高级安全GRC分析师
Senior Security GRC Analyst
### **关于我们:**
Monarch 是一个功能强大的一站式个人理财平台,旨在让复杂的财务变得简单。自 2021 年推出以来,我们已成为用户和专家推荐的首选个人理财应用。我们的目标是让财务不再令人焦虑,让我们的会员能够专注于真正重要的事情。
我们是一支务实的团队,由有经验的企业家领导,他们热衷于帮助会员实现财务目标。我们专注于打造人们喜爱的产品,并不断寻找能让我们做得更好的优势。AI 是我们运营的核心:团队中的每个人都将其作为合作伙伴,以提升判断力、加快速度并拓展可能性。我们不追求工具的精通,而是追求熟练度和好奇心。重要的是,AI 是你当前工作的一部分,并且你正在主动提高自己使用 AI 的标准。
作为一家完全远程的公司(甚至在新冠疫情之前),我们欢迎几乎所有地方的申请人。我们的团队主要在太平洋时间上午 9 点至下午 2 点进行同步协作,并采用异步工作方式,以便跨时区保持联系。
加入我们,共同完成简化金钱、改变生活的使命。
### **职位描述:**
Monarch 正在寻找一名高级安全 GRC 分析师加入我们的安全团队。向企业与基础设施安全经理汇报,你将负责我们合规计划和客户安全保证职能的日常运作,同时推动整体 GRC 计划的成熟发展。这是一个注重协作和精准的构建者-运营者角色:你将每天与人力资源、法务、IT、运营、工程和管理层合作,通过自动化重复性工作,使计划随着公司成长而扩展。
### **你将负责:**
- 负责并完善我们的合规框架:持续控制监控、开发安全意识培训、证据更新、审计协调——收集和展示证据,将合适的人带入审计会议,并管理发现项直至解决。
- 自动化 GRC —— 证据收集、问卷回复、风险管理流程和合规性执行,使用合规平台和 AI 工具。
- 负责第三方风险管理(TPRM)计划:供应商安全评估、风险分级、审批流程和持续监控。
- 制定、维护并完善我们的风险管理计划——风险登记册、风险评估、处理跟踪以及向管理层报告。
- 撰写
查看英文原文
### **About Us:**
Monarch is a powerful, all-in-one personal finance platform designed to help make the complexity of finances feel simple again. Since launching in 2021, we've become the top-recommended personal finance app by users and experts. Our goal? To take the stress out of finances so our members can focus on what truly matters.
We are a team of do-ers led by experienced entrepreneurs who are passionate about helping our members reach their financial goals. We're hyper focused on building a product people love, and on finding every edge that helps us do that better. AI is core to how we operate: every person on the team uses it as a partner to sharpen judgment, move faster, and expand what's possible. We're not looking for tool mastery, we're looking for fluency and curiosity. What matters is that AI is part of how you work today and that you're actively raising your own bar on how to use it well.
As a fully remote company (even before COVID!), we welcome applicants from almost anywhere. Our team collaborates synchronously mostly from 9 AM – 2 PM PT and embraces asynchronous work to stay connected across time zones.
Join us on our mission to transform lives by **simplifying money, together.**
### **The Role:**
Monarch is seeking a Senior Security GRC Analyst to join our Security team. Reporting to the Manager of Corporate and Infrastructure Security, you'll own the day-to-day of our compliance program and customer security assurance function while maturing our overall GRC program. This is a builder-operator role that runs on cross-coordination and precision: you'll work daily with People, Legal, IT, Operations, Engineering, and leadership, automating the repetitive work so the program scales as we grow.
### **What You'll Do:**
- Own and mature our compliance framework: continuous controls monitoring, develop security awareness training, evidence currency, audit coordination — collecting and presenting evidence, pulling the right people into auditor calls, and managing findings to closure.
- Automate GRC — evidence collection, questionnaire responses, risk management workflows, and enforcing compliance — using compliance platforms and AI tooling.
- Own the third-party risk management (TPRM) program: vendor security assessments, risk tiering, approval workflows, and continuous monitoring.
- Develop, maintain, and mature our risk management program — risk register, risk assessments, treatment tracking, and reporting to leadership.
- Write, maintain, and update security policies and procedures, keeping documentation current as our control environment evolves.
- Own and scale customer assurance end to end — security questionnaires, evidence requests, trust center content, and knowledge base.
### **What You'll Bring:**
- 3-5 years operating and scaling security GRC, compliance, or customer assurance programs in high-growth environments — security GRC specifically.
- Hands on security knowledge — you have worked on designing and developing the technical controls behind the frameworks (IAM, endpoint, cloud infrastructure) well enough to speak credibly with both auditors and engineers.
- Meticulous attention to detail — you can sit down and work a sensitive or content heavy document line by line quickly, you deeply care about the nuances.
- Strong cross-functional coordination — this role lives across People, Legal, IT, Operations, Engineering, and leadership. This will frequently require gathering of people and pushing the needle forward.
- Hands-on experience writing, maintaining, and updating security policies, standards, and procedures.
- Hands-on experience with SOC 2 or equivalent and customer assurance (security questionnaires, evidence requests, RFPs).
- Experience with compliance platforms and continuous controls monitoring (Vanta, Drata, Oneleet, SafeBase, or similar).
- Experience leveraging AI tools (Claude, ChatGPT) for GRC workflows.
- Strong written communication for customer-facing security responses and audit documentation.
### **Nice to Haves:**
- Incident response or SOC/security operations background.
- Auditor background — time on the audit side (e.g., Big 4 or security audit firms) or serving as an internal audit lead.
- Developed agents and/or tools to assist with GRC related workflows.
- Experience supporting contract reviews from the security side (e.g., assessing customer redlines against our security posture, legal contracts).
- Fintech or financial services background.
- Relevant certifications (CISSP, CISA, CRISC, or equivalent).
### **Typical Process (May vary depending on role):**
- Recruiter Video Call
- Hiring Manager Video Call
- Take Home Assignment
- Virtual "onsite" round consisting of 2-4 rounds
- Reference Checks
- Offer!
_#LI-DNI_
### **Benefits :**
- Work wherever you want! As a **fully** remote company with no central office, we want you to work wherever you are happiest and most productive. Whether that’s out of your home, a co-working space, or elsewhere.
- Competitive cash and equity compensation in a hyper growth, early stage company 🚀.
- Stipend to set-up your ideal working environment.
- Competitive Benefit Plans for employees based on your location (e.g. in the US we offer: Medical, dental and vision benefits and the ability to contribute to a 401k plan).
- Unlimited PTO.
- 3 day weekend every month! We take off the “First Friday” every month to focus on rest, recuperation, or just having fun!
### **Equal Opportunity & Non-Discrimination**
We are an equal opportunity employer and value diversity. We do not discriminate on the basis of race, religion, color, national origin, sex (including pregnancy and gender identity), sexual orientation, age, marital status, veteran status, disability status, or genetic information.
### **Applicant Notices**
_California & San Francisco:_ Pursuant to the California Fair Chance Act and the San Francisco Fair Chance Ordinance, qualified applicants with arrest and conviction records will be considered for employment. We comply with all applicable fair chance hiring laws.