
Senior Security GRC Analyst
Posted 18 hours ago

Posted 18 hours ago
This is a fully remote position, open to applicants in United States.
• Take ownership of and enhance Monarch’s compliance framework, which encompasses continuous controls monitoring, security awareness training, evidence currency, audit coordination, evidence presentation, auditor communications, and resolution of findings.
• Automate Governance, Risk, and Compliance (GRC) processes, including evidence collection, questionnaire responses, risk management workflows, and compliance enforcement using compliance platforms and AI tools.
• Manage and expand the third-party risk management program, involving vendor security assessments, risk tiering, approval workflows, and ongoing monitoring.
• Develop, sustain, and enhance the risk management program, which includes the risk register, risk assessments, treatment tracking, and reporting to leadership.
• Author, maintain, and revise security policies and procedures as the control environment evolves.
• Oversee and expand customer assurance from start to finish, including security questionnaires, evidence requests, trust center content, and knowledge base management.
• Collaborate daily with People, Legal, IT, Operations, Engineering, and leadership teams.
• Automate repetitive tasks to ensure the GRC program scales alongside company growth.
• Report directly to the Manager of Corporate and Infrastructure Security.
• 3–5 years of experience in operating and scaling security GRC, compliance, or customer assurance programs in fast-paced environments, particularly in security GRC.
• Practical security knowledge with experience in designing and implementing technical controls for Identity and Access Management (IAM), endpoints, and cloud infrastructure.
• Exceptional attention to detail when handling sensitive or content-heavy documents.
• Strong ability to coordinate across multiple functions, including People, Legal, IT, Operations, Engineering, and leadership.
• Direct experience in writing, maintaining, and updating security policies, standards, and procedures.
• Hands-on experience with SOC 2 or equivalent frameworks and customer assurance processes, including security questionnaires, evidence requests, and RFPs.
• Familiarity with compliance platforms and continuous controls monitoring tools such as Vanta, Drata, Oneleet, or SafeBase.
• Experience utilizing AI tools like Claude and ChatGPT for GRC workflows.
• Strong written communication skills for crafting customer-facing security responses and audit documentation.
• Relevant certifications such as CISSP, CISA, or CRISC are advantageous.
• Background in incident response or SOC/security operations is a plus.
• Experience as an auditor or in a role leading internal audits is a plus.
• Familiarity with developing agents or tools for GRC workflows is a plus.
• Experience in supporting security-related contract reviews is a plus.
• Background in fintech or financial services is a plus.
• Competitive cash and equity compensation.
• Bonus opportunities available.
• Stipend provided to create an ideal working environment.
• Competitive benefits packages based on location.
• Medical, dental, and vision coverage available in the US.
• Opportunity to contribute to a 401(k) plan in the US.
• Unlimited paid time off (PTO).
• Enjoy a 3-day weekend every month with First Friday off.
• Fully remote work with no central office location.
• Flexible options for working from home, coworking spaces, or other locations.
Aya Healthcare
XBOX
XBOX
Get handpicked remote jobs straight to your inbox weekly.