Jobs › GRC Manager
GRC Manager
Mattermost is hiring for the job of GRC Manager, United States (On-site). This is a Governance job in the governance, risk, and compliance field, with a posted range of $139,254-$168,318. Review the full details below and apply directly with Mattermost.
Mattermost is the leading collaborative workflow platform for defense, intelligence, security, and critical infrastructure. Trusted by the U.S. Department of War and Fortune 500s, our platform runs on-premises and in private clouds, delivering secure messaging, file sharing, workflow automation, audio/screenshare, and project management, all with full data and operational control. Mattermost powers high-stakes workflows across mission planning, real-time, real-world operations, DevSecOps, incident response, and cyber defense, enabling secure collaboration from tactical edge and DDIL environments to enterprise HQ. Teams operate across web, desktop, and mobile, with embedded interoperability for Microsoft Teams, Outlook, and Microsoft 365.
To learn more, visit a www.mattermost.com
Mattermost is hiring a GRC Manager to own and modernize our governance, risk, and compliance program across both federal and commercial markets.
This is a program-ownership role for someone who brings a modern, engineering-led approach to compliance, harnessing GRC engineering and AI to reduce manual effort and scale our programs. You will own Mattermost s compliance posture end to end, accountable for our federal readiness and commercial certifications, and you will modernize how we run them: automated, continuously monitored, and AI-native.
You will do the hands-on compliance work while coordinating across internal stakeholders in engineering, infrastructure, and IT who implement controls, the external auditors who assess them, and the customers whose trust rests on the outcome. As the program scales, you will grow and lead the team behind it.
What You ll Do
Own and modernize Mattermost s compliance programs across federal and commercial markets
Lead readiness, certification, and surveillance cycles across both programs
Operate the risk management program end to end, from identification and assessment through treatment and acceptance
Own the third-party and vendor risk management program, including security assessments and supply chain risk
Apply GRC engineering and automation to replace manual evidence collection with continuous controls monitoring
Build AI-native workflows to accelerate and improve the quality of recurring compliance work
Maintain the control library, system security plans, POA and Ms, and policies
Coordinate external audits from scoping through remediation
Accelerate deal cycles by owning customer security questionnaires, trust center content, and reusable compliance artifacts
Grow and lead the GRC team as the program scales
What We re Looking For
Bachelor s degree in computer science, information security, or related field, or significant professional GRC and compliance experience
Proven senior-level experience in governance, risk, and compliance, security compliance, or IT audit, including direct ownership of a certification or authorization program
Experience with U.S. Federal standards including CMMC and NIST series (800-171 / 800-53)
Experience with ISO 27001 and SOC 2 Type II
Experience operating a formal risk management program
Experience running a third-party and vendor risk management program
Experience owning customer-facing security assurance, including security questionnaires and trust center content
Working knowledge of security controls for cloud environments (AWS, GCP, and/or Azure)
Excellent written and verbal communication skills
Nice to Have
Professional GRC certifications such as CISA, CRISC, CISM, CISSP, or CIPP
Experience working with AI platforms such as Claude, OpenAI, or Gemini
Experience with compliance automation tooling such as Vanta or Drata, and continuous controls monitoring
Direct experience applying AI or LLM-based workflows to GRC tasks
Proficiency in no-code automation or scripting languages
Past success in critical infrastructure industries including defense, cybersecurity, communications, or manufacturing
How Success Is Measured
CMMC Level 2 gap assessment and readiness roadmap delivered within first 90 days
SOC 2 Type II and ISO 27001 audit cycles completed on time without slippage
Manual evidence collection replaced with automated, continuously monitored controls
Customer security questionnaires and trust center content maintained to unblock deal cycles
GRC team grown and operating as a scalable, program-driven function
Why Mattermost
Mission-driven work: Your contributions directly support the organizations and missions that depend on secure, reliable collaboration
Remote-first culture: Work from anywhere with a globally distributed, high-trust team built for autonomy and ownership
Open source at the core: Be part of a vibrant developer community shaping the future of secure collaboration
AI-forward environment: We actively adopt and build AI-enabled workflows, you ll work with and on cutting-edge tooling
Unique scope: Own the compliance program end to end across both federal and commercial markets at a high-growth Series company
Compensation
Mattermost takes a market-based approach to pay. Actual compensation may vary based on location, skills, experience, qualifications, and market conditions.
Target Salary Range: $139,254-$168,318
U.S. Eligibility and Compliance
This role requires U.S. citizenship. Candidates must be located in the United States and eligible to obtain and maintain a U.S. government security clearance. For more information visit a Security Clearances, United States Department of State
Applicants must meet eligibility requirements for access to export-controlled information as defined by U.S. export control laws, including EAR and ITAR. For more information visit the a Bureau of Industry and Security and the a Directorate of Defense Trade Controls.
Mattermost is an EEO Employer, we are a remote-first, open-source company.
We are continually working to expand our hiring in more countries and regions, ensuring compliance with local laws and regulations, which takes time.
Mattermost values your unique perspective, we welcome all applicants. We encourage individuals from all backgrounds to apply and are committed to assessing candidates based on their skills and qualifications. We do not tolerate discrimination against staff or applicants based on race, religion, national origin, age, disability, pregnancy status, veteran status, or other personal characteristics.
If you require accommodations during the interview process, please let us know, we’re happy to assist.
Certifications this role asks for
Studying for one of these? Try the free CISA practice questions or the free CISM practice questions in our academy. No signup, no cost.
Location and market context
Location and work arrangement for this governance job are set by Mattermost; confirm remote, hybrid, or on-site expectations and any travel directly on the application page.
About governance jobs
Governance jobs design the structures, policies, and oversight that keep complex programs accountable, coordinating across legal, risk, compliance, and technology. Jobs like this one are typically evaluated against frameworks such as governance frameworks, policy standards, and oversight and reporting practices.
How to position yourself for this governance job
Strong candidates emphasize policy and standard-setting, committee and stakeholder coordination, oversight reporting, and translating strategy into durable operating structures. In your resume and outreach, tie your experience to how Mattermost would apply governance frameworks, policy standards, and oversight and reporting practices, and lead with concrete outcomes rather than duties.
Similar GRC jobs
- Staff Security Governance Engineer, Policies & Standards · Gitlab · Remote
- Global Sanctions Advisory Oversight Specialist - Vice President · Deutsche Bank · 2 Locations
- Senior KYC Analyst, Onboarding Operations, EMEA · Airwallex · Vilnius, LT
- Lead Analyst, Financial Crimes · Chime · Chicago, IL
- Operations Associate, Sanctions · Stripe · Bengaluru
- Regulatory Control Analyst, NCT · Deutsche Bank · Bangalore, Velankani Tech Park
- Senior Anti Financial Crime Officer · Deutsche Bank · Geneva Place des Bergues 3
- Due Diligence Implementation Analyst (KYC) · Deutsche Bank · Luxembourg 2 Blvd K. Adenauer
Hiring for Governance?
Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.
Post a job Pricing from $99 · About GRC Careers · Hiring toolkit
Want to be next in a job like this?
Jobs like GRC Manager in United States open regularly. Be first to know, privately. No current employer ever sees you looking.
Employer, or see something wrong with this posting? Report this posting and we will review it promptly.