GRC Analyst - Mesh

Remote $130k–$175k 2 months ago full-time quality 7.8/10

Role in brief

Mesh is building infrastructure for crypto payments, aiming to make tokenized assets usable for commerce. This GRC Analyst role involves managing and strengthening compliance programs, including SOC 2 and NIST, and developing business continuity plans. It suits someone with hands-on GRC experience in regulated environments who can build scalable processes and manage risk.

About the role

This role focuses on developing and maintaining Mesh's governance, risk, and compliance framework. The work includes owning and strengthening the controls environment, managing SOC 2 operations, and aligning with security frameworks like NIST. A key part of the job involves building and maturing Business Continuity and Disaster Recovery programs, which includes creating business impact assessments and recovery runbooks.

The GRC Analyst will also conduct vendor and third-party risk assessments as Mesh expands its network. The position involves supporting licensing applications, such as MiCA and U.S. Money Transmitter Licenses, through due diligence, regulatory responses, and compliance reporting. Managing the security issue lifecycle and driving remediation efforts are also core responsibilities.

Success in this position means standardizing policies, controls, and compliance processes that can scale across various jurisdictions and regulatory frameworks. The ideal candidate is a hands-on builder who enjoys improving processes and operationalizing controls, turning requirements into scalable programs. Regular use of AI tools to enhance efficiency in areas like policy development and program management is also expected.

The annual salary for this position ranges from $130,000 to $175,000 USD.

Skills that matter here

  • SOC 2: This role involves supporting and maturing SOC 2 operations within the GRC program.
  • NIST: The GRC Analyst will align compliance efforts with security frameworks such as NIST.
  • MiCA: The role supports MiCA licensing applications through due diligence and regulatory responses.
  • Business Continuity and Disaster Recovery programs: A core responsibility is to build and maintain these programs, including BIAs and recovery runbooks.
  • AI tools: Candidates should regularly use AI tools to increase efficiency in policy development, process monitoring, or program management.
  • GRC platforms (Vanta, Drata, Archer): Familiarity with these platforms is a plus for managing compliance programs.

Who this role suits

  • Someone with 3-5 years of direct GRC experience in an operational setting, specifically building and managing compliance programs.
  • A person who is comfortable supporting the entire risk lifecycle, from assessments to issue management and remediation.
  • An individual who enjoys a hands-on approach to improving processes and operationalizing controls to create scalable programs.
  • A professional who has experience in fintech, crypto, payments, or other regulated industries.

From the employer

What You'll Do

  • Own and strengthen our controls environment, ensuring compliance requirements are effectively implemented and maintained.
  • Support and mature our GRC program, including SOC 2 operations and alignment with broader security frameworks such as NIST.
  • Build and maintain our Business Continuity and Disaster Recovery program, including BIAs, continuity plans, and recovery runbooks.
  • Conduct vendor and third-party risk assessments as we expand our global network of partners.
  • Support MiCA licensing and U.S. Money Transmitter License applications through due diligence, regulatory responses, and compliance reporting.
  • Manage the security issue lifecycle, driving remediation efforts and partnering with teams to reduce risk.
  • Help standardize policies, controls, and compliance processes that can scale across jurisdictions and regulatory frameworks.

Who You Are

  • 3–5 years of hands-on GRC experience in an operating environment, with a track record of building and managing compliance programs—not just auditing them.
  • Deep familiarity with one or more major frameworks, such as SOC 2, NIST, PCI, MiCA, NYDFS, or CCPA.
  • Experience building or maturing Business Continuity and Disaster Recovery programs, with a strong understanding of how business impact assessments inform recovery strategies.
  • Comfortable supporting the full risk lifecycle, including risk assessments, control testing, issue management, and remediation.
  • A hands-on builder who enjoys improving processes, operationalizing controls, and turning requirements into scalable programs.
  • Regularly uses AI tools to increase efficiency and improve outcomes across areas such as policy development, process monitoring, or program management.
  • Experience in fintech, crypto, payments, or other regulated industries is a plus, as is familiarity with GRC platforms such as Vanta, Drata, or Archer.

Why You’ll Love It Here

  • Competitive salary and equity that grows as you and the company grow.
  • Comprehensive health coverage for you and your family.
  • Unlimited PTO—and we mean it. Take the time you need to recharge and show up at your best.
  • Dedicated budget for courses, conferences, and certifications.
  • Remote-friendly approach with top-tier tools and equipment.

Questions about this role

What is the remote work policy for this role?

This is a remote-friendly position, and the company provides top-tier tools and equipment for remote work.

What specific experience is required for this role?

Candidates need 3-5 years of hands-on GRC experience, deep familiarity with major frameworks like SOC 2 or NIST, and experience building Business Continuity and Disaster Recovery programs.

How do I apply for this position?

The provided job description does not include specific application instructions or a link. Candidates should likely visit the company's website or a relevant job board to apply.

Similar jobs

Before you apply

  • Legitimate employers never ask you to pay anything to apply or get hired.
  • Never share seed phrases or private keys. No real job needs them.
  • Do not install software ("test tasks", "trading tools", "video call clients") sent during hiring.
  • Check that the application page's domain really belongs to Mesh.