Skip to content
MattermostMattermost

GRC Manager

Own and modernize Mattermost's end-to-end GRC program across federal (CMMC/NIST) and commercial (SOC 2/ISO 27001) markets. Apply GRC engineering, automation, and AI to replace manual processes with continuous monitoring while leading risk management, audits, customer assurance, and team growth.

About the job

What You'll Do

  • Own and modernize Mattermost's compliance programs across federal and commercial markets
  • Lead readiness, certification, and surveillance cycles across both programs
  • Operate the risk management program end to end — from identification and assessment through treatment and acceptance
  • Own the third-party and vendor risk management program, including security assessments and supply chain risk
  • Apply GRC engineering and automation to replace manual evidence collection with continuous controls monitoring
  • Build AI-native workflows to accelerate and improve the quality of recurring compliance work
  • Maintain the control library, system security plans, POA&Ms, and policies
  • Coordinate external audits from scoping through remediation
  • Accelerate deal cycles by owning customer security questionnaires, trust center content, and reusable compliance artifacts
  • Grow and lead the GRC team as the program scales

What We're Looking For

  • Bachelor's degree in computer science, information security, or related field — or significant professional GRC and compliance experience
  • Proven senior-level experience in governance, risk, and compliance, security compliance, or IT audit, including direct ownership of a certification or authorization program
  • Experience with U.S. Federal standards including CMMC and NIST series (800-171 / 800-53)
  • Experience with ISO 27001 and SOC 2 Type II
  • Experience operating a formal risk management program
  • Experience running a third-party and vendor risk management program
  • Experience owning customer-facing security assurance, including security questionnaires and trust center content
  • Working knowledge of security controls for cloud environments (AWS, GCP, and/or Azure)
  • Excellent written and verbal communication skills

Nice to Have

  • Professional GRC certifications such as CISA, CRISC, CISM, CISSP, or CIPP
  • Experience working with AI platforms such as Claude, OpenAI, or Gemini
  • Experience with compliance automation tooling such as Vanta or Drata, and continuous controls monitoring
  • Direct experience applying AI or LLM-based workflows to GRC tasks
  • Proficiency in no-code automation or scripting languages
  • Past success in critical infrastructure industries including defense, cybersecurity, communications, or manufacturing

How Success Is Measured

  • CMMC Level 2 gap assessment and readiness roadmap delivered within first 90 days
  • SOC 2 Type II and ISO 27001 audit cycles completed on time without slippage
  • Manual evidence collection replaced with automated, continuously monitored controls
  • Customer security questionnaires and trust center content maintained to unblock deal cycles
  • GRC team grown and operating as a scalable, program-driven function

Skills

GRC, Cmmc, Nist 800-171, Nist 800-53, ISO 27001, SOC 2, Risk Management, Vendor Risk Management, AWS, GCP, Azure, Compliance Automation, Vanta, Drata, Cissp

Similar jobs

Chime

Chime

Chicago, IL

Lead Analyst, Financial Crimes
$139k+/yrOn-site7+ YOEOther

Leads high-complexity financial crime investigations, vendor operations, risk trend analysis, typology development, and audit readiness. Requires 7+ years of regulated-environment experience, advanced SQL, transaction-monitoring expertise, and knowledge of AML and fraud typologies.

Crusoe

Crusoe

San Francisco, CA

Manager, Sourcing
$130k+/yrOn-site7+ YOEOther

Leads corporate services procurement for IT, Finance, Legal, HR, and Travel categories. Manages full procurement lifecycle, negotiates contracts, analyzes spend for cost savings, and builds sourcing team. Requires 7+ years experience and bachelor's degree.

Coalition Security

Coalition Security

United States

Senior/Executive Underwriter
$150k+/yrRemote5+ YOEOther

Underwrites complex cyber and Technology E&O risks for large enterprise accounts, leads broker and client negotiations, and shapes portfolio strategy. Requires at least five years of underwriting experience, strong executive communication, and demonstrated mentorship of other underwriters.

Akur8

Akur8

New York, NY

Senior Life Actuary
$170k+/yrRemote7+ YOEOther

Senior Life Actuary responsible for designing and maintaining Life, Annuity, and Health actuarial models, supporting client onboarding, demos, and technical guidance. Requires ASA/FSA-level qualification, 7+ years of relevant experience, actuarial platform expertise, and strong communication skills.

Mercury

Mercury

San Francisco, CA
Senior KYC Investigator - Ongoing Due Diligence
$96k+/yrRemote5+ YOEOther

The Senior KYC Investigator will strengthen ongoing due diligence controls, improve KYC workflows, support complex refresh cases, and partner across Compliance, Product, and Risk teams to increase efficiency and reduce customer friction. The role requires at least 3–5 years in KYC, AML, sanctions, or risk investigations.