Role Overview
Mattermost is hiring a GRC Manager. This is a full-time role in United States. posted 3 weeks ago. Full responsibilities, required qualifications, and the apply link are listed in the description below.
Resume Keywords to Include
Make sure these keywords appear in your resume to improve ATS scoring
Job description
Mattermost is hiring a GRC Manager to own and modernize our governance, risk, and compliance program across both federal and commercial markets.
This is a program-ownership role for someone who brings a modern, engineering-led approach to compliance — harnessing GRC engineering and AI to reduce manual effort and scale our programs. You will own Mattermost's compliance posture end to end, accountable for our federal readiness and commercial certifications, and you will modernize how we run them: automated, continuously monitored, and AI-native.
You will do the hands-on compliance work while coordinating across internal stakeholders in engineering, infrastructure, and IT who implement controls, the external auditors who assess them, and the customers whose trust rests on the outcome. As the program scales, you will grow and lead the team behind it.
What You'll Do
- Own and modernize Mattermost's compliance programs across federal and commercial markets
- Lead readiness, certification, and surveillance cycles across both programs
- Operate the risk management program end to end — from identification and assessment through treatment and acceptance
- Own the third-party and vendor risk management program, including security assessments and supply chain risk
- Apply GRC engineering and automation to replace manual evidence collection with continuous controls monitoring
- Build AI-native workflows to accelerate and improve the quality of recurring compliance work
- Maintain the control library, system security plans, POA&Ms, and policies
- Coordinate external audits from scoping through remediation
- Accelerate deal cycles by owning customer security questionnaires, trust center content, and reusable compliance artifacts
- Grow and lead the GRC team as the program scales
What We're Looking For
- Bachelor's degree in computer science, information security, or related field — or significant professional GRC and compliance experience
- Proven senior-level experience in governance, risk, and compliance, security compliance, or IT audit, including direct ownership of a certification or authorization program
- Experience with U.S. Federal standards including CMMC and NIST series (800-171 / 800-53)
- Experience with ISO 27001 and SOC 2 Type II
- Experience operating a formal risk management program
- Experience running a third-party and vendor risk management program
- Experience owning customer-facing security assurance, including security questionnaires and trust center content
- Working knowledge of security controls for cloud environments (AWS, GCP, and/or Azure)
- Excellent written and verbal communication skills
Nice to Have
- Professional GRC certifications such as CISA, CRISC, CISM, CISSP, or CIPP
- Experience working with AI platforms such as Claude, OpenAI, or Gemini
- Experience with compliance automation tooling such as Vanta or Drata, and continuous controls monitoring
- Direct experience applying AI or LLM-based workflows to GRC tasks
- Proficiency in no-code automation or scripting languages
- Past success in critical infrastructure industries including defense, cybersecurity, communications, or manufacturing
How Success Is Measured
- CMMC Level 2 gap assessment and readiness roadmap delivered within first 90 days
- SOC 2 Type II and ISO 27001 audit cycles completed on time without slippage
- Manual evidence collection replaced with automated, continuously monitored controls
- Customer security questionnaires and trust center content maintained to unblock deal cycles
- GRC team grown and operating as a scalable, program-driven function
Why Mattermost
- Mission-driven work: Your contributions directly support the organizations and missions that depend on secure, reliable collaboration
- Remote-first culture: Work from anywhere with a globally distributed, high-trust team built for autonomy and ownership
- Open source at the core: Be part of a vibrant developer community shaping the future of secure collaboration
- AI-forward environment: We actively adopt and build AI-enabled workflows — you'll work with and on cutting-edge tooling
- Unique scope: Own the compliance program end to end across both federal and commercial markets at a high-growth Series B company
Compensation
Mattermost takes a market-based approach to pay. Actual compensation may vary based on location, skills, experience, qualifications, and market conditions.
Target Salary Range: $139,254-$168,318
U.S. Eligibility & Compliance
This role requires U.S. citizenship. Candidates must be located in the United States and eligible to obtain and maintain a U.S. government security clearance. For more information visit Security Clearances — United States Department of State
Applicants must meet eligibility requirements for access to export-controlled information as defined by U.S. export control laws, including EAR and ITAR. For more information visit the Bureau of Industry and Security and the Directorate of Defense Trade Controls.
About Mattermost
Mattermost
mattermost.com
7 other open roles at Mattermost on TryApplyNow.
Frequently Asked Questions
How do I apply for the GRC Manager position at Mattermost?
Use the Apply button above to submit your application directly to Mattermost. Most applications take less than 5 minutes if your resume and contact details are ready, and you'll be routed to the employer's official application system to finish.
Where is the GRC Manager position at Mattermost located?
This position is based in United States. Mattermost has not indicated remote or hybrid options for this role, so candidates should plan for on-site work.
What does a GRC Manager at Mattermost earn?
Mattermost has not disclosed a salary range in this posting. Many employers share specifics later in the interview process; you can also ask during a recruiter screen if compensation transparency is important to you.
When was the GRC Manager role at Mattermost posted?
This role was posted on July 2, 2026 (21 days ago). It's still listed as actively hiring; we re-confirm openings against the source system multiple times per day and remove closed roles.
More Jobs at Mattermost
View all →Senior Account Executive (Enterprise)
Mattermost
Account Manager - Federal
Mattermost
Staff Software Engineer, Testing Infrastructure
Mattermost
Forward Deployed Engineer
Mattermost
Lead Site Reliability Engineer
Mattermost
AI-powered job search
Get every job scored to your resume
Upload your resume and get jobs ranked, your resume tailored, and employee contacts found automatically.
Get started freeNo credit card to start