About Monarch Money
Monarch Money is a well-funded FinTech startup changing how millions of people manage their money. We’re a tight-knit team working in a hybrid, remote-first environment (US, Canada, Latin America). We’re passionate about building beautiful products and providing stellar customer experiences.
Our founding team started One Medical (ONEM) and built products at Google, Amazon, and Apple. We’re backed by Accel, Founders Fund, a16z, Goldcrest, Initialized, and more. Our app has 4.9 stars on the App Store and Google Play.
As a Security GRC Analyst, you will play a crucial role in enhancing our security posture and ensuring compliance with industry standards and regulations. You’ll be responsible for developing, implementing, and monitoring security policies, procedures, and controls to safeguard company assets and data, conducting regular risk assessments, and managing and improving the security awareness program. You will collaborate with cross-functional teams to integrate security and privacy by design into all aspects of our products and operations, ensuring that our security practices align with our commitment to protecting user data.
What You’ll Do
- Develop, implement, and monitor security policies, procedures, and controls to safeguard company assets and data.
- Conduct regular risk assessments, vulnerability scans, and penetration tests to identify and mitigate security risks.
- Manage and improve the security awareness program, ensuring employees are educated on best practices and emerging threats.
- Ensure compliance with relevant industry standards and regulations (e.g., SOC 2, ISO 27001, GDPR, CCPA).
- Collaborate with engineering, product, and legal teams to integrate security and privacy by design into all aspects of our products and operations.
- Respond to security incidents, conduct forensic analysis, and implement corrective actions to prevent future occurrences.
- Participate in external audits and assessments, providing necessary documentation and support.
- Evaluate and recommend new security technologies and solutions to improve our security posture.
- Maintain accurate records of security incidents, risk assessments, and compliance activities.
About You
- 3-5 years of experience in information security, with a strong focus on GRC (Governance, Risk, and Compliance).
- Proven experience with compliance frameworks such as SOC 2, ISO 27001, NIST, GDPR, CCPA, etc.
- Strong understanding of security principles, technologies, and best practices.
- Excellent communication, interpersonal, and problem-solving skills.
- Ability to work independently and as part of a team in a fast-paced, dynamic environment.
Bonus Points
- Relevant security certifications (e.g., CISSP, CISM, CISA).
- Experience with cloud security (AWS preferred).
- Bachelor’s degree in Computer Science, Information Security, or a related field.