chime
San Francisco Office · On-site · Full-time
<h2><strong>About the role</strong></h2> <p>We’re hiring a Security Risk Governance Analyst to help strengthen how Chime identifies, assesses, and manages security risk across our third-party ecosystem and internal control environment. You’ll work across vendor security reviews, risk assessments, controls testing, and key compliance initiatives, while helping turn security requirements into clear, repeatable processes. You’ll partner closely with teams across Security, Risk, Compliance, Engineering, Application Security, and Infrastructure Security to identify gaps, manage risk, and move assessments through to completion. You'll work alongside Senior Analysts who hold risk coverage for Chime's business domains, taking secondary coverage for one of them as you build depth. This role is a strong fit for someone building a security risk career who is organized, curious, and follows an assessment through to a documented decision.</p> <p>The base salary offered for this role and level of experience will begin at $105,000.00 and up to $145,000.00. Full-time employees are also eligible for a bonus, competitive equity package, and benefits. The actual base salary offered may be higher, depending on your location, skills, qualifications, and experience.</p> <h2><strong>In this role, you can expect to</strong></h2> <ul> <li>Run third-party security reviews end to end: due diligence assessments, evidence collection, vendor interviews, and ongoing monitoring.</li> <li>Support SOX IT General Controls, PCI DSS, SOC 2, and ISO 27001 programs with audit preparation, evidence collection, and walkthrough coordination.</li> <li>Conduct risk assessments, gap analyses, and controls testing, including reviews of new tools, AI systems, and new lines of business arriving through Security intake. Record findings, remediation owners, and risk exceptions in the SRG risk register and track them to closure.</li> <li>Run quarterly user access reviews for applications in scope for SOX, SOC 2, PCI, and ISO 27001, including population builds in ConductorOne, reviewer follow-up, revocation and lookback handling, and evidence retention.</li> <li>Help define and maintain security KPIs, KRIs, and dashboards that give leadership clear visibility into risk and program performance.</li> <li>Develop or source security training content and support delivery to employees and contractors through a learning management system.</li> <li>Create and maintain operational runbooks, security baselines, and standards, and work with SRG engineering to move manual evidence collection into automated workflows.</li> <li>Move Security Architecture Reviews through the process with Security Engineering, Application Security, and Infrastructure Security, and help document the steps as they stabilize.</li> </ul> <h2>&
chime
Posted via Greenhouse_public
Apply Now takes you to Rozgoo, where auto-apply can submit your application for this role. Updated 7 days ago.
Apply Now