Mattermost
GRC Manager
United States
No sponsorship$171k-$800kDetected 19 days ago
AWSGCPAzureCloud PlatformsLLMsCybersecurityIncident ResponseComplianceProject ManagementSupply ChainCommunicationCollaborationMicrosoft OfficeMicrosoft Teams
About the role
- Teams operate across web, desktop, and mobile, with embedded interoperability for Microsoft Teams, Outlook, and Microsoft 365.
- This is a program-ownership role for someone who brings a modern, engineering-led approach to compliance - harnessing GRC engineering and AI to reduce manual effort and scale our programs.
- Target Salary Range: $139,254-$168,318 U.S. Eligibility & Compliance This role requires U.S. citizenship.
Responsibilities
- Own and modernize Mattermost's compliance programs across federal and commercial markets
- Lead readiness, certification, and surveillance cycles across both programs
- Own the third-party and vendor risk management program, including security assessments and supply chain risk
- Build AI-native workflows to accelerate and improve the quality of recurring compliance work
- Maintain the control library, system security plans, POA&Ms, and policies
- Grow and lead the GRC team as the program scales
- Mattermost is hiring a GRC Manager to own and modernize our governance, risk, and compliance program across both federal and commercial markets.
- You will own Mattermost's compliance posture end to end, accountable for our federal readiness and commercial certifications, and you will modernize how we run them: automated, continuously monitored, and AI-native.
- As the program scales, you will grow and lead the team behind it.
- Your contributions directly support the organizations and missions that depend on secure, reliable collaboration
Requirements
- Bachelor's degree in computer science, information security, or related field - or significant professional GRC and compliance experience
- Proven senior-level experience in governance, risk, and compliance, security compliance, or IT audit, including direct ownership of a certification or authorization program
- Experience with U.S. Federal standards including CMMC and NIST series (800-171 / 800-53)
- Experience with ISO 27001 and SOC 2 Type II
- Experience operating a formal risk management program
- Experience running a third-party and vendor risk management program
- Experience owning customer-facing security assurance, including security questionnaires and trust center content
- Working knowledge of security controls for cloud environments (AWS, GCP, and/or Azure)
Nice to have
- Professional GRC certifications such as CISA, CRISC, CISM, CISSP, or CIPP
- Experience working with AI platforms such as Claude, OpenAI, or Gemini
- Experience with compliance automation tooling such as Vanta or Drata, and continuous controls monitoring
- Direct experience applying AI or LLM-based workflows to GRC tasks
- Proficiency in no-code automation or scripting languages
- Past success in critical infrastructure industries including defense, cybersecurity, communications, or manufacturing
- CMMC Level 2 gap assessment and readiness roadmap delivered within first 90 days
- SOC 2 Type II and ISO 27001 audit cycles completed on time without slippage
Compensation
- Mattermost takes a market-based approach to pay.
- Actual compensation may vary based on location, skills, experience, qualifications, and market conditions.
- U.S. Eligibility & Compliance
- This role requires U.S. citizenship.
- Candidates must be located in the United States and eligible to obtain and maintain a U.S. government security clearance.
- For more information visit Security Clearances - United States Department of State
Benefits
- We do not tolerate discrimination against staff or applicants based on race, religion, national origin, age, disability, pregnancy status, veteran status, or other personal characteristics.
Company info
- Work from anywhere with a globally distributed, high-trust team built for autonomy and ownership
- What We're Looking For
- Mattermost is the leading collaborative workflow platform for defense, intelligence, security, and critical infrastructure.
- You will do the hands-on compliance work while coordinating across internal stakeholders in engineering, infrastructure, and IT who implement controls, the external auditors who assess them, and the customers whose trust rests on the outcome.
Equal opportunity
- Mattermost is an EEO Employer, we are a remote-first, open-source company.
Visa & Work Authorization
- citizenship
Apply directly at Mattermost →Create a free account for alerts like thisView Mattermost immigration profile
This listing is sourced directly from Mattermost's careers page and normalized into a canonical job model.