Back to jobs

GRC Manager

United States
Mattermost is the leading collaborative workflow platform for defense, intelligence, security, and critical infrastructure. Trusted by the U.S. Department of War and Fortune 500s, our platform runs on-premises and in private clouds, delivering secure messaging, file sharing, workflow automation, audio/screenshare, and project management—all with full data and operational control. Mattermost powers high-stakes workflows across mission planning, real-time, real-world operations, DevSecOps, incident response, and cyber defense—enabling secure collaboration from tactical edge and DDIL environments to enterprise HQ. Teams operate across web, desktop, and mobile, with embedded interoperability for Microsoft Teams, Outlook, and Microsoft 365.

To learn more, visit www.mattermost.com

Mattermost is hiring a GRC Manager to own and modernize our governance, risk, and compliance program across both federal and commercial markets.

This is a program-ownership role for someone who brings a modern, engineering-led approach to compliance — harnessing GRC engineering and AI to reduce manual effort and scale our programs. You will own Mattermost's compliance posture end to end, accountable for our federal readiness and commercial certifications, and you will modernize how we run them: automated, continuously monitored, and AI-native.

You will do the hands-on compliance work while coordinating across internal stakeholders in engineering, infrastructure, and IT who implement controls, the external auditors who assess them, and the customers whose trust rests on the outcome. As the program scales, you will grow and lead the team behind it.

What You'll Do

  • Own and modernize Mattermost's compliance programs across federal and commercial markets
  • Lead readiness, certification, and surveillance cycles across both programs
  • Operate the risk management program end to end — from identification and assessment through treatment and acceptance
  • Own the third-party and vendor risk management program, including security assessments and supply chain risk
  • Apply GRC engineering and automation to replace manual evidence collection with continuous controls monitoring
  • Build AI-native workflows to accelerate and improve the quality of recurring compliance work
  • Maintain the control library, system security plans, POA&Ms, and policies
  • Coordinate external audits from scoping through remediation
  • Accelerate deal cycles by owning customer security questionnaires, trust center content, and reusable compliance artifacts
  • Grow and lead the GRC team as the program scales

What We're Looking For

  • Bachelor's degree in computer science, information security, or related field — or significant professional GRC and compliance experience
  • Proven senior-level experience in governance, risk, and compliance, security compliance, or IT audit, including direct ownership of a certification or authorization program
  • Experience with U.S. Federal standards including CMMC and NIST series (800-171 / 800-53)
  • Experience with ISO 27001 and SOC 2 Type II
  • Experience operating a formal risk management program
  • Experience running a third-party and vendor risk management program
  • Experience owning customer-facing security assurance, including security questionnaires and trust center content
  • Working knowledge of security controls for cloud environments (AWS, GCP, and/or Azure)
  • Excellent written and verbal communication skills

Nice to Have

  • Professional GRC certifications such as CISA, CRISC, CISM, CISSP, or CIPP
  • Experience working with AI platforms such as Claude, OpenAI, or Gemini
  • Experience with compliance automation tooling such as Vanta or Drata, and continuous controls monitoring
  • Direct experience applying AI or LLM-based workflows to GRC tasks
  • Proficiency in no-code automation or scripting languages
  • Past success in critical infrastructure industries including defense, cybersecurity, communications, or manufacturing

How Success Is Measured

  • CMMC Level 2 gap assessment and readiness roadmap delivered within first 90 days
  • SOC 2 Type II and ISO 27001 audit cycles completed on time without slippage
  • Manual evidence collection replaced with automated, continuously monitored controls
  • Customer security questionnaires and trust center content maintained to unblock deal cycles
  • GRC team grown and operating as a scalable, program-driven function

Why Mattermost

  • Mission-driven work: Your contributions directly support the organizations and missions that depend on secure, reliable collaboration
  • Remote-first culture: Work from anywhere with a globally distributed, high-trust team built for autonomy and ownership
  • Open source at the core: Be part of a vibrant developer community shaping the future of secure collaboration
  • AI-forward environment: We actively adopt and build AI-enabled workflows — you'll work with and on cutting-edge tooling
  • Unique scope: Own the compliance program end to end across both federal and commercial markets at a high-growth Series B company

Compensation

Mattermost takes a market-based approach to pay. Actual compensation may vary based on location, skills, experience, qualifications, and market conditions.

Target Salary Range: $139,254-$168,318

U.S. Eligibility & Compliance

This role requires U.S. citizenship. Candidates must be located in the United States and eligible to obtain and maintain a U.S. government security clearance. For more information visit Security Clearances — United States Department of State

Applicants must meet eligibility requirements for access to export-controlled information as defined by U.S. export control laws, including EAR and ITAR. For more information visit the Bureau of Industry and Security and the Directorate of Defense Trade Controls.

 

Mattermost is an EEO Employer, we are a remote-first, open-source company.
 
We are continually working to expand our hiring in more countries and regions, ensuring compliance with local laws and regulations, which takes time.
 
Mattermost values your unique perspective—we welcome all applicants. We encourage individuals from all backgrounds to apply and are committed to assessing candidates based on their skills and qualifications. We do not tolerate discrimination against staff or applicants based on race, religion, national origin, age, disability, pregnancy status, veteran status, or other personal characteristics.
 
If you require accommodations during the interview process, please let us know—we’re happy to assist.

Apply for this job

*

indicates a required field

Phone
Resume/CV

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...
Select...
Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Mattermost’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.


We use Greenhouse’s AI-powered Talent Matching tool to compare your application against our job requirements.

Learn more