GRC Manager
$139,254–$168,318 year
RemoteUnited States
Job Summary
Own and modernize Mattermost's governance, risk, and compliance programs across federal and commercial markets by leading readiness, certification, and surveillance cycles. Operate the risk management program end-to-end, from identification through acceptance, while managing third-party vendor risk and security assessments. Apply GRC engineering and automation to replace manual evidence collection with continuous controls monitoring, building AI-native workflows to accelerate recurring compliance work. Maintain the control library, system security plans, POA&Ms, and policies, and coordinate external audits from scoping to remediation. Accelerate deal cycles by owning customer security questionnaires and trust center content, then grow and lead the GRC team as the program scales. Deliver the CMMC Level 2 gap assessment and roadmap within 90 days, ensuring SOC 2 Type II and ISO 27001 audits complete on time.
Required Qualifications
- Bachelor's degree in computer science, information security, or related field — or significant professional GRC and compliance experience
- Proven senior-level experience in governance, risk, and compliance, security compliance, or IT audit, including direct ownership of a certification or authorization program
- Experience with U.S. Federal standards including CMMC and NIST series (800-171 / 800-53)
- Experience with ISO 27001 and SOC 2 Type II
- Experience operating a formal risk management program
- Experience running a third-party and vendor risk management program
- Experience owning customer-facing security assurance, including security questionnaires and trust center content
- Working knowledge of security controls for cloud environments (AWS, GCP, and/or Azure)
- Excellent written and verbal communication skills
- U.S. citizenship
- Located in the United States
- Eligible to obtain and maintain a U.S. government security clearance
- Meet eligibility requirements for access to export-controlled information as defined by U.S. export control laws, including EAR and ITAR
Desired Qualifications
- Professional GRC certifications such as CISA, CRISC, CISM, CISSP, or CIPP
- Experience working with AI platforms such as Claude, OpenAI, or Gemini
- Experience with compliance automation tooling such as Vanta or Drata, and continuous controls monitoring
- Direct experience applying AI or LLM-based workflows to GRC tasks
- Proficiency in no-code automation or scripting languages
- Past success in critical infrastructure industries including defense, cybersecurity, communications, or manufacturing
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.