Security Risk Governance Analyst

Chime

San Francisco (CA)

On-site

USD 105,000 - 145,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Bonus
Equity

Job summary

Chime is hiring a Security Risk Governance Analyst to strengthen how we identify, assess, and manage risk across our third-party ecosystem and internal controls. You will collaborate with Security, Risk, Compliance, Engineering, and Infra Security to close gaps and move assessments to closure.

The role advances through vendor reviews, risk assessments, and controls testing, with opportunities to contribute to SOX, PCI DSS, SOC 2, and ISO 27001 programs.

Qualifications

  • 2-4 years of experience in security, IT audit, risk, or compliance, or equivalent in a regulated environment.
  • Hands-on experience with third-party security reviews, risk assessments, or controls testing.
  • Experience with information security, security risk, and/or security program management.
  • Familiarity with security frameworks such as SOX, SOC 2, NIST, ISO 27001, PCI DSS.
  • Experience documenting security procedures, processes, standards, and runbooks.

Responsibilities

  • Run third‑party security reviews end to end: due diligence, evidence collection, vendor interviews, and monitoring.
  • Support SOX ITGC, PCI DSS, SOC 2, and ISO 27001 programs with audit prep and coordination.
  • Conduct risk assessments, gap analyses, and controls testing; document findings and track remediation.
  • Run quarterly user access reviews for applicable frameworks; manage builds, revocation, and evidence retention.
  • Define and maintain security KPIs, KRIs, and leadership dashboards.

Skills

Security risk
Third-party reviews
Risk assessments
Controls testing
SOX
SOC 2
ISO 27001

Tools

ConductorOne
Vulnerability management tools

Job description

About the role

We're hiring a Security Risk Governance Analyst to help strengthen how Chime identifies, assesses, and manages security risk across our third‑party ecosystem and internal control environment. You'll work across vendor security reviews, risk assessments, controls testing, and key compliance initiatives, while helping turn security requirements into clear, repeatable processes. You'll partner closely with teams across Security, Risk, Compliance, Engineering, Application Security, and Infrastructure Security to identify gaps, manage risk, and move assessments through to completion. You'll work alongside Senior Analysts who hold risk coverage for Chime's business domains, taking secondary coverage for one of them as you build depth. This role is a strong fit for someone building a security risk career who is organized, curious, and follows an assessment through to a documented decision.

The base salary offered for this role and level of experience will begin at $105,000.00 and up to $145,000.00. Full‑time employees are also eligible for a bonus, competitive equity package, and benefits. The actual base salary offered may be higher, depending on your location, skills, qualifications, and experience.

In this role, you can expect to
  • Run third‑party security reviews end to end: due diligence assessments, evidence collection, vendor interviews, and ongoing monitoring.
  • Support SOX IT General Controls, PCI DSS, SOC 2, and ISO 27001 programs with audit preparation, evidence collection, and walkthrough coordination.
  • Conduct risk assessments, gap analyses, and controls testing, including reviews of new tools, AI systems, and new lines of business arriving through Security intake. Record findings, remediation owners, and risk exceptions in the SRG risk register and track them to closure.
  • Run quarterly user access reviews for applications in scope for SOX, SOC 2, PCI, and ISO 27001, including population builds in ConductorOne, reviewer follow‑up, revocation and lookback handling, and evidence retention.
  • Help define and maintain security KPIs, KRIs, and dashboards that give leadership clear visibility into risk and program performance.
  • Develop or source security training content and support delivery to employees and contractors through a learning management system.
  • Create and maintain operational runbooks, security baselines, and standards, and work with SRG engineering to move manual evidence collection into automated workflows.
  • Move Security Architecture Reviews through the process with Security Engineering, Application Security, and Infrastructure Security, and help document the steps as they stabilize.
To thrive in this role, you have
  • 2-4 years of experience in security, IT audit, risk, or compliance, or equivalent experience in a regulated environment.
  • Hands‑on experience with at least one of: third‑party security reviews, risk assessments, or controls testing.
  • Professional experience focused on information security, security risk, and/or security program management.
  • Experience using vulnerability management tooling and managing security risk exceptions through their lifecycle.
  • Working knowledge of security and compliance frameworks such as SOX, SOC 2, NIST 800‑series or NIST Cybersecurity Framework, ISO 27001, and PCI DSS.
  • Experience documenting security procedures, operational processes, standards, and runbooks.
  • Evidence of driving work to closure through people you don't manage: chasing owners, unblocking, and escalating when it stalls.
  • Comfort working without a fully defined path, and a habit of raising problems early with a proposed next step.
  • Progress toward a security or audit certification such as CISA, CRISC, or Security+ is a plus. We support analysts in earning them.
  • Experience working with AWS, GitHub, and/or GCP is a plus.
A little about us

At Chime, we believe that everyone can achieve financial progress. We created Chime-a financial technology company, not a bank*-on the premise that core banking services should be helpful, easy, and free. Through our user‑friendly tools and intuitive platforms, we empower our members to take control of their finances and work towards their goals. Whether it's starting a savings account, purchasing a first car or home, launching a business, or pursuing higher education, we're proud to have helped millions unlock their financial potential.

We're a team of problem solvers, dreamers, and builders with one shared obsession: our members. From day one, Chimers have worked tirelessly to out‑hustle and out‑execute competitors to bring our mission to life. Their grit and determination inspire us to work harder every day to deliver the very best experience possible. We each bring an owner's mindset to our work, refusing to be outdone and holding ourselves accountable to meet and exceed the highest bars for our teams, our company, and our members.

We believe in being bold, dreaming big, and taking risks, while also working

#LI-Onsite #LI-TP1

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Risk Governance Analyst
Security Risk Governance Analyst

RiseMe • San Francisco (CA)

On-site
USD 105,000 - 145,000
Bonus
Equity package
Benefits
Senior Business Analyst, TPRM
Senior Business Analyst, TPRM

Chime Financial, Inc • San Francisco (CA)

On-site
USD 105,000 - 145,000
Health benefits
Parental leave
Wellness stipend
+1
Senior Business Analyst, TPRM New San Francisco, CA, USA
Senior Business Analyst, TPRM New San Francisco, CA, USA

Chime Enterprise • San Francisco (CA), Northern (KY)

On-site
USD 105,000 - 145,000
Bonus eligible
Equity package
Benefits
Senior Business Analyst, TPRM
Senior Business Analyst, TPRM

Chime • San Francisco (CA)

On-site
USD 105,000 - 145,000
Bonus eligibility
Equity package
Benefits
Business Control Manager
Business Control Manager

Menlo Ventures • San Francisco (CA)

Hybrid
USD 101,000 - 140,000
In-office policy
Wellbeing benefits
Parental leave
+2
Lead Analyst, Financial Crimes
Lead Analyst, Financial Crimes

Chime • Chicago (IL)

On-site
USD 139,000 - 193,000
Lead Analyst, Financial Crimes New San Francisco, CA, USA
Lead Analyst, Financial Crimes New San Francisco, CA, USA

Chime Enterprise • San Francisco (CA), Northern (KY)

On-site
USD 139,000 - 193,000
Health benefits
Equity package
On-site office in San Francisco
+1
Senior Security Engineer New York, NY, USA; San Francisco, CA, USA
Senior Security Engineer New York, NY, USA; San Francisco, CA, USA

Chime • New York (NY)

On-site
USD 130,000 - 250,000
401(k) match
Generous vacation policy
Annual wellness stipend
+3
Business Control Manager
Business Control Manager

Chime • San Francisco (CA)

On-site
USD 101,000 - 140,000
In-office four days a week with Friday
Fridays from home for some locations
Backup care for child, elder, and pet
+1
Lead Analyst, Financial Crimes
Lead Analyst, Financial Crimes

Chime Financial, Inc • San Francisco (CA)

On-site
USD 139,000 - 193,000
Bonus
Equity
Benefits