SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: GBP 57,000 - 70,000 / annual
Monzo is a fintech company on a mission to make money work for everyone, offering personal and business bank accounts, joint accounts, credit cards, savings, investments, and pensions in the UK.
We're seeking a proactive, technically-minded Senior Security Analyst to join Monzo's Security team. The Security team serves as Monzo's front door to security, helping the entire business operate securely. You'll gain exposure to a wide range of business contexts and a diverse mix of information security work—from assessing supplier security posture to supporting audits, evaluating product risks, updating policies, and translating regulatory requirements into practical action.
You'll work closely with security specialists, engineers, product teams, third-party risk managers, procurement, and colleagues across Monzo to solve complex security problems and strengthen risk management as the company grows. The role balances security protection with user experience, creating opportunities for innovation.
Key responsibilities include:
- Delivering third-party and supplier security assurance: assess new and existing suppliers by reviewing questionnaires, certifications, and security evidence; identify risks, translate technical findings into recommendations, and manage them throughout the supplier lifecycle.
- Conducting security assurance activities: lead and contribute to control testing, PCI DSS assessments, regulatory reviews, and internal/external audits; evaluate evidence, identify gaps, and drive remediation.
- Strengthening governance: improve security policies, procedures, and controls to be practical, proportionate, and reflective of real-world operations.
- Supporting the Security Front Door: respond to security questions and requests from across Monzo, escalating to specialists as needed.
- Taking ownership: turn loosely defined security problems into clear outcomes and coordinate the right people to execute.
- Helping teams build safely: work with engineers and product teams to understand objectives, review new products/technology/business changes, identify security risks and control gaps, and translate requirements into practical implementation.
- Improving processes: use data, automation, and AI to make processes simpler and more scalable.
- Raising the bar: bring fresh perspectives to security challenges, develop your own skills, and mentor less experienced analysts.
Requirements:
- Understand security risk: comfortable identifying and assessing security risks and recommending proportionate mitigation strategies. Experience in third-party or supplier security assurance is a bonus.
- Evaluate security evidence: able to review supplier questionnaires, security policies, penetration test reports, and assurance evidence; know when to dig deeper.
- Strong security fundamentals and technical curiosity: understand core security concepts and best practices; comfortable with technical detail; ask thoughtful questions.
- Think strategically: look for patterns and root causes; use evidence and data to prioritize; seek ways to improve processes.
- Proactive: make progress independently, seek information, and challenge assumptions constructively.
- Manage competing priorities: juggle multiple workstreams, keep stakeholders informed, and make sound escalation decisions.
- Clear communicator: explain security risks and recommendations to technical and non-technical audiences.
- Collaborative: enjoy working across disciplines, build strong relationships, and make security easier to execute well.
- Passionate about security: excited by cyber security challenges and opportunities; stay current with industry evolution; motivated to develop knowledge and skills.
Nice-to-have:
- Experience in financial services, fintech, or other highly regulated environments.
- Support for PCI DSS, ISO 27001, SOC 2, or NIST-aligned assurance, regulatory reviews, or internal/external audits.