
About the Role
Mattermost is seeking a GRC Manager to own and modernize our governance, risk, and compliance program across federal and commercial markets. This is a program-ownership role for someone who brings a modern, engineering-led approach to compliance—harnessing GRC engineering and AI to reduce manual effort and scale our programs.
You will own Mattermost's compliance posture end-to-end, accountable for federal readiness and commercial certifications, while coordinating across engineering, infrastructure, and IT stakeholders.
What You'll Do
- Program Ownership: Lead readiness, certification, and surveillance cycles across federal and commercial markets.
- Risk Management: Operate the risk management program from identification and assessment through treatment and acceptance.
- Vendor Risk: Own third-party and vendor risk management, including security assessments and supply chain risk.
- Automation: Apply GRC engineering to replace manual evidence collection with continuous controls monitoring and build AI-native workflows.
- Documentation: Maintain the control library, system security plans, POA&Ms, and policies.
- Audit Coordination: Manage external audits from scoping through remediation.
- Sales Enablement: Accelerate deal cycles by owning customer security questionnaires, trust center content, and reusable compliance artifacts.
- Leadership: Grow and lead the GRC team as the program scales.
What We're Looking For
- Bachelor's degree in CS, Information Security, or equivalent experience.
- Proven senior-level experience in GRC, security compliance, or IT audit.
- Deep experience with U.S. Federal standards (CMMC, NIST 800-171/800-53).
- Experience with ISO 27001 and SOC 2 Type II.
- Experience operating formal risk management and third-party risk programs.
- Working knowledge of cloud security controls (AWS, GCP, or Azure).
- Excellent written and verbal communication skills.
Nice to Have
- Professional certifications: CISA, CRISC, CISM, CISSP, or CIPP.
- Experience with AI platforms (Claude, OpenAI, Gemini) and LLM-based GRC workflows.
- Proficiency in compliance automation tools (Vanta, Drata) or no-code/scripting languages.
- Background in critical infrastructure industries (defense, cybersecurity, manufacturing).
Why Mattermost
- Mission-Driven: Support organizations that depend on secure, reliable collaboration.
- Remote-First: Work from anywhere with a globally distributed, high-trust team.
- AI-Forward: Work with and build cutting-edge AI-enabled workflows.
- Unique Scope: Own the compliance program end-to-end at a high-growth Series B company.
Eligibility Requirements
- This role requires U.S. citizenship.
- Candidates must be located in the United States.
- Must be eligible to obtain and maintain a U.S. government security clearance.
- Must meet eligibility requirements for access to export-controlled information (EAR/ITAR).
Timezone overlap
UTC-8–-4
Open to
US
Sign in to track applications and earn points.