
About Us:
Monarch is a powerful, all-in-one personal finance platform designed to make the complexity of finances feel simple again. Since launching in 2021, we've become the top-recommended personal finance app by users and experts. Our goal? To take the stress out of finances so our members can focus on what truly matters.
We are a team of do-ers led by experienced entrepreneurs who are passionate about helping our members reach their financial goals. We're hyper focused on building a product people love, and on finding every edge that helps us do that better. AI is core to how we operate: every person on the team uses it as a partner to sharpen judgment, move faster, and expand what's possible.
As a fully remote company, we welcome applicants from almost anywhere. Our team collaborates synchronously mostly from 9 AM – 2 PM PT and embraces asynchronous work to stay connected across time zones.
The Role:
Monarch is seeking a Senior Security GRC Analyst to join our Security team. Reporting to the Manager of Corporate and Infrastructure Security, you'll own the day-to-day of our compliance program and customer security assurance function while maturing our overall GRC program. This is a builder-operator role that runs on cross-coordination and precision.
What You'll Do:
- Own and mature our compliance framework: continuous controls monitoring, develop security awareness training, evidence currency, and audit coordination.
- Automate GRC — evidence collection, questionnaire responses, risk management workflows, and enforcing compliance — using compliance platforms and AI tooling.
- Own the third-party risk management (TPRM) program: vendor security assessments, risk tiering, approval workflows, and continuous monitoring.
- Develop, maintain, and mature our risk management program — risk register, risk assessments, treatment tracking, and reporting to leadership.
- Write, maintain, and update security policies and procedures, keeping documentation current as our control environment evolves.
- Own and scale customer assurance end to end — security questionnaires, evidence requests, trust center content, and knowledge base.
What You'll Bring:
- 3-5 years operating and scaling security GRC, compliance, or customer assurance programs in high-growth environments.
- Hands-on security knowledge regarding technical controls behind frameworks (IAM, endpoint, cloud infrastructure).
- Meticulous attention to detail and ability to work with sensitive or content-heavy documents.
- Strong cross-functional coordination across People, Legal, IT, Operations, Engineering, and leadership.
- Experience with compliance platforms and continuous controls monitoring (Vanta, Drata, Oneleet, SafeBase, or similar).
- Experience leveraging AI tools (Claude, ChatGPT) for GRC workflows.
- Strong written communication for customer-facing security responses and audit documentation.
Timezone overlap
UTC-8–-7
Culture
Async-friendly
Benefits
Equity, Health, Dental, Vision, 401k, Unlimited PTO, Home office, PTO, Coworking
Open to
Worldwide
Sign in to track applications and earn points.