Monarch Money logo

Senior Security GRC Analyst

Monarch Money
Remote
Remote$180k–$215k· about 2 hours ago

Straight from Monarch Money’s careers page. Apply on the company site — no recruiter, no middleman.

Explore more remote Security Analyst jobs — salaries, top companies, and the latest openings.See all →

Senior Security GRC Analyst

Department: Engineering

Location: Remote

Compensation: $180K – $215K • Offers Equity • Offers Bonus

Employment Type: FullTime

About Us:

Monarch is a powerful, all-in-one personal finance platform designed to help make the complexity of finances feel simple again. Since launching in 2021, weve become the top-recommended personal finance app by users and experts. Our goal? To take the stress out of finances so our members can focus on what truly matters.

We are a team of do-ers led by experienced entrepreneurs who are passionate about helping our members reach their financial goals. Were hyper focused on building a product people love, and on finding every edge that helps us do that better. AI is core to how we operate: every person on the team uses it as a partner to sharpen judgment, move faster, and expand whats possible. Were not looking for tool mastery, were looking for fluency and curiosity. What matters is that AI is part of how you work today and that youre actively raising your own bar on how to use it well.

As a fully remote company (even before COVID!), we welcome applicants from almost anywhere. Our team collaborates synchronously mostly from 9 AM – 2 PM PT and embraces asynchronous work to stay connected across time zones.

Join us on our mission to transform lives by simplifying money, together.

The Role:

Monarch is seeking a Senior Security GRC Analyst to join our Security team. Reporting to the Manager of Corporate and Infrastructure Security, youll own the day-to-day of our compliance program and customer security assurance function while maturing our overall GRC program. This is a builder-operator role that runs on cross-coordination and precision: youll work daily with People, Legal, IT, Operations, Engineering, and leadership, automating the repetitive work so the program scales as we grow.

What Youll Do:

  • Own and mature our compliance framework: continuous controls monitoring, develop security awareness training, evidence currency, audit coordination — collecting and presenting evidence, pulling the right people into auditor calls, and managing findings to closure.

  • Automate GRC — evidence collection, questionnaire responses, risk management workflows, and enforcing compliance — using compliance platforms and AI tooling.

  • Own the third-party risk management (TPRM) program: vendor security assessments, risk tiering, approval workflows, and continuous monitoring.

  • Develop, maintain, and mature our risk management program — risk register, risk assessments, treatment tracking, and reporting to leadership.

  • Write, maintain, and update security policies and procedures, keeping documentation current as our control environment evolves.

  • Own and scale customer assurance end to end — security questionnaires, evidence requests, trust center content, and knowledge base.

What Youll Bring:

  • 3-5 years operating and scaling security GRC, compliance, or customer assurance programs in high-growth environments — security GRC specifically.

  • Hands on security knowledge — you have worked on designing and developing the technical controls behind the frameworks (IAM, endpoint, cloud infrastructure) well enough to speak credibly with both auditors and engineers.

  • Meticulous attention to detail — you can sit down and work a sensitive or content heavy document line by line quickly, you deeply care about the nuances.

  • Strong cross-functional coordination — this role lives across People, Legal, IT, Operations, Engineering, and leadership. This will frequently require gathering of people and pushing the needle forward.

  • Hands-on experience writing, maintaining, and updating security policies, standards, and procedures.

  • Hands-on experience with SOC 2 or equivalent and customer assurance (security questionnaires, evidence requests, RFPs).

  • Experience with compliance platforms and continuous controls monitoring (Vanta, Drata, Oneleet, SafeBase, or similar).

  • Experience leveraging AI tools (Claude, ChatGPT) for GRC workflows.

  • Strong written communication for customer-facing security responses and audit documentation.

Nice to Haves:

  • Incident response or SOC/security operations background.

  • Auditor background — time on the audit side (e.g., Big 4 or security audit firms) or serving as an internal audit lead.

  • Developed agents and/or tools to assist with GRC related workflows.

  • Experience supporting contract reviews from the security side (e.g., assessing customer redlines against our security posture, legal contracts).

  • Fintech or financial services background.

  • Relevant certifications (CISSP, CISA, CRISC, or equivalent).

Typical Process (May vary depending on role):

  • Recruiter Video Call

  • Hiring Manager Video Call

  • Take Home Assignment

  • Virtual onsite round consisting of 2-4 rounds

  • Reference Checks

  • Offer!

    ## LI-DNI

Benefits :

  • Work wherever you want! As a fully remote company with no central office, we want you to work wherever you are happiest and most productive. Whether that’s out of your home, a co-working space, or elsewhere.

  • Competitive cash and equity compensation in a hyper growth, early stage company 🚀.

  • Stipend to set-up your ideal working environment.

  • Competitive Benefit Plans for employees based on your location (e.g. in the US we offer: Medical, dental and vision benefits and the ability to contribute to a 401k plan).

  • Unlimited PTO.

  • 3 day weekend every month! We take off the “First Friday” every month to focus on rest, recuperation, or just having fun!

Equal Opportunity & Non-Discrimination

We are an equal opportunity employer and value diversity. We do not discriminate on the basis of race, religion, color, national origin, sex (including pregnancy and gender identity), sexual orientation, age, marital status, veteran status, disability status, or genetic information.

Applicant Notices

California & San Francisco: Pursuant to the California Fair Chance Act and the San Francisco Fair Chance Ordinance, qualified applicants with arrest and conviction records will be considered for employment. We comply with all applicable fair chance hiring laws.

Jasper logo

Jasper

Senior Governance, Risk, and Compliance Lead

Remote
$174k–$205k
✓ From careers page· 9 minutes ago
Relativity logo

Relativity

Senior Security Engineer, Identity and Access Management

Remote
Illinois$130k–$195k
✓ From careers page· about 11 hours ago
Abnormal AI logo

Abnormal AI

Senior Customer Trust Analyst

Remote
✓ From careers page· about 12 hours ago
Sur Global Services logo

Sur Global Services

Security Compliance Analyst

Remote
Mexico$24k–$36k
✓ From careers page· about 13 hours ago

Discover More than 100,000 Hidden Remote Jobs Before Everyone Else

Unlock All Remote Jobs Today

Simple pricing. Big savings on Quarterly and Yearly.

Monthly Access

$19/month
  • Instant access to fresh remote jobs from 500+ companies
  • New opportunities added hourly, often 3-7 days before anywhere else
  • Advanced filtering by role type, stack, pay, and location
  • Priority customer support
Start 7-day trial — $2.95
Most Popular

Yearly Access

$59/year
  • Everything in Monthly
  • Save $169 (~74%) vs paying monthly
  • Average job search takes ~6 months - get covered for the whole journey
  • Less than the cost of one lunch per month for competitive advantage
  • Equivalent to just ~$4.92/month
Start 7-day trial — $2.95