Remote GRC Manager
$139.25k - $168.32kMattermost
Mattermost is the leading collaborative workflow platform for defense, intelligence, security, and critical infrastructure. Trusted by the U.S. Department of War and Fortune 500s, our platform runs on-premises and in private clouds, delivering secure messaging, file sharing, workflow automation, audio/screenshare, and project management—all with full data and operational control. Mattermost powers high-stakes workflows across mission planning, real-time, real-world operations, DevSecOps, incident response, and cyber defense—enabling secure collaboration from tactical edge and DDIL environments to enterprise HQ. Teams operate across web, desktop, and mobile, with embedded interoperability for Microsoft Teams, Outlook, and Microsoft 365.
To learn more, visit
Mattermost is hiring a GRC Manager to own and modernize our governance, risk, and compliance program across both federal and commercial markets.
This is a program-ownership role for someone who brings a modern, engineering-led approach to compliance — harnessing GRC engineering and AI to reduce manual effort and scale our programs. You will own Mattermost’s compliance posture end to end, accountable for our federal readiness and commercial certifications, and you will modernize how we run them: automated, continuously monitored, and AI-native.
You will do the hands-on compliance work while coordinating across internal stakeholders in engineering, infrastructure, and IT who implement controls, the external auditors who assess them, and the customers whose trust rests on the outcome. As the program scales, you will grow and lead the team behind it.
What You’ll Do
- Own and modernize Mattermost’s compliance programs across federal and commercial markets
- Lead readiness, certification, and surveillance cycles across both programs
- Operate the risk management program end to end — from identification and assessment through treatment and acceptance
- Own the third-party and vendor risk management program, including security assessments and supply chain risk
- Apply GRC engineering and automation to replace manual evidence collection with continuous controls monitoring
- Build AI-native workflows to accelerate and improve the quality of recurring compliance work
- Maintain the control library, system security plans, POA&Ms, and policies
- Coordinate external audits from scoping through remediation
- Accelerate deal cycles by owning customer security questionnaires, trust center content, and reusable compliance artifacts
- Grow and lead the GRC team as the program scales
What We’re Looking For
- Bachelor’s degree in computer science, information security, or related field — or significant professional GRC and compliance experience
- Proven senior-level experience in governance, risk, and compliance, security compliance, or IT audit, including direct ownership of a certification or authorization program
- Experience with U.S. Federal standards including CMMC and NIST series (800-171 / 800-53)
- Experience with ISO 27001 and SOC 2 Type II
- Experience operating a formal risk management program
- Experience running a third-party and vendor risk management program
- Experience owning customer-facing security assurance, including security questionnaires and trust center content
- Working knowledge of security controls for cloud environments (AWS, GCP, and/or Azure)
- Excellent written and verbal communication skills
Nice to Have
- Professional GRC certifications such as CISA, CRISC, CISM, CISSP, or CIPP
- Experience working with AI platforms such as Claude, OpenAI, or Gemini
- Experience with compliance automation tooling such as Vanta or Drata, and continuous controls monitoring
- Direct experience applying AI or LLM-based workflows to GRC tasks
- Proficiency in no-code automation or scripting languages
- Past success in critical infrastructure industries including defense, cybersecurity, communications, or manufacturing
How Success Is Measured
- CMMC Level 2 gap assessment and readiness roadmap delivered within first 90 days
- SOC 2 Type II and ISO 27001 audit cycles completed on time without slippage
- Manual evidence collection replaced with automated, continuously monitored controls
- Customer security questionnaires and trust center content maintained to unblock deal cycles
- GRC team grown and operating as a scalable, program-driven function
Why Mattermost
- Mission-driven work: Your contributions directly support the organizations and missions that depend on secure, reliable collaboration
- Remote-first culture: Work from anywhere with a globally distributed, high-trust team built for autonomy and ownership
- Open source at the core: Be part of a vibrant developer community shaping the future of secure collaboration
- AI-forward environment: We actively adopt and build AI-enabled workflows — you’ll work with and on cutting-edge tooling
- Unique scope: Own the compliance program end to end across both federal and commercial markets at a high-growth Series B company
Compensation
Mattermost takes a market-based approach to pay. Actual compensation may vary based on location, skills, experience, qualifications, and market conditions.
Target Salary Range: $139,254-$168,318
U.S. Eligibility & Compliance
This role requires U.S. citizenship. Candidates must be located in the United States and eligible to obtain and maintain a U.S. government security clearance. For more information visit Security Clearances — United States Department of State
Applicants must meet eligibility requirements for access to export-controlled information as defined by U.S. export control laws, including EAR and ITAR. For more information visit the Bureau of Industry and Security and the Directorate of Defense Trade Controls .
Mattermost is an EEO Employer, we are a remote-first, open-source company.
We are continually working to expand our hiring in more countries and regions, ensuring compliance with local laws and regulations, which takes time.
Mattermost values your unique perspective—we welcome all applicants. We encourage individuals from all backgrounds to apply and are committed to assessing candidates based on their skills and qualifications. We do not tolerate discrimination against staff or applicants based on race, religion, national origin, age, disability, pregnancy status, veteran status, or other personal characteristics.
If you require accommodations during the interview process, please let us know—we’re happy to assist.
Jobicy JobID: 153443$230k
...Manager, Security GRC Salary: Starting at $230k + bonus Location: Remote *We are unable to provide sponsorship for this role* Qualifications ~8+ years of professional experience in cybersecurity with at least 1 year in a leadership role ~ Heavy experience...Remote work$170k - $201k
...1, 2022, 2023, 2024) About the Role: We're looking for a GRC Manager to own governance, risk, and compliance for our B2B health benefits... ...operate from the New York Metropolitan area, NY, and remotely via San Francisco/Bay Area, CA, Seattle, WA. For those in our...Remote workFull timeContract workWork at officeImmediate startFlexible hours3 days per week- Optro, a leader in AI-powered GRC Intelligence, is seeking a go-to-market leader to own market definition for audit, risk, and compliance. You will guide a team of product marketers through a transition to a category-definer, shaping how the market sees Optro’s solutions...Remote job
$212.1k - $342.65k
...people’s lives. With intelligent agreement management, Docusign unleashes business-critical... ...Compliance as a Product by embedding adaptive GRC frameworks directly into the Docusign... ...divides their time between in-office and remote work. Access to an office location is required...Remote workContract workWork at officeLocal areaShift work2 days per week- A cutting-edge cybersecurity firm is seeking an Account Executive to drive sales of their AI-powered GRC platform. This remote role focuses on engaging enterprise customers and navigating regulatory requirements like PCI, HIPAA, and NIST. Candidates must have over 3 years...Remote job
- Mariner Wealth Advisors seeks a Director, Cyber GRC to lead governance, vendor risk, and security awareness across the organization. You will shape policies, drive risk management efforts, and ensure compliance with SEC, FINRA, and NYDFS requirements while partnering with...Remote job
- ...Job Description Job Description Job Summary: We are seeking a Manager, Information Security (GRC) to own and mature Neumo's Governance, Risk, and Compliance program. This role is critical to maintaining our SOC 1, SOC 2, and PCI certifications and to raising our...Remote workWork at officeLocal area
- PetsApp is seeking a Product Marketing Manager to lead product positioning and messaging within the governance, risk, and compliance space... ...into compelling narratives for banks and fintechs. This remote role involves collaborating with Product, Sales, and Customer Success...Remote job
- Workiva is seeking a Senior Sales Manager to lead high‑performing sales teams across enterprise technology solutions in the United States. The role focuses on coaching, talent recruitment, forecasting, and cross‑functional collaboration to meet aggressive sales goals. The...Remote job
- The Manager, AI Enablement leads implementation of the O’Reilly AI strategy by establishing... ...position located in Springfield, MO. Remote work is not an option for this role. ESSENTIAL... ...in coordination with accountable Legal, GRC, Privacy, Information Security, and...Remote workWork experience placementLocal areaFlexible hours
- ...program at scale.Crane is seeking a Senior Manager, Security Operations & Incident Response... ...partner with Legal, Privacy, HR, and GRC to align response processes, evidence handling... ...managing, leading, and developing remote/distributed teams with diverse backgrounds...Remote workFull time
- ...more at .OVERVIEWThe Identity and Access Management (IAM) Manager reports to the Sr. Director... ...BW/BI, RISE, Fiori, CIS, IAS, SolMan, and GRC Access Control (ARA, ARM, BRM, EAM),... ...cross-functional teams.Location of RoleUSA Remote, able to work from 8AM to 5PM Eastern Time...Remote workLocal area
- ...that modernizes, connects, secures, and manages technology environments for commercial enterprises... ..., visit udtonline.com.This position is remote but must be located in one of the... ...Help Desk; Governance, Risk and Compliance (GRC) Team; Professional Services Cyber...Remote workFor subcontractorCurrently hiringWork at officeLocal areaWork visaFlexible hoursShift workNight shiftWeekend work
- ...security-first technology consulting and managed services firm helping organizations address... ...and risk advisory, vCISO and GRC, managed IT and security services, cloud... ...significant earning potential . The role is remote within the United States. The Client Executive...Remote workFull timeContract work
$190k - $240k
Employee Experience Control Manager Location New York Business Area Accounting... ...and seamlessly across global offices and remote environments. This role is the control integrator... ...are clearly documented. Maintain clear GRC (governance, risk, compliance)...Remote workTemporary workFor contractorsWork experience placement- ...We’re a profitable, venture-backed, fully remote company building products that turn clinical... ...security awareness and training, and the GRC tooling that keeps evidence current. Run offensive security yourself: scope and manage external pentest firms, triage findings,...Remote workFor contractorsFixed term contractWork from homeHome office
$150.4k - $188k
...Sr. Director - Information Security for a Remote Assignment in McLean, VA My name is Stephen Hrutka. I lead a Veteran-Owned management consulting firm in Washington, DC. We specialize... ...certification, and experience with GRC platforms such as eMASS, CSAM, or CFACTS....Remote work$100k
...Founder & CEO Location: United States (remote), New York preferred; travel to Abu Dhabi... ..., or an adjacent RegTech, LegalTech, GRC or AML/KYC vendor, strongly preferred.... ...Existing networks across US banks, asset managers, fintechs and/or major law firms is a strong...Remote workFull time- ...now.We are currently seeking a Engagement Manager to join our team in Plano, Texas (US-TX),... ...Engagement Manager - ServiceNowLocation: Remote (with occasional travel as needed)Role... ...modules such as ITSM, ITOM, HRSD, CSM, and GRC.- Collaborate with technical leads and architects...Remote workWork at officeFlexible hours
- ...Location : Remote (US or Canada) JOB SUMMARY CyberGuard Advantage is a fast-growing... ...opportunities. This is not a passive alliance-management role. We are looking for a hands-on... ...develop high-value relationships across GRC platforms, cybersecurity vendors, MSP/...Remote workFull timeWork at office
- ResponsibilitiesThe Manager, IAM Engineering is responsible for leading and managing the Identity... ..., partnering with Security Operations, GRC, Infrastructure, and application teams to... ....**This position offers a fully remote work opportunity. Employees in this role...Remote work
- ...Enterprise Account Executive – West Region is a fully remote, full-cycle sales role responsible for managing opportunities from initial discovery through close,... ...~ Former experience at a Compliance Automation GRC tool provider is a plus ~ Bachelor’s degree preferred...Remote workFull time
$30k - $60k
...from scratch, identify key accounts, and manage full-cycle sales processes targeting mid-... ...with 500 to 1,000 employees, while working remotely. Key responsibilities Build and manage a... ...a challenger brand within cybersecurity, GRC, compliance, or security-adjacent SaaS...Remote workFull time- ...Servicenow Project Manager At TTEC Digital, we coach clients to ensure their employees... ...ITOM, SCM, FSM, HR Service Delivery, and GRC, and who is ready to take full ownership... ...drive issues to resolution. This is a remote role open to Philippines-based candidates...Remote workHourly pay
- ...Cybersecurity Sales Manager Location: Central / East Coast, USA Work Model: Remote / Hybrid Employment Type: Full-Time Industry: IT Services & Consulting... ...including Cloud Security, SOC/MDR, IAM, Zero Trust, GRC, Security Consulting, and Cyber Risk Services....Remote workFull timeContract work
$92k - $120k
...internal Career Portal (Jobs Hub). Click here to access. Time Type: Full time Remote Type: Job Family Group: Human Resources Job Description Summary: The Manager, Talent & People Analytics at Breakthru Beverage Group manages talent management...Remote workFull timeWork at officeFlexible hours- ...Product Marketing Manager We're looking for a Product Marketing Manager to own how Themis brings its products to market and tells its... ...institutions Familiarity with governance, risk, and compliance (GRC) or Banking-as-a-Service (BaaS) Experience marketing...Remote workFlexible hoursShift work
$20k
...life on Mars.INFORMATION SYSTEM SECURITY MANAGER SpaceX is seeking a classified cyber assurance... ...of Service Now (SNOW), eMASS, and other GRC tools Guide and mentor Cleared Cyber... ...Hawthorne, CA and requires being onsite - remote work not consideredActive Top Secret clearance...Remote workPermanent employmentTemporary workWeekend work- ...Marketing Manager Location: Remote (Greater Tampa Bay Area or New York City Preferred) About Compyl Compyl is a fast-growing cybersecurity SaaS company redefining the GRC space and transforming how businesses approach governance, risk, and compliance. We...Remote workFreelanceLocal areaFlexible hours
- ...CMMC) Company: ControlCase Location : Remote (US) with preference for proximity to key... ...opportunities, develop relationships, manage complex sales cycles, and close business.... ...Defense and DIB-focused sales Cybersecurity, GRC, compliance, or professional services...Remote workFull timeFor contractorsFor subcontractor
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Remote GRC Manager. Be the first to apply!





