scripting languages.
  • Background in critical infrastructure industries (defense, cybersecurity, manufacturing).

Why Mattermost

  • Mission-Driven: Support organizations that depend on secure, reliable collaboration.
  • Remote-First: Work from anywhere with a globally distributed, high-trust team.
  • AI-Forward: Work with and build cutting-edge AI-enabled workflows.
  • Unique Scope: Own the compliance program end-to-end at a high-growth Series B company.

Eligibility Requirements

  • This role requires U.S. citizenship.
  • Candidates must be located in the United States.
  • Must be eligible to obtain and maintain a U.S. government security clearance.
  • Must meet eligibility requirements for access to export-controlled information (EAR/ITAR).

Timezone overlap

UTC-8–-4

Open to

US

Sign in to track applications and earn points.

More roles at Mattermost

Similar remote roles