Skip to content
MonarchMonarch

Senior Security GRC Analyst

Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.

About the job

Responsibilities

  • Own and mature the security compliance framework, including continuous controls monitoring, security awareness training, evidence currency, audit coordination, auditor communications, and remediation tracking.
  • Automate GRC workflows for evidence collection, questionnaire responses, risk management, and compliance enforcement using compliance platforms and AI tooling.
  • Own the third-party risk management program, including vendor security assessments, risk tiering, approval workflows, and continuous monitoring.
  • Develop and maintain the risk management program, including the risk register, risk assessments, treatment tracking, and leadership reporting.
  • Write, maintain, and update security policies, standards, procedures, and related documentation.
  • Own customer security assurance, including security questionnaires, evidence requests, trust center content, and knowledge base materials.

Requirements

  • 3–5 years of experience operating and scaling security GRC, compliance, or customer assurance programs in high-growth environments, specifically security GRC.
  • Hands-on knowledge of security controls involving IAM, endpoint security, and cloud infrastructure.
  • Strong attention to detail and ability to review sensitive, content-heavy documentation.
  • Strong cross-functional coordination across People, Legal, IT, Operations, Engineering, and leadership.
  • Experience writing, maintaining, and updating security policies, standards, and procedures.
  • Experience with SOC 2 or equivalent frameworks and customer assurance, including security questionnaires, evidence requests, and RFPs.
  • Experience with compliance platforms and continuous controls monitoring, such as Vanta, Drata, Oneleet, or SafeBase.
  • Experience using AI tools such as Claude or ChatGPT for GRC workflows.
  • Strong written communication for customer-facing security responses and audit documentation.

Nice-to-haves

  • Incident response or security operations experience.
  • Auditor experience, including Big Four or security audit firms, or experience serving as an internal audit lead.
  • Experience developing agents or tools for GRC workflows.
  • Experience supporting security reviews of contract redlines and legal contracts.
  • Fintech or financial services experience.
  • CISSP, CISA, CRISC, or equivalent certification.

Compensation and Benefits

  • Salary range: $180,000–$215,000 annually, plus equity compensation.
  • Fully remote work.
  • Workspace setup stipend.
  • Competitive benefits based on employee location, including medical, dental, vision, and 401(k) benefits in the United States.
  • Unlimited paid time off.
  • Monthly three-day weekend.

Skills

Security Grc, SOC 2, IAM, Endpoint Security, Cloud Infrastructure, Third-Party Risk Management, Risk Management, Security Policies, Vanta, Drata, Oneleet, Safebase, AI Tools, Incident Response, Cissp

Valon

Valon

United States

Senior Security Engineer, Threat & Offensive Security
$180k+/yrRemote5+ YOESecurity Engineering

Leads offensive security, threat intelligence, security testing, and incident response across applications, infrastructure, and networks. The role requires at least five years of relevant experience, cloud security expertise, AI and automation experience, and a bachelor's degree.

Anyscale

Anyscale

India
Senior Product Security Engineer
$180k+/yrOn-site8+ YOESecurity Engineering

Own Anyscale’s secure software development lifecycle, partner with engineering on secure architecture and features, and lead vulnerability management and remediation. The role requires 8+ years of product or application security experience and strong hands-on secure-development expertise.

Anyscale

Anyscale

San Francisco, CA

Compliance Manager
$180k+/yrOn-site7+ YOESecurity Engineering

Own Anyscale’s compliance function end to end, leading SOC 2 and ISO 27001 programs, audit readiness, customer security diligence, and enterprise risk management. The role requires 7+ years in governance, risk, and compliance plus strong cloud and SaaS security-controls expertise.

Siftstack

Siftstack

Marina Del Rey, CA

Senior Application Security Engineer
$180k+/yrHybrid5+ YOESecurity Engineering

The Senior Application Security Engineer will build secure-by-default software patterns, supply-chain controls, and developer-facing security tooling across a distributed systems platform. The role requires 5+ years of production software experience, strong application security expertise, and depth in Go or Rust.

Fireworks AI

Fireworks AI

San Mateo, CA
Security Operations Lead
$180k+/yrRemote7+ YOESecurity Engineering

Build and lead Fireworks AI’s security operations function, owning detection engineering, incident response, threat intelligence, and SecOps workflows. The role requires 7+ years of security experience, hands-on EDR and cloud security expertise, strong Python automation skills, and the ability to grow an IC function into a team.