- As a Senior Business Analyst, TPRM, you will support the assessment and ongoing oversight of third party relationships, including vendors and partners, throughout the third party risk management lifecycle
- You will assess third party risk, conduct business due diligence, and coordinate additional risk assessments with cross-functional partners. You will help ensure risks are appropriately identified, documented, and addressed while working closely with business owners, risk partners, and Chime’s bank partners
- You will serve as a trusted partner to the business while contributing to the continued development and maturity of Chime’s TPRM program
- Review and challenge Inherent Risk Questionnaires (IRQs), working with business owners to understand vendor relationships, validate information, and determine appropriate inherent risk and criticality ratings
- Coordinate due diligence activities with cross-functional risk partners and subject matter experts across areas such as Information Security, Privacy, Compliance, Enterprise Risk Management, and Legal
- Conduct business due diligence, including reviews of corporate registration, reputational information, insurance coverage, and other relevant documentation, and coordinate additional activities such as background checks
- Manage assigned third party assessments through completion, coordinating with business owners and cross-functional risk partners to address questions, follow up on outstanding requirements, and elevate concerns as appropriate
- Facilitate vendor approval processes with Chime’s bank partners, including coordinating assessment information, responding to follow-up requests, and tracking approvals through completion
- Identify and document issues arising from TPRM assessments and partner with relevant stakeholders to track third party risk issues and remediation activities through resolution
- Support ongoing monitoring and periodic reassessments of third party relationships, including reviewing changes that may impact the inherent risk rating, criticality rating, or due diligence requirements
- Clearly document TPRM assessments, risk decisions, and supporting rationale in accordance with program requirements
- Provide guidance to business owners and stakeholders on TPRM requirements, processes, and expectations
- Contribute to the continued development and maturity of the TPRM program through process improvements, tooling enhancements, reporting, and updates to policies, procedures, standards, and supporting documentation
- Support internal audits, regulatory examinations, bank partner oversight, and other program activities as needed
Benefits
- Physical: We believe in taking care of your physical health, so as a Chimer you’ll get medical, dental, and vision insurance, as well as benefits to support your physical activity, family planning, and all of your little Chimers
- Emotional: We know that staying healthy involves a lot more than doctor’s checkups. We partner with Modern Health to help you navigate your mental health, give monthly Take Care of Yourself Days, and want you to take time off when you need it
- Financial: We want Chimers to save and feel financially supported, so we offer savings plans with competitive matching, as well as access to financial planning and legal assistance so that you can find your financial peace of mind
- Social: We’ll celebrate your milestones together with travel stipends, swag, and high-fives and make sure you’re connected to fellow Chimers through our Chime Resource Groups (CRGs) and company events
This role requires strong analytical judgment, attention to detail, and the ability to manage multiple assessments and stakeholdersFamiliarity with regulatory expectations and industry practices for third party risk management, including applicable interagency guidance4+ years of experience in Third Party Risk Management, Vendor Risk Management, Operational Risk, Compliance, Audit, or a related risk management functionStrong stakeholder management and communication skills, with experience working across business owners, risk and control functions, and cross-functional teamsFamiliarity with Third Party Risk Management platforms, workflow tools, and reporting solutions is a plusExperience contributing to risk program initiatives such as process improvement, policy and procedure development, tooling enhancements, reporting, audit support, or similar activitiesExperience in financial services, fintech, banking, or another regulated environment is preferredExperience with third party risk assessments, due diligence, and related third party risk management activitiesStrong organizational skills and the ability to manage multiple assessments, approvals, and competing prioritiesStrong analytical and critical-thinking skills, with the ability to challenge information, identify gaps or inconsistencies, synthesize information from multiple sources, and make well-supported risk-based decisions