
Metropolis · Los Angeles, California, United States
WHO WE ARE The real world is the next frontier, and at Metropolis, we are creating the artificial intelligence to make it responsive. We are pioneering the Rec...
The real world is the next frontier, and at Metropolis, we are creating the artificial intelligence to make it responsive. We are
pioneering the Recognition Economy — a future where mundane repetition disappears and being known unlocks access, comfort and
belonging everywhere you go. From transforming parking into a seamless drive-in, drive-out experience for millions of Members to
expanding our intelligence layer across retail and hospitality, we are building a world that feels instinctive and magical. The
future isn’t coming; it’s here, and we need builders, innovators and problem solvers to help us create it.
Metropolis is seeking a Governance, Risk, and Compliance (GRC) Analyst to join our expanding Security team. Reporting to the
Senior Manager, GRC, you will mature information security policies, drive employee security awareness, and pioneer our AI
governance framework. You will partner across Technology, Legal, Internal Audit, Procurement, and People Operations to safeguard
customer trust and support operational excellence.
4 Days in Office: Metropolis values in-person collaboration to drive innovation, strengthen culture, and enhance the Member
experience. Our corporate team members hold to our office-first model, which requires employees to be on-site at least four days a
week, fostering organic interactions that spark creativity and connection
When you join Metropolis, you'll join a team of world-class product leaders and engineers, building an ecosystem of technologies
at the intersection of parking, mobility, and real estate. Our goal is to build an inclusive culture where everyone has a voice
and the best idea wins. You will play a key role in building and maintaining this culture as our organization grows. The
anticipated base salary for this position is $100,000.00 USD to $135,000.00 USD annually. The actual base salary offered is
determined by a number of variables, including, as appropriate, the applicant's qualifications for the position, years of relevant
experience, distinctive skills, level of education attained, certifications or other professional licenses held, and the location
of residence and/or place of employment. Base salary is one component of Metropolis’s total compensation package, which may also
include access to or eligibility for healthcare benefits, a 401(k) plan, short-term and long-term disability coverage, basic life
insurance, a lucrative stock option plan, bonus plans and more. #LI-CM1 #LI-Onsite
Metropolis may utilize an automated employment decision tool (AEDT) to assess or evaluate your candidacy for employment or
promotion. AEDTs are used to assist in assessing a candidate’s application relative to the required job qualifications and
responsibilities listed in the job posting.
As part of this process, Metropolis retains data relevant to your candidacy, including personal information, for a period that is
reasonably necessary for the use of the tool. If you are hired for the position, your data may become part of your employee
records.
Metropolis Technologies is an equal opportunity employer. We make all hiring decisions based on merit, qualifications, and
business needs, without regard to race, color, religion, sex (including gender identity, sexual orientation, or pregnancy),
national origin, disability, veteran status, or any other protected characteristic under federal, state, or local law.
ABOUT VERCEL: Vercel is the agentic infrastructure company. We free people and agents to ship what’s next. For more than a decade, Vercel has shaped how the web is built. As the team behind Next.js, v0, and AI SDK, we create products that help builders move from idea to production with speed, security, and exceptional developer experience. Now, software is entering a new era, and the next generation of products will not just be used by people. They will be built, extended, and operated by agents. We are building the platform for that future, trusted by companies like OpenAI, PayPal, Ramp, Supreme, and millions of developers worldwide. Whether you’re building our products, supporting our customers, growing our community, or shaping our story, you’ll help define what comes next. ABOUT THE ROLE: We are looking for a GRC Analyst to join our Governance, Risk & Compliance (GRC) team. You will have the opportunity to manage and maintain ongoing compliance with security and privacy frameworks, policies, procedures, and commercial assessments, including ISO 27001, SOC 2, HIPAA, PCI DSS, and more. Your role will be instrumental in ensuring that our company operates ethically, responsibly, and in accordance with regulatory requirements. You will collaborate with cross-functional teams to promote a culture of accountability and integrity throughout the organization and foster an environment where everyone understands the importance of adhering to established guidelines and ethical practices. You will report to the Head of GRC and will be located ((remote, onsite, hybrid)). Think you may not have all the skills and are hesitant to apply? There is no “perfect” candidate and encourage you to apply if you think that you can bring value to our team and are passionate and committed to upholding the highest standards of compliance and ethics. If you’re based within a pre-determined commuting distance of one of our offices (SF, NY, London, or Berlin), the role includes in-office anchor days on Monday, Tuesday, and Friday, even if the role is listed as remote. For location-specific details, please connect with our recruiting team. WHAT YOU WILL DO: * Collaborate with internal teams to maintain an effective suite of internal controls and driving remediation efforts to completion with clear documentation of progress. * Build strong working relationships across the business so compliance accountability is shared and stakeholders are informed. * Streamline annual audits by managing audit deliverables, developing treatment plans, and coordinating across teams to document and track completion to ensure audit success. * Monitor and improve controls, processes, and evidence management practices, identify opportunities to automate and streamline GRC operations, and contribute to controls maturity scoring and reporting * Enable go-to-market teams and accelerate deal cycles by supporting security questionnaires, addressing compliance inquiries, and maintaining clear, customer-facing documentation on Vercel’s security and compliance posture. * Design and manage company training and enhance visibility on compliance-specific topics for internal stakeholders to ensure an understanding of compliance, ethics, and regulatory requirements within the organization. ABOUT YOU: * At least 3 years of relevant experience in supporting the audit lifecycle in a cloud-centric environment (SOC 2, ISO 27001, PCI, HIPAA, etc.), with strong organizational skills to be flexible and proactive in a high-growth, start-up environment. * Experience collaborating closely with internal partners to seamlessly incorporate policies and technical controls into the SDLC. * Strong project management skills and sense of ownership with the ability to communicate and collaborate effectively, and execute projects across various business units and levels. BONUS IF YOU HAVE : * Strong experience with cloud infrastructure (e.g., Azure, AWS) * Familiarity with compliance or software development tools and systems (e.g., Drata, Linear, Datadog, etc.) * Experience with frontend development and open source components * Relevant industry certifications (i.e., CISM, CISSP, CCEP) is a plus, but not required BENEFITS: * Competitive compensation package, including equity. * Inclusive Healthcare Package. * Learn and Grow - we provide mentorship and send you to events that help you build your network and skills. * Flexible Time Off. * We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed. The San Francisco, CA base pay range for this role is $134,000-$202,000. Actual salary will be based on job-related skills, experience, and location. Compensation outside of San Francisco may be adjusted based on employee location. The total compensation package may include benefits, equity-based compensation, and eligibility for a company bonus or variable pay program depending on the role. Your recruiter can share more details during the hiring process.
ABOUT LENDABLE Lendable is on a mission to build the world's best technology to help people get credit and save money. We're building one of the world’s leading fintech companies and are off to a strong start: * One of the UK’s newest unicorns with a team of just over 700 people * Among the fastest-growing tech companies in the UK * Profitable since 2017 * Backed by top investors including Balderton Capital and Goldman Sachs * Loved by customers with the best reviews in the market (4.9 across 10,000s of reviews on Trustpilot) So far, we’ve rebuilt the Big Three consumer finance products from scratch: loans, credit cards and car finance. We get money into our customers’ hands in minutes instead of days. We’re growing fast, and there’s a lot more to do: we’re going after the two biggest Western markets (UK and US) where trillions worth of financial products are held by big banks with dated systems and painful processes. JOIN US IF YOU WANT TO 1. Take ownership across a broad remit. You are trusted to make decisions that drive a material impact on the direction and success of Lendable from day 1 2. Work in small teams of exceptional people, who are relentlessly resourceful to solve problems and find smarter solutions than the status quo 3. Build the best technology in-house, using new data sources, machine learning and AI to make machines do the heavy lifting ABOUT THE ROLE We are looking for a proactive Security GRC Analyst to join our Information Security team. You will play a pivotal role in scaling our security posture in a fast-paced, AI driven, cloud-native environment. You will be part of a growing team, where your voice will be heard, and your ability to take ownership and drive initiative will directly shape our security culture and operational resilience. Your approach to GRC starts with the risk, not the checklist. Rather than chasing compliance for its own sake, you will identify and assess the risks first, then collaborate with stakeholders to design pragmatic mitigations. You understand that compliance doesn't drive the business; rather, it is the natural outcome of a mature security posture that actively works for the organisation. WHAT YOU’LL BE DOING * Framework & Regulatory Alignment: Help maintain, improve, and scale our security compliance programmes, ensuring ongoing alignment with standards such as SOC 2, ISO 27001, and PCI-DSS, as well as regulator expectations and UK GDPR. * Risk & Mitigation: Collaborate on identifying security risks across the business - including emerging risks from AI-driven and agentic threats - and support the team in driving practical, risk-first mitigation strategies. * Compliance Automation: Utilise our security compliance platform (e.g., Vanta/Drata) to orchestrate automated evidence collection, reducing manual overhead and moving the company toward a state of continuous audit readiness. * Third-Party Risk Management (TPRM): Conduct vendor and third-party security risk assessments to evaluate the security posture of partners and critical outsourced service providers. * Translating Risk & Governance: Work with the team to bridge the gap between engineering and business governance by turning technical security metrics into clear, risk-based narratives for internal stakeholders and external auditors. * Security Culture & Awareness: Support the delivery and promotion of security awareness initiatives to help drive a strong culture of shared security responsibility across the organisation. * Technical Collaboration: Actively engage in conversations with engineers, developers, and IT teams - understanding their technical language and workflows to help align security controls with engineering realities. * Audit & Assessment Support: Participate in external audits and assessments by gathering evidence, preparing documentation, and helping to ensure a smooth, successful audit cycle. WHAT YOU WILL BRING Essential: * Experience: 5+ years of experience in a related role (ideally within a regulated, cloud-native business or FinTech). * Compliance & Risk Expertise: A strong, foundational understanding of security risk management principles and hands-on experience working with compliance frameworks (e.g. ISO 27001, PCI-DSS, or SOC 2). * Risk-First & Pragmatic Mindset: A natural tendency to start with the "why" (the risk) rather than the checklist. You possess the ability to balance strict financial regulations with the operational agility of a fast-paced FinTech, ensuring security controls protect the business without slowing it down. * Communication & Collaboration: Outstanding communication skills with a proven ability to comfortably converse with technical stakeholders, understand their challenges, and translate them into business risks. * Drive & Initiative: A highly proactive and self-motivated mindset - someone who actively looks for ways to improve our security posture and drive change. Deisrable: * Tooling: Direct, practical experience working with modern security compliance and automation platforms (such as Vanta or Drata). * Programming and automation: Experience with Python or a similar programming/scripting language, and/or using AI to improve productivity through automation. INTERVIEW PROCESS 1. Initial Chat all with a Recruiter 2. 15 minute Cognitive Assessment 3. 30 minute Hiring Manager call 4. 60 minute Technical Interview 5. 60 Culture-Add Interview LIFE AT LENDABLE * Winning team: the opportunity to scale up one of the world’s most successful fintech companies * Flexible working: flexible approach tailored to each role. Hybrid roles require three days in-office weekly; fully remote roles include regular opportunities for in-person connection through socials and off-sites * Socials & connection: opportunities and events to come together, socialise, and get to know each other beyond the office walls * Health coverage: support for your physical and mental wellbeing, including private health cover * Retirement & savings: long-term financial wellbeing through retirement savings plans * Employee referral programme: earn a competitive bonus when you refer successful new team members * Office meals & snacks: enjoy a fully stocked kitchen, plus complimentary lunches prepared by in-house chefs on in-office days at select locations * Sustainable commuting: cycle-to-work and electric vehicle salary sacrifice schemes available in select locations Please note: The availability and details of specific benefits vary by location and role. For more information, please speak to your Talent Partner. Check out our blog!
WHO WE ARE ABOUT STRIPE Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career. ABOUT THE TEAM Bridge Building S.A. (BBSA) is the Luxembourg regulated entity of Bridge, a Stripe company. We operate as an EMI and future CASP in one of Europe's most demanding regulatory environments (CSSF, DORA, MiCA). BBSA is building a local regulated platform powered by a global-first technology model. WHAT YOU'LL DO In this context, we're looking for an IT GRC Analyst to act as the bridge between strict European regulations and high-velocity global engineering. This role is the control and risk right hand of the Bridge Global CISO. While our global teams build the tech, you ensure it is compliant, resilient, and audit-ready. You'll translate requirements like DORA and MiCA into tangible IT controls, oversee third-party risks, and maintain the integrity of our governance framework. This is not a tick-the-box compliance role. It is an operational position for a professional who understands technology well enough to govern it effectively. You'll have high visibility, owning the frameworks that allow us to scale securely. RESPONSIBILITIES IT governance and risk management • Maintain and evolve the IT Risk Register, ensuring risks are identified, assessed, and treated in line with the company's risk appetite. • Drive the local implementation of the DORA (Digital Operational Resilience Act) framework, including ICT risk management and incident classification. • Bridge the gap between technical reality and policy by drafting, reviewing, and updating IT policies and procedures. • Perform periodic control testing to ensure global engineering practices align with local regulatory requirements. • Act as the primary support to the local Head of IT. Third-party risk management (TPRM) • Support ICT due diligence and risk assessments of critical vendors and service providers, while assisting with Developer and Customer Oversight. • Monitor service level agreements and performance metrics of critical vendors, challenging performance where necessary. • Act as the primary support to the outsourcing manager regarding technical vendor oversight. Access governance and control (IAG) • Oversee the identity and access governance strategy, including adherence to Segregation of Duties, principle of least privilege, and others. • Conduct periodic user access reviews for critical systems. Regulatory compliance and audit readiness • Act as the primary liaison for internal audit regarding IT topics. • Prepare technical inputs and evidence for CSSF notifications and regulatory reporting. • Monitor compliance with GDPR and data privacy controls (e.g., DLP oversight, data residency). • Coordinate business continuity (BCP) and disaster recovery (DR) testing documentation and reporting. Incident governance • Oversee the IT incident management process to ensure proper classification, reporting, and root cause analysis (RCA). • Ensure major incidents are reported to regulators within mandated timeframes, in collaboration with Compliance. WHO YOU ARE MINIMUM REQUIREMENTS * Bachelor's or Master's degree in Information Systems, Cybersecurity, or Business Administration, with a strong IT focus. * 3–6 years of experience in IT audit, IT risk, GRC, or information security. • High professional fluency in English. PREFERRED QUALIFICATIONS * Experience in a regulated sector (Banking, Fintech, or Insurance). * Experience at a large-scale public accounting firm in IT risk advisory. * Experience with CSSF circulars, EBA guidelines, or DORA. * Strong understanding of ISO 27001, NIST, or COBIT. * Understanding of cloud fundamentals (AWS).