GRC Manager
Own and modernize Mattermost's end-to-end GRC program across federal (CMMC/NIST) and commercial (SOC 2/ISO 27001) markets. Apply GRC engineering, automation, and AI to replace manual processes with continuous monitoring while leading risk management, audits, customer assurance, and team growth.
About the job
What You'll Do
- Own and modernize Mattermost's compliance programs across federal and commercial markets
- Lead readiness, certification, and surveillance cycles across both programs
- Operate the risk management program end to end — from identification and assessment through treatment and acceptance
- Own the third-party and vendor risk management program, including security assessments and supply chain risk
- Apply GRC engineering and automation to replace manual evidence collection with continuous controls monitoring
- Build AI-native workflows to accelerate and improve the quality of recurring compliance work
- Maintain the control library, system security plans, POA&Ms, and policies
- Coordinate external audits from scoping through remediation
- Accelerate deal cycles by owning customer security questionnaires, trust center content, and reusable compliance artifacts
- Grow and lead the GRC team as the program scales
What We're Looking For
- Bachelor's degree in computer science, information security, or related field — or significant professional GRC and compliance experience
- Proven senior-level experience in governance, risk, and compliance, security compliance, or IT audit, including direct ownership of a certification or authorization program
- Experience with U.S. Federal standards including CMMC and NIST series (800-171 / 800-53)
- Experience with ISO 27001 and SOC 2 Type II
- Experience operating a formal risk management program
- Experience running a third-party and vendor risk management program
- Experience owning customer-facing security assurance, including security questionnaires and trust center content
- Working knowledge of security controls for cloud environments (AWS, GCP, and/or Azure)
- Excellent written and verbal communication skills
Nice to Have
- Professional GRC certifications such as CISA, CRISC, CISM, CISSP, or CIPP
- Experience working with AI platforms such as Claude, OpenAI, or Gemini
- Experience with compliance automation tooling such as Vanta or Drata, and continuous controls monitoring
- Direct experience applying AI or LLM-based workflows to GRC tasks
- Proficiency in no-code automation or scripting languages
- Past success in critical infrastructure industries including defense, cybersecurity, communications, or manufacturing
How Success Is Measured
- CMMC Level 2 gap assessment and readiness roadmap delivered within first 90 days
- SOC 2 Type II and ISO 27001 audit cycles completed on time without slippage
- Manual evidence collection replaced with automated, continuously monitored controls
- Customer security questionnaires and trust center content maintained to unblock deal cycles
- GRC team grown and operating as a scalable, program-driven function
Skills
GRC, Cmmc, Nist 800-171, Nist 800-53, ISO 27001, SOC 2, Risk Management, Vendor Risk Management, AWS, GCP, Azure, Compliance Automation, Vanta, Drata, Cissp
Similar jobs
Leads high-complexity financial crime investigations, vendor operations, risk trend analysis, typology development, and audit readiness. Requires 7+ years of regulated-environment experience, advanced SQL, transaction-monitoring expertise, and knowledge of AML and fraud typologies.
Leads corporate services procurement for IT, Finance, Legal, HR, and Travel categories. Manages full procurement lifecycle, negotiates contracts, analyzes spend for cost savings, and builds sourcing team. Requires 7+ years experience and bachelor's degree.
Underwrites complex cyber and Technology E&O risks for large enterprise accounts, leads broker and client negotiations, and shapes portfolio strategy. Requires at least five years of underwriting experience, strong executive communication, and demonstrated mentorship of other underwriters.
Senior Life Actuary responsible for designing and maintaining Life, Annuity, and Health actuarial models, supporting client onboarding, demos, and technical guidance. Requires ASA/FSA-level qualification, 7+ years of relevant experience, actuarial platform expertise, and strong communication skills.
The Senior KYC Investigator will strengthen ongoing due diligence controls, improve KYC workflows, support complex refresh cases, and partner across Compliance, Product, and Risk teams to increase efficiency and reduce customer friction. The role requires at least 3–5 years in KYC, AML, sanctions, or risk investigations.