Open Role
Chime

Remote opportunity at

Chime

Security Risk Governance Analyst

Chime is a financial technology company dedicated to making core banking services helpful, easy, and free, empowering millions of members to achieve financial progress. The organization…

View Company

Role Snapshot

Hiring Now

Remote from

Remote

Salary

Undisclosed

Department

General

Employment

Full-time

Experience

Not specified

Published13d ago
Listing Views21
Applications0
Apply BeforeNo deadline

Career Tools

About This Role

Chime is a financial technology company dedicated to making core banking services helpful, easy, and free, empowering millions of members to achieve financial progress. The organization is currently seeking a Security Risk Governance Analyst to join the team on an on-site basis. In this position, you will help strengthen how security risk is identified, assessed, and managed across the internal control environment and third-party ecosystem. Working alongside senior analysts, you…

Job Description

Chime is a financial technology company dedicated to making core banking services helpful, easy, and free, empowering millions of members to achieve financial progress. The organization is currently seeking a Security Risk Governance Analyst to join the team on an on-site basis.

In this position, you will help strengthen how security risk is identified, assessed, and managed across the internal control environment and third-party ecosystem. Working alongside senior analysts, you will take secondary coverage of a business domain while participating in vendor security reviews, controls testing, risk assessments, and compliance initiatives. Responsibilities include conducting end-to-end third-party due diligence, supporting compliance programs such as SOX IT General Controls, SOC 2, ISO 27001, and PCI DSS, managing risk register findings, and executing quarterly user access reviews.

This role is ideal for an organized and curious professional with a background in security, risk, IT audit, or compliance who is building a career in information security. Successful candidates will feel comfortable operating without a fully defined path, possess a habit of raising problems early, and demonstrate the ability to drive tasks to closure across cross-functional teams.

Responsibilities

  • Manage end-to-end third-party security reviews including due diligence, evidence gathering, vendor interviews, and ongoing monitoring
  • Assist with SOX IT General Controls, PCI DSS, SOC 2, and ISO 27001 audits through preparation, evidence gathering, and walkthrough coordination
  • Perform risk assessments, gap analyses, and controls testing for new tools, artificial intelligence systems, and business lines
  • Record findings, remediation owners, and risk exceptions in the security risk governance register and track them to completion
  • Execute quarterly user access reviews for applicable systems using ConductorOne alongside follower tracking and evidence retention
  • Help define and maintain security key performance indicators, key risk indicators, and dashboards for leadership
  • Develop or source security training content for delivery through a learning management system
  • Maintain operational runbooks, security baselines, and standards while collaborating on automated evidence collection workflows
  • Guide security architecture reviews through completion with security engineering, application security, and infrastructure security teams

Requirements

  • Two to four years of professional experience in information security, IT audit, risk, compliance, or a regulated environment
  • Hands-on background with controls testing, risk assessments, or third-party security reviews
  • Experience utilizing vulnerability management tools and lifecycle management for security risk exceptions
  • Working knowledge of compliance frameworks including SOC 2, SOX, PCI DSS, ISO 27001, and NIST standards
  • Demonstrated skill in documenting operational processes, standards, runbooks, and security procedures
  • Proven ability to drive tasks to completion through unblocking, escalation, and coordination with unmanaged peers

Qualifications

  • Progress toward or possession of security and audit credentials such as Security+, CISA, or CRISC
  • Prior professional exposure working with GCP, GitHub, or AWS

Core Skills

Benefits

  • Four days per week in the office with remote work on Fridays near a company location
  • Comprehensive health, financial, and wellbeing coverage
  • Backup pet, child, and elder care along with subsidized commuter benefits
  • Generous vacation policy and company-wide paid days off
  • Time off allowance dedicated to supporting local community organizations
  • Annual wellness stipend for eligible expenses
  • Paid parental leave providing up to 22 weeks for birthing parents and 12 weeks for non-birthing parents
  • Family planning reimbursement access

Frequently Asked Questions

What is the employment type for this role?

The position is a full-time role.

What is the remote work policy?

This is an on-site position requiring four days a week in the office and Fridays from home for employees near a company office.

What is the salary range for the Security Risk Governance Analyst?

The base salary offered ranges from $105,000 to $145,000 USD, with potential for bonuses, competitive equity, and benefits.

What level of experience is required?

Candidates need two to four years of experience in security, IT audit, risk, compliance, or equivalent regulated environments.

Sample Interview Questions

AI-generated questions tailored to this specific role — a preview of the full practice set.

Search similar jobs

Related Jobs

HackerOne
HackerOnePosted 1h ago
Full-timeRemoteUSD 135,000 - 155,000/yr
HackerOne
HackerOnePosted 1h ago
Full-timeRemoteUSD 247,000 - 302,000/yr
CertiK
CertiKPosted 9h ago
Full-timeUSD 120,000 - 180,000/yr
Advertisement
320 × 50

Posted by Chime

Source: Chime

Chime

Chime

60Open Jobs
—No reviews yet
View Company Profile