MonzoFound on the web

Posted 3w ago

Senior Security Analyst

Pay

GBP 57,000–70,000

Location

Cardiff, London or Remote (UK)

Remote

Skills this role screens for

securitytestingai/mlautomationcustomer servicesocial mediaprocurementinformation security

Opens on Monzo's site. Sign in first and we keep it in your pipeline.

About the role

🚀 We’re on a mission to make money work for everyone.

We’re waving goodbye to the complicated and confusing ways of traditional banking.

After starting as a prepaid card, our product offering has grown a lot in the last 10 years in the UK. As well as personal and business bank accounts, we offer joint accounts, accounts for 16-17 year olds, a free kids account and credit cards in the UK, with more exciting things to come beyond. Our UK customers can also save, invest and combine their pensions with us.

With our hot coral cards and get-paid-early feature, combined with financial education on social media and our award winning customer service, we have a long history of creating magical moments for our customers!

We’re not about selling products - we want to solve problems and change lives through Monzo ❤️

📍London/Cardiff/UK Remote | 💰£57,000 - £70,000 + Incentive Awards tied to your performance + Benefits ✨

At Monzo our mission is to make money work for everyone. Central to this is making sure the bank is safe and secure for our customers. We’re always keen to hear from people who believe in our mission and want to join us on this journey.

We’re looking for a proactive, curious, technically-minded and organised Senior Security Analyst to join Monzo's Security team.

Our team is Monzo’s front door to Security, helping the whole business operate securely. This means you’ll get exposure to a wide range of business context and a broad mix of information security work. One day you might be assessing the security of a new supplier; the next you could be supporting an audit or assurance review, assessing the risks of a new product or technology change, updating a policy, or helping a team turn regulatory requirements into practical action.

You’ll work closely with security specialists, engineers, product teams, third party risk, procurement, and colleagues from across Monzo to solve interesting problems and strengthen how we effectively manage security risk as we grow.

We want security to protect Monzo without creating unnecessary friction or compromising user experience. You’ll have the opportunity to make a notable impact in an environment where security is both a priority and an opportunity for innovation!

The work

You’ll play a key role by

  • Delivering third party security and supplier security assurance: assess new and existing suppliers, reviewing questionnaires, certifications, and other evidence to understand their security posture. Use your judgement to identify risks, translate technical findings into recommendations, and work with teams across Monzo to manage them throughout the supplier lifecycle. Help us build a more effective, scalable and industry-leading third party security capability as Monzo grows!
  • Delivering security assurance activities: lead and contribute to control testing, PCI DSS assessments, regulatory reviews, and internal and external audits. Evaluate evidence, identify gaps and work with teams across Monzo to see findings and remediation through to completion.
  • Strengthening our governance: improve security policies, procedures and controls so they’re practical, proportionate, and reflect how things work in reality.
  • Supporting our Security Front Door: work alongside our other analysts to respond to security questions and requests from across Monzo, bringing in specialists when needed and finding ways to make the experience better for other Monzonauts.
  • Taking ownership and running with it: turn loosely defined security problems into clear outcomes, work out the best way forward, and bring in the right people to make it happen.
  • Helping teams build and change safely: work with engineers, product teams and other colleagues to understand what they’re trying to achieve. Review new products and technology or business changes, identify security risks and control gaps, and turn security and regulatory expectations into requirements that work in practice.
  • Improving how we work: use data, automation and AI to make our processes simpler and more scalable, while exploring new ways technology can help us work smarter.
  • Raising the bar for security: bring fresh perspectives to real-world security challenges, keep developing your own skills and knowledge, and help less experienced analysts grow.

Who they want

We’d love to hear from you if

  • You understand security risk: you’re comfortable identifying and assessing security risks, and can recommend proportionate ways to manage them. Experience in third party security or supplier security assurance would be a bonus!
  • You can evaluate security evidence: you can review supplier questionnaires, security policies, penetration test reports and assurance evidence, and know when to dig deeper.
  • You have strong security fundamentals and technical curiosity: you understand core security concepts and good practice, are comfortable getting into technical detail, and ask thoughtful questions to get to the heart of a problem.
  • You think beyond the task in front of you: you look for patterns and root causes, use evidence and data to prioritise and look for ways to make things work better.
  • You’re proactive: you can make progress independently, seek out the information you need, and are comfortable challenging assumptions to move things forward.
  • You can manage competing priorities: you can juggle different pieces of work, keep people informed, and make sensible decisions about what needs attention or escalation.
  • You’re a clear communicator: you can explain security risks and recommendations to technical and non-technical audiences in a way that works for them.
  • You enjoy collaborating: you like working with people across different disciplines, building strong relationships, and helping make security easier to do well.
  • You’re passionate about security: you’re excited by the challenges and opportunities in cyber security, keep up with an evolving industry, and are motivated to continue developing your knowledge and skills.

Also

It would be great if

Not ticking every box? That’s totally okay! Studies show that women and people of colour might hesitate to apply unless they meet every single requirement. At Monzo, we’re dedicated to creating a diverse and welcoming team. If you’re passionate about this role and keen to learn and grow with us, we encourage you to apply— even if you don’t have everything that's listed just yet. Drop us your application, we’d love to hear from you!

  • You’ve worked in financial services, fintech, or another highly regulated environment.
  • You’ve supported PCI DSS, ISO 27001, SOC 2 or NIST-aligned assurance, regulatory reviews, or internal and external audits.

What you get

What’s in it for you

  • £57,000 - £70,000 ➕Incentive Awards tied to your performance.
  • This role can be based in our London office, but we're open to distributed working within the UK (with ad hoc meetings in London)
  • We offer flexible working hours and trust you to work enough hours to do your job well, and at times that suit you and your team.
  • £1,000 learning budget each year to use on books, training courses and conferences.
  • We will set you up to work from home; all employees are given Macbooks and for fully remote workers we will provide extra support for your work-from-home setup.
  • Plus lots more! Read our full list of benefits.

Also

The application journey has 3 key steps

This process should take around 4-5 weeks - your schedule is really important to us, so we promise to be as flexible as possible!

We have some guidelines on using Artificial Intelligence (AI) to ace an application and interview at Monzo. You can read them here.

We’ll only close this role once we have enough applications for the next stage. Please submit your application as soon as possible to make sure you don’t miss out.…

  • Intro call with the recruiter
  • 30 min call with the hiring manager
  • 2 hours of technical and behavioural interviews

Monzo

Found on the web. You apply on the company's own site

Where this listing comes from

From Monzo's own careers system (Greenhouse).

insiderOne never charges students to apply. Never pay anyone for an internship. Check an offer you received

Prove Security first

This role screens for Security. Sit a ten-minute live challenge, get a signed receipt, and the employer sees it verified on your application instead of claimed.

Prove it, then apply

Ask about this role

SCOUT, an AI agent, not a person, answers from this ad, and says so when the ad doesn't cover it. No account, and nothing you type here is kept.

More security roles

Every security role here

insiderOne University

Cybersecurity Fundamentals Associate certification opens November 2026

Free, built for roles like this one, with a certificate employers can check. The ones most asked for open first.

Tell me when it opens

Interned at Monzo? Report what it paid

From the Wire Desk