
Remote opportunity at
ChimeSecurity Risk Governance Analyst
Chime is a financial technology company dedicated to making core banking services helpful, easy, and free, empowering millions of members to achieve financial progress. The organization…
Career Tools
About This Role
Chime is a financial technology company dedicated to making core banking services helpful, easy, and free, empowering millions of members to achieve financial progress. The organization is currently seeking a Security Risk Governance Analyst to join the team on an on-site basis. In this position, you will help strengthen how security risk is identified, assessed, and managed across the internal control environment and third-party ecosystem. Working alongside senior analysts, you…
Job Description
Chime is a financial technology company dedicated to making core banking services helpful, easy, and free, empowering millions of members to achieve financial progress. The organization is currently seeking a Security Risk Governance Analyst to join the team on an on-site basis.
In this position, you will help strengthen how security risk is identified, assessed, and managed across the internal control environment and third-party ecosystem. Working alongside senior analysts, you will take secondary coverage of a business domain while participating in vendor security reviews, controls testing, risk assessments, and compliance initiatives. Responsibilities include conducting end-to-end third-party due diligence, supporting compliance programs such as SOX IT General Controls, SOC 2, ISO 27001, and PCI DSS, managing risk register findings, and executing quarterly user access reviews.
This role is ideal for an organized and curious professional with a background in security, risk, IT audit, or compliance who is building a career in information security. Successful candidates will feel comfortable operating without a fully defined path, possess a habit of raising problems early, and demonstrate the ability to drive tasks to closure across cross-functional teams.
Responsibilities
- Manage end-to-end third-party security reviews including due diligence, evidence gathering, vendor interviews, and ongoing monitoring
- Assist with SOX IT General Controls, PCI DSS, SOC 2, and ISO 27001 audits through preparation, evidence gathering, and walkthrough coordination
- Perform risk assessments, gap analyses, and controls testing for new tools, artificial intelligence systems, and business lines
- Record findings, remediation owners, and risk exceptions in the security risk governance register and track them to completion
- Execute quarterly user access reviews for applicable systems using ConductorOne alongside follower tracking and evidence retention
- Help define and maintain security key performance indicators, key risk indicators, and dashboards for leadership
- Develop or source security training content for delivery through a learning management system
- Maintain operational runbooks, security baselines, and standards while collaborating on automated evidence collection workflows
- Guide security architecture reviews through completion with security engineering, application security, and infrastructure security teams
Requirements
- Two to four years of professional experience in information security, IT audit, risk, compliance, or a regulated environment
- Hands-on background with controls testing, risk assessments, or third-party security reviews
- Experience utilizing vulnerability management tools and lifecycle management for security risk exceptions
- Working knowledge of compliance frameworks including SOC 2, SOX, PCI DSS, ISO 27001, and NIST standards
- Demonstrated skill in documenting operational processes, standards, runbooks, and security procedures
- Proven ability to drive tasks to completion through unblocking, escalation, and coordination with unmanaged peers
Qualifications
- Progress toward or possession of security and audit credentials such as Security+, CISA, or CRISC
- Prior professional exposure working with GCP, GitHub, or AWS
Core Skills
Benefits
- Four days per week in the office with remote work on Fridays near a company location
- Comprehensive health, financial, and wellbeing coverage
- Backup pet, child, and elder care along with subsidized commuter benefits
- Generous vacation policy and company-wide paid days off
- Time off allowance dedicated to supporting local community organizations
- Annual wellness stipend for eligible expenses
- Paid parental leave providing up to 22 weeks for birthing parents and 12 weeks for non-birthing parents
- Family planning reimbursement access
Frequently Asked Questions
What is the employment type for this role?
The position is a full-time role.
What is the remote work policy?
This is an on-site position requiring four days a week in the office and Fridays from home for employees near a company office.
What is the salary range for the Security Risk Governance Analyst?
The base salary offered ranges from $105,000 to $145,000 USD, with potential for bonuses, competitive equity, and benefits.
What level of experience is required?
Candidates need two to four years of experience in security, IT audit, risk, compliance, or equivalent regulated environments.
Sample Interview Questions
AI-generated questions tailored to this specific role — a preview of the full practice set.

