[![Image]() Meet Jobicy Copilot — free AI autofill for job applications + remote job alerts ›](#)   [All remote jobs](https://jobicy.com/jobs.md)Open role[![Mattermost logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2022/02/ecb6ff3992a12e3be49b73ca8a11f5c5.webp)](https://jobicy.com/company/mattermost.md)Remote opportunity at[Mattermost](https://jobicy.com/company/mattermost.md)

# GRC Manager

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

[Apply for this job](#job-application)[View company](https://jobicy.com/company/mattermost.md)Share16 Sep 2026Published21Listing views2Application actions16 Oct 2026Apply before  Opportunity details

## About this role.

AI SummaryMattermost is seeking a senior GRC Manager to own and modernize its governance, risk, and compliance program across federal and commercial markets. The role leads certification readiness, audits, risk management, vendor risk, customer security assurance, and compliance documentation for standards including CMMC, NIST, ISO 27001, and SOC 2 Type II. A major objective is replacing manual evidence gathering with continuous controls monitoring, GRC automation, and AI-enabled workflows. This is a hands-on, high-autonomy program ownership position that is expected to scale into leadership of a GRC team. U.S. citizenship, U.S. location, and eligibility for a government security clearance are required.

## Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

### Job Complexity

5/5EasyHard

### Pace & Pressure

5/5RelaxedFast-paced

### Autonomy Level

5/5GuidedFull ownership

### Communication Load

5/5IndependentCollaborative

AI insightThis role carries end-to-end accountability for high-stakes federal and commercial compliance programs, including CMMC readiness, audit execution, and customer assurance. It requires deep regulatory expertise, technical cloud-control knowledge, and the ability to drive cross-functional remediation while building scalable automation.

## Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianMarket rate$153,786US market range$135k–$180k0$198k

AI insightThe disclosed target yearly salary range is USD 139,254 to USD 168,318, with a midpoint of USD 153,786. This is competitive for a senior U.S.-based GRC Manager responsible for federal compliance, CMMC/NIST programs, SOC 2 and ISO 27001, and compliance automation; an estimated broader U.S. market range is USD 135,000 to USD 180,000 annually, depending on location, clearance requirements, certifications, and management scope.

## Core skills

Skills and capabilities most closely associated with this opportunity.

[Governance, Risk & Compliance](https://jobicy.com/jobs?search_keywords=Governance%20Risk%20%20Compliance.md)[CMMC](https://jobicy.com/jobs?search_keywords=CMMC.md)[NIST 800-171](https://jobicy.com/jobs?search_keywords=NIST%20800-171.md)[NIST 800-53](https://jobicy.com/jobs?search_keywords=NIST%20800-53.md)[ISO 27001](https://jobicy.com/jobs?search_keywords=ISO%2027001.md)[SOC 2 Type II](https://jobicy.com/jobs?search_keywords=SOC%202%20Type%20II.md)[Federal Compliance](https://jobicy.com/jobs?search_keywords=Federal%20Compliance.md)[Risk Management](https://jobicy.com/jobs?search_keywords=Risk%20Management.md)[Third-Party Risk Management](https://jobicy.com/jobs?search_keywords=Third-Party%20Risk%20Management.md)[Compliance Automation](https://jobicy.com/jobs?search_keywords=Compliance%20Automation.md)

Sample interview questionsHow would you approach delivering a CMMC Level 2 gap assessment and readiness roadmap in your first 90 days?I would first define the CMMC assessment boundary, identify applicable CUI flows and systems, and map existing controls and evidence to NIST SP 800-171 requirements. I would validate implementation with engineering, IT, and infrastructure owners, document gaps and POA&Ms, prioritize remediation by risk and dependency, and present an accountable roadmap with milestones, owners, and measurable readiness criteria.

Describe how you would replace manual compliance evidence collection with continuous controls monitoring.

I would identify the most repetitive, high-volume evidence requests and map them to authoritative system sources such as cloud configurations, identity platforms, ticketing systems, endpoint tooling, and CI/CD logs. I would then implement integrations through a compliance platform, APIs, scripts, or no-code workflows, establish control tests and exception alerts, and retain audit-ready evidence with clear ownership and review cadence.

How do you manage competing requirements across CMMC, NIST, ISO 27001, and SOC 2?

I create a unified control library that maps shared control objectives to each framework while preserving framework-specific evidence and testing requirements. This reduces duplicate work, clarifies ownership, and allows remediation efforts to improve multiple programs at once. I maintain a change-management process so regulatory updates, system changes, and audit findings are reflected promptly in the mapping.

How would you handle a critical control deficiency discovered shortly before an external audit?

I would rapidly confirm the scope, root cause, and affected evidence, then engage the responsible technical owner on a remediation plan. If immediate remediation is not feasible, I would document a defensible risk assessment, compensating controls, a time-bound POA&M, and leadership acceptance where appropriate. I would communicate transparently with the auditor while ensuring statements are accurate, supported, and coordinated.

What is your approach to customer security questionnaires and trust center content?

I would build a maintained response library grounded in approved policies, architecture descriptions, audit reports, and control evidence, with defined review owners and expiration dates. I would use automation and AI-assisted drafting carefully to speed first responses, but require human validation for accuracy and sensitive claims. I would also track recurring questions to improve trust-center materials and reduce sales-cycle friction over time.

Mattermost is the leading collaborative workflow platform for defense, intelligence, security, and critical infrastructure. Trusted by the U.S. Department of War and Fortune 500s, our platform runs on-premises and in private clouds, delivering secure messaging, file sharing, workflow automation, audio/screenshare, and project management—all with full data and operational control. Mattermost powers high-stakes workflows across mission planning, real-time, real-world operations, DevSecOps, incident response, and cyber defense—enabling secure collaboration from tactical edge and DDIL environments to enterprise HQ. Teams operate across web, desktop, and mobile, with embedded interoperability for Microsoft Teams, Outlook, and Microsoft 365.

To learn more, visit [www.mattermost.com](http://www.mattermost.com/)

Mattermost is hiring a GRC Manager to own and modernize our governance, risk, and compliance program across both federal and commercial markets.

This is a program-ownership role for someone who brings a modern, engineering-led approach to compliance — harnessing GRC engineering and AI to reduce manual effort and scale our programs. You will own Mattermost’s compliance posture end to end, accountable for our federal readiness and commercial certifications, and you will modernize how we run them: automated, continuously monitored, and AI-native.

You will do the hands-on compliance work while coordinating across internal stakeholders in engineering, infrastructure, and IT who implement controls, the external auditors who assess them, and the customers whose trust rests on the outcome. As the program scales, you will grow and lead the team behind it.

What You’ll Do

* Own and modernize Mattermost’s compliance programs across federal and commercial markets
* Lead readiness, certification, and surveillance cycles across both programs
* Operate the risk management program end to end — from identification and assessment through treatment and acceptance
* Own the third-party and vendor risk management program, including security assessments and supply chain risk
* Apply GRC engineering and automation to replace manual evidence collection with continuous controls monitoring
* Build AI-native workflows to accelerate and improve the quality of recurring compliance work
* Maintain the control library, system security plans, POA&Ms, and policies
* Coordinate external audits from scoping through remediation
* Accelerate deal cycles by owning customer security questionnaires, trust center content, and reusable compliance artifacts
* Grow and lead the GRC team as the program scales

What We’re Looking For

* Bachelor’s degree in computer science, information security, or related field — or significant professional GRC and compliance experience
* Proven senior-level experience in governance, risk, and compliance, security compliance, or IT audit, including direct ownership of a certification or authorization program
* Experience with U.S. Federal standards including CMMC and NIST series (800-171 / 800-53)
* Experience with ISO 27001 and SOC 2 Type II
* Experience operating a formal risk management program
* Experience running a third-party and vendor risk management program
* Experience owning customer-facing security assurance, including security questionnaires and trust center content
* Working knowledge of security controls for cloud environments (AWS, GCP, and/or Azure)
* Excellent written and verbal communication skills

Nice to Have

* Professional GRC certifications such as CISA, CRISC, CISM, CISSP, or CIPP
* Experience working with AI platforms such as Claude, OpenAI, or Gemini
* Experience with compliance automation tooling such as Vanta or Drata, and continuous controls monitoring
* Direct experience applying AI or LLM-based workflows to GRC tasks
* Proficiency in no-code automation or scripting languages
* Past success in critical infrastructure industries including defense, cybersecurity, communications, or manufacturing

How Success Is Measured

* CMMC Level 2 gap assessment and readiness roadmap delivered within first 90 days
* SOC 2 Type II and ISO 27001 audit cycles completed on time without slippage
* Manual evidence collection replaced with automated, continuously monitored controls
* Customer security questionnaires and trust center content maintained to unblock deal cycles
* GRC team grown and operating as a scalable, program-driven function

Why Mattermost

* Mission-driven work: Your contributions directly support the organizations and missions that depend on secure, reliable collaboration
* Remote-first culture: Work from anywhere with a globally distributed, high-trust team built for autonomy and ownership
* Open source at the core: Be part of a vibrant developer community shaping the future of secure collaboration
* AI-forward environment: We actively adopt and build AI-enabled workflows — you’ll work with and on cutting-edge tooling
* Unique scope: Own the compliance program end to end across both federal and commercial markets at a high-growth Series B company

Compensation

Mattermost takes a market-based approach to pay. Actual compensation may vary based on location, skills, experience, qualifications, and market conditions.

Target Salary Range: $139,254-$168,318

U.S. Eligibility & Compliance

This role requires U.S. citizenship. Candidates must be located in the United States and eligible to obtain and maintain a U.S. government security clearance. For more information visit [Security Clearances — United States Department of State](https://www.state.gov/securityclearances)

Applicants must meet eligibility requirements for access to export-controlled information as defined by U.S. export control laws, including EAR and ITAR. For more information visit the [Bureau of Industry and Security](https://www.bis.doc.gov) and the [Directorate of Defense Trade Controls](https://www.pmddtc.state.gov).

Mattermost is an EEO Employer, we are a remote-first, open-source company.

We are continually working to expand our hiring in more countries and regions, ensuring compliance with local laws and regulations, which takes time.

Mattermost values your unique perspective—we welcome all applicants. We encourage individuals from all backgrounds to apply and are committed to assessing candidates based on their skills and qualifications. We do not tolerate discrimination against staff or applicants based on race, religion, national origin, age, disability, pregnancy status, veteran status, or other personal characteristics.

If you require accommodations during the interview process, please let us know—we’re happy to assist.

Show more

[Apply now >](https://jobicy.com/jobs/153443-grc-manager.md)

*

![Upload CV](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NSIgaGVpZ2h0PSI2NSIgZmlsbD0ibm9uZSIgeG1sbnM6dj0iaHR0cHM6Ly92ZWN0YS5pby9uYW5vIj48ZyBjbGlwLXBhdGg9InVybCgjQSkiPjxwYXRoIGQ9Ik0wIDBINjVWNjVIMFYwWiIgZmlsbD0iIzAyOWFlYiIvPjxnIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2ZmZiIgc3Ryb2tlLXdpZHRoPSIyIj48cGF0aCBkPSJNMzMuMDQ5IDE1LjQ1NGExLjQzIDEuNDMgMCAwIDAtMi4wOTcgMGwtNy41NzkgOC4xNDdhMS4zOCAxLjM4IDAgMCAwIC4wOSAxLjk3MyAxLjQ0IDEuNDQgMCAwIDAgMi4wMDgtLjA4OGw1LjEwOS01LjQ5MnYyMC42MWExLjQxIDEuNDEgMCAwIDAgMS40MjEgMS4zOTdjLjc4NSAwIDEuNDIxLS42MjUgMS40MjEtMS4zOTd2LTIwLjYxbDUuMTA5IDUuNDkyYTEuNDQgMS40NCAwIDAgMCAyLjAwOC4wODggMS4zOCAxLjM4IDAgMCAwIC4wOS0xLjk3M2wtNy41NzktOC4xNDZ6TTE2Ljc2OSAzOC40YzAtLjc3My0uNjItMS40LTEuMzg1LTEuNFMxNCAzNy42MjcgMTQgMzguNHYuMTAybC4yMTUgNi4yMjljLjIyMyAxLjY4LjcwMSAzLjA5NSAxLjgxMyA0LjIxOHMyLjUxIDEuNjA3IDQuMTcyIDEuODMzYzEuNi4yMTggMy42MzYuMjE4IDYuMTYuMjE4aDExLjI4bDYuMTYtLjIxOGMxLjY2Mi0uMjI2IDMuMDYxLS43MDkgNC4xNzItMS44MzNzMS41ODktMi41MzggMS44MTMtNC4yMThDNTAgNDMuMTEzIDUwIDQxLjA1NSA1MCAzOC41MDNWMzguNGMwLS43NzMtLjYyLTEuNC0xLjM4NS0xLjRzLTEuMzg1LjYyNy0xLjM4NSAxLjRsLS4xOSA1Ljk1OGMtLjE4MiAxLjM3LS41MTUgMi4wOTUtMS4wMjYgMi42MTJzLTEuMjI4Ljg1My0yLjU4MyAxLjAzOGMtMS4zOTUuMTktMy4yNDMuMTkzLTUuODkzLjE5M0gyNi40NjJjLTIuNjUgMC00LjQ5OC0uMDAzLTUuODkzLS4xOTMtMS4zNTUtLjE4NC0yLjA3Mi0uNTIxLTIuNTgzLTEuMDM4cy0uODQ0LTEuMjQyLTEuMDI2LTIuNjEyYy0uMTg3LTEuNDEtLjE5MS0zLjI3OS0uMTkxLTUuOTU4eiIvPjwvZz48L2c+PGRlZnM+PGNsaXBQYXRoIGlkPSJBIj48cGF0aCBmaWxsPSIjZmZmIiBkPSJNMCAwaDY1djY1SDB6Ii8+PC9jbGlwUGF0aD48L2RlZnM+PC9zdmc+)

### Upload your resume now

To unlock remote work opportunities and be discovered by global employers.

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

## Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Keep exploring

## Related remote jobs.

Matched by job category10 related opportunities[Legal & Compliance](https://jobicy.com/categories/legal.md) [Browse all jobs](https://jobicy.com/jobs.md)
*
![UpGuard logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/474a12c7-221.png)
UpGuard  Sep 16

### [Associate Commercial Counsel](https://jobicy.com/jobs/153431-associate-commercial-counsel-2.md)

Who are we? At UpGuard, we are replacing manual security bottlenecks with AI-driven precision. Fresh off a US$75M Series C, we are scaling our infrastructure to process 100 billion risk…

*
![CertiK logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/03/Jobicy-210308091023-955845.jpg)
CertiK  Sep 16

### [Director of AML & Virtual Asset Compliance](https://jobicy.com/jobs/153369-director-of-aml-virtual-asset-compliance.md)

About the Company Born from groundbreaking research at Columbia University and Yale University, CertiK is a leading Web3 security company focused on securing blockchain protocols, smart contracts, and decentralized applications…

*
![GiveDirectly logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/07307149-221.png)
GiveDirectly  Sep 16

### [Internal Audit Field Officer (Part-Time Contractor)](https://jobicy.com/jobs/153359-internal-audit-field-officer-part-time-contractor.md)

GiveDirectly has delivered more than $1B in cash directly to 2+ million people living in poverty across 15 countries since 2011. We believe cash transfers are one of the most…

*
![Canonical logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/b4d068a9-221-1.png)
Canonical  Sep 16

### [Legal Counsel – Regulatory Compliance, Product and Privacy](https://jobicy.com/jobs/146234-legal-counsel-regulatory-compliance-product-and-privacy.md)

Canonical is a leading provider of open source software and operating systems to the global enterprise and technology markets. Our platform, Ubuntu, is very widely used in breakthrough enterprise initiatives…

*
![Axiom logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/08/1c48ca0c-221.jpeg)
Axiom  Sep 16

### [Legal Consultant – Japanese Speakers (to be based in Hong Kong)](https://jobicy.com/jobs/149307-legal-consultant-japanese-speakers-to-be-based-in-hong-kong.md)

We are currently seeking to hire Legal Consultant with excellent/native Japanese language skills to join our ranks and support multiple Fortune 500 clients across financial services and corporates, role…

*
![Playson logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/6f266d9c-221-1.png)
Playson  Sep 14

### [Senior Legal Counsel](https://jobicy.com/jobs/153231-senior-legal-counsel-3.md)

About the Role We’re looking for a proactive and commercially minded Senior Legal Counsel with solid B2B iGaming experience to join Playson’s Legal Team. This is a high-ownership role with…

*
![Legion logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/99d2bb45-221-1.jpg)
Legion  Sep 14

### [General Counsel](https://jobicy.com/jobs/153198-general-counsel.md)

General Counsel Remote, United States Company Overview Legion Technologies is the pioneer in AI-powered workforce management. Our SaaS platform helps large, distributed enterprises maximize labor efficiency while improving the experience…

*
![Nivoda logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/42cf7153-221.jpeg)
Nivoda  Sep 14

### [Trade Compliance Specialist (Europe)](https://jobicy.com/jobs/150578-trade-compliance-specialist-europe.md)

Location: Fully remote in EuropeWorking Hours: Mon – Fri, 9AM – 6PM CETAbout Nivoda 🚀Nivoda is a rapidly scaling global B2B diamond and gemstone marketplace connecting jewellery retailers with competitive,…

*
![Axiom logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/08/1c48ca0c-221.jpeg)
Axiom  Sep 14

### [Legal Consultant – GMSLA](https://jobicy.com/jobs/149122-legal-consultant-gmsla.md)

We are currently on the lookout for legal consultants with strong GMSLA experience to join our ranks and support our Fortune 500 financial service client:Key Responsibilities Draft, review, and negotiate GMSLAs and…

*
![Axiom logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/08/1c48ca0c-221.jpeg)
Axiom  Sep 14

### [Legal Consultant – Financial Services](https://jobicy.com/jobs/149126-legal-consultant-financial-services-2.md)

Currently, we’re hiring Financial Services Legal Consultants to join us with: Minimum of 1 years’ experience within the general banking / regulatory compliance / banking finance areas. In-house legal experience is preferred…