Skip to main content
Mattermost
Mattermost

GRC Manager

RemoteUnited States only
Published
Role
Security
Experience
Senior
Company size
Startup
$139.3k–$168.3k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Senior GRC/compliance manager for U.S.-based U.S. citizens who can obtain and maintain a U.S. government security clearance. Must own certification/authorization programs across CMMC, NIST, ISO 27001, SOC 2 Type II, risk management, vendor risk, and customer security assurance. Needs cloud security controls knowledge across AWS/GCP/Azure and strong communication.

Core skills

CMMCGRCNIST

Required skills

NIST 800-171NIST 800-53ISO 27001SOC 2 Type IIAWS/GCP/Azure

Optional skills

CISACRISCCISMCISSPCIPPClaudeOpenAIGemini

What you'll do

  • Own and modernize Mattermost's compliance programs across federal and commercial markets
  • Lead readiness, certification, and surveillance cycles across both programs
  • Operate the risk management program end to end — from identification and assessment through treatment and acceptance
  • Own the third-party and vendor risk management program, including security assessments and supply chain risk
  • Apply GRC engineering and automation to replace manual evidence collection with continuous controls monitoring
  • Build AI-native workflows to accelerate and improve the quality of recurring compliance work
  • Maintain the control library, system security plans, POA&Ms, and policies
  • Coordinate external audits from scoping through remediation
  • Accelerate deal cycles by owning customer security questionnaires, trust center content, and reusable compliance artifacts
  • Grow and lead the GRC team as the program scales

What they require

  • Bachelor's degree in computer science, information security, or related field — or significant professional GRC and compliance experience
  • Proven senior-level experience in governance, risk, and compliance, security compliance, or IT audit, including direct ownership of a certification or authorization program
  • Experience with U.S. Federal standards including CMMC and NIST series (800-171 / 800-53)
  • Experience with ISO 27001 and SOC 2 Type II
  • Experience operating a formal risk management program
  • Experience running a third-party and vendor risk management program
  • Experience owning customer-facing security assurance, including security questionnaires and trust center content
  • Working knowledge of security controls for cloud environments (AWS, GCP, and/or Azure)
  • Excellent written and verbal communication skills
  • This role requires U.S. citizenship.
  • Candidates must be located in the United States and eligible to obtain and maintain a U.S. government security clearance.
  • Applicants must meet eligibility requirements for access to export-controlled information as defined by U.S. export control laws, including EAR and ITAR.
  • Preferred: Professional GRC certifications such as CISA, CRISC, CISM, CISSP, or CIPP
  • Preferred: Experience working with AI platforms such as Claude, OpenAI, or Gemini
  • Preferred: Experience with compliance automation tooling such as Vanta or Drata, and continuous controls monitoring
  • Preferred: Direct experience applying AI or LLM-based workflows to GRC tasks
  • Preferred: Proficiency in no-code automation or scripting languages
  • Preferred: Past success in critical infrastructure industries including defense, cybersecurity, communications, or manufacturing

Benefits

  • Mission-driven work: Your contributions directly support the organizations and missions that depend on secure, reliable collaboration
  • Remote-first culture: Work from anywhere with a globally distributed, high-trust team built for autonomy and ownership
  • Open source at the core: Be part of a vibrant developer community shaping the future of secure collaboration
  • AI-forward environment: We actively adopt and build AI-enabled workflows — you'll work with and on cutting-edge tooling
  • Unique scope: Own the compliance program end to end across both federal and commercial markets at a high-growth Series B company

Mattermost is the leading collaborative workflow platform for defense, intelligence, security, and critical infrastructure. Its platform runs on-premises and in private clouds, delivering secure messaging, file sharing, workflow automation, audio/screenshare, and project management with full data and operational control.

SoftwareStartupmattermost.com/

Details

Visa sponsorshipNo
$139.3k–$168.3k/yr