GRC Analyst

Posted 2 Days Ago
Be an Early Applicant
27 Locations
Remote
Mid level
Fintech • Payments • Financial Services
The Role
Build and operate Mesh's GRC program: own controls, support SOC 2 and NIST alignment, run BC/DR programs, perform vendor risk assessments, support MiCA and U.S. Money Transmitter licensing, manage security issue remediation, and standardize scalable policies and controls across jurisdictions.
Summary Generated by Built In

About Mesh

At Mesh, our mission is to enable consumers to pay and be paid with any asset. Today, trillions of dollars in tokenized assets exist but remain largely unusable for everyday commerce. Mesh is bridging this gap by making crypto payments reliable, useful, and ubiquitous. We combine a powerful orchestration engine with a seamless consumer app to unlock liquidity for the world. Backed by leading investors like PayPal Ventures, Paradigm, and Galaxy Ventures, we are building the infrastructure for the next era of the global economy. Join us!

Overview

We're hiring a GRC Analyst to help build the compliance foundation powering the future of global crypto payments. At Mesh, we're connecting hundreds of exchanges, wallets, and financial platforms into a single open network, and this role will be instrumental in ensuring we scale securely, responsibly, and with trust at the center of everything we do.

As we continue to grow, you'll play a key role in shaping and maturing our GRC program across initiatives including SOC 2, MiCA licensing, and Money Transmitter Licenses throughout the U.S. This is a hands-on role with meaningful ownership—from managing day-to-day controls and strengthening core compliance processes to partnering closely with our Head of Security and GRC lead to navigate an increasingly complex regulatory landscape. We're looking for someone who enjoys rolling up their sleeves, building programs that scale, and contributing to the infrastructure powering the next generation of global payments.

What You'll Do

  • Own and strengthen our controls environment, ensuring compliance requirements are effectively implemented and maintained.
  • Support and mature our GRC program, including SOC 2 operations and alignment with broader security frameworks such as NIST.
  • Build and maintain our Business Continuity and Disaster Recovery program, including BIAs, continuity plans, and recovery runbooks.
  • Conduct vendor and third-party risk assessments as we expand our global network of partners.
  • Support MiCA licensing and U.S. Money Transmitter License applications through due diligence, regulatory responses, and compliance reporting.
  • Manage the security issue lifecycle, driving remediation efforts and partnering with teams to reduce risk.
  • Help standardize policies, controls, and compliance processes that can scale across jurisdictions and regulatory frameworks.

Who You Are

  • 3–5 years of hands-on GRC experience in an operating environment, with a track record of building and managing compliance programs—not just auditing them.
  • Deep familiarity with one or more major frameworks, such as SOC 2, NIST, PCI, MiCA, NYDFS, or CCPA.
  • Experience building or maturing Business Continuity and Disaster Recovery programs, with a strong understanding of how business impact assessments inform recovery strategies.
  • Comfortable supporting the full risk lifecycle, including risk assessments, control testing, issue management, and remediation.
  • A hands-on builder who enjoys improving processes, operationalizing controls, and turning requirements into scalable programs.
  • Regularly uses AI tools to increase efficiency and improve outcomes across areas such as policy development, process monitoring, or program management.
  • Experience in fintech, crypto, payments, or other regulated industries is a plus, as is familiarity with GRC platforms such as Vanta, Drata, or Archer. 

Why You’ll Love It Here

At Mesh, you're not stepping into a typical role—you're joining a rocket ship in mid-liftoff. You'll tackle complex, meaningful problems that actually move an industry forward, working alongside a sharp, motivated team that moves quickly, collaborates deeply, and expects everyone to operate with ownership. This is the kind of place where you'll see your work ship fast, make real impact, and be able to point to something and say, "I built that." You'll grow fast, level up your skills, and get a front-row seat to how a high-growth company scales from the inside, with competitive comp, solid benefits, and room to stretch your craft all coming standard. If you're energized by building, learning, and shaping something big—this is where you'll want to be.

In-Office Expectations

Employees based in our San Francisco, New York, and Bangalore hubs are expected to work from the office at least 40% of the time (approximately two days per week). This expectation may vary slightly depending on role, team, and business needs. Certain roles that require closer cross-functional collaboration or operational support may have additional in-office requirements, which will be discussed during the interview process. Our hybrid approach is designed to balance meaningful in-person collaboration, team building, and real-time decision-making with the flexibility to work remotely. We believe this structure supports strong execution while preserving autonomy and focus time.

How We Care For Our Team

We believe great work happens when people feel valued and supported. That starts with competitive salary and equity that grows as you and the company grow, plus comprehensive health coverage for you and your family. We offer unlimited PTO—and we mean it. Take the time you need to recharge and show up at your best.

We're invested in your growth with a dedicated budget for courses, conferences, and certifications. Work from wherever you're most productive with our remote-friendly approach, and count on having the top-tier tools and equipment you need to do exceptional work.

Mesh Pay is committed to equal employment opportunities regardless of race, color, genetic information, creed, religion, sex, sexual orientation, gender identity, lawful alien status, national origin, age, marital status, and non-job related physical or mental disability, or protected veteran status. Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

Skills Required

  • 3-5 years of hands-on GRC experience in an operating environment
  • Track record of building and managing compliance programs (not just auditing)
  • Deep familiarity with one or more frameworks (SOC 2, NIST, PCI, MiCA, NYDFS, CCPA)
  • Experience building or maturing Business Continuity and Disaster Recovery programs, including BIAs, continuity plans, and recovery runbooks
  • Experience supporting the full risk lifecycle: risk assessments, control testing, issue management, and remediation
  • Conduct vendor and third-party risk assessments
  • Support MiCA licensing and U.S. Money Transmitter License applications through due diligence, regulatory responses, and compliance reporting
  • Manage the security issue lifecycle and drive remediation efforts across teams
  • Regularly use AI tools to increase efficiency in policy development, process monitoring, or program management
  • Hands-on builder mindset: improve processes and operationalize controls
  • Experience in fintech, crypto, payments, or other regulated industries
  • Familiarity with GRC platforms such as Vanta, Drata, or Archer
  • If based in San Francisco, New York, or Bangalore, ability to work in-office at least 40% of the time
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
San Francisco, , CA
77 Employees
Year Founded: 2020

What We Do

Founded in 2020, Mesh is a leader in creating a modern financial connectivity layer for digital assets, delivering a secure, enterprise-grade platform for seamless transfers, payments, and account aggregation. Supporting over 300 integrations with exchanges, wallets, and financial services, Mesh is pioneering an open, connected, and secure ecosystem for digital finance

Similar Jobs

Mondelēz International Logo Mondelēz International

Sr. Analyst, Governance, Risk & Compliance (GRC), Information Security

Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
Remote or Hybrid
Greece
90000 Employees

Mondelēz International Logo Mondelēz International

Change Manager o9 MEU, Demand Planning

Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
Remote or Hybrid
9 Locations
90000 Employees

Mondelēz International Logo Mondelēz International

Change Manager o9 MEU, IBP

Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
Remote or Hybrid
8 Locations
90000 Employees

Mondelēz International Logo Mondelēz International

o9 Change Readiness Lead

Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
Remote or Hybrid
11 Locations
90000 Employees

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account