Security Risk Governance Analyst

Chime

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
San Francisco, CA
Posted
3 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

How this pay compares to similar roles

Similar $166k
$119k most similar roles pay here $211k

This listing doesn't post a salary. Most similar roles pay $133,437–$198,362.

Based on 240 similar postings.

Employer

About Chime

Chime is a financial technology company offering mobile-first banking services including fee-free checking accounts, savings accounts, and a secured credit builder card through partner banks. Industry: Financial Technology & Neobanking

Chime currently has 32 open roles on FindRole.

Most-posted roles

View all roles at Chime

At a glance

TL;DR · Security Risk Governance Analyst

The Security Risk Governance Analyst joins a team focused on identifying, assessing, and managing security risks across the third-party ecosystem and internal control environment. This role involves executing end-to-end third-party security reviews, including due diligence assessments, evidence collection, and vendor interviews. The analyst will support SOX IT General Controls, PCI DSS, SOC 2, and ISO 27001 programs through audit preparation and coordinated walkthroughs. Daily responsibilities include conducting risk assessments for new tools and AI systems, performing gap analyses, and managing the security risk register. Key tasks involve running quarterly user access reviews in ConductorOne and developing security KPIs and training content. Required skills include experience with vulnerability management tooling, security frameworks like NIST 800-series, and technical familiarity with AWS, GitHub, or GCP to manage risks within a regulated environment.

What you'll do

  • Execute end-to-end third-party security reviews including due diligence, evidence collection, and vendor interviews.
  • Support compliance programs such as SOX, PCI DSS, SOC 2, and ISO 27001 through audit preparation and coordination.
  • Conduct risk assessments, gap analyses, and controls testing for new tools, AI systems, and business lines.
  • Manage the lifecycle of security risks by tracking findings and remediation actions in the risk register.
  • Perform quarterly user access reviews for applications within the scope of major compliance frameworks.
  • Develop and maintain security KPIs, KRIs, and dashboards to provide leadership with visibility into program performance.
  • Create operational runbooks, security baselines, and standards while transitioning manual processes into automated workflows.
  • Manage Security Architecture Reviews by coordinating with engineering teams to document and stabilize the process.

What we're looking for

  • 2–4 years of experience in security, IT audit, risk, or compliance in a regulated environment.
  • Hands-on experience with third-party security reviews, risk assessments, or controls testing.
  • Professional experience focused on information security, security risk, and/or security program management.
  • Experience using vulnerability management tooling and managing security risk exceptions through their lifecycle.
  • Working knowledge of frameworks such as SOX, SOC 2, NIST 800-series, ISO 27001, and PCI DSS.
  • Experience documenting security procedures, operational processes, standards, and runbooks.
  • Evidence of driving work to closure through people you do not manage by chasing owners and escalating when stalled.
  • Progress toward a security or audit certification such as CISA, CRISC, or Security+ (preferred); experience with AWS, GitHub, or GCP (preferred).

More like this

Similar roles

Cyber Risk Analyst

Fiserv

Alpharetta, GA +1 3 days ago
Python SQL LLMs Generative AI Prompt Engineering API) development Git GitHub NIST) Cybersecurity Framework NIST AI Risk Management Framework Cybersecurity Risk Management Governance, Risk, and Compliance Data Analytics Workflow Automation Agile
2+ yrs exp

Counterintelligence & Security Risk Analyst

Anduril Industries

Costa Mesa, CA +1 23 days ago $129,000–$171,000
Counterintelligence Risk Management Intelligence Analysis Supply Chain Risk Management ITAR EAR Security Clearance Investigation
8+ yrs exp

Senior Analyst, Security Compliance & Assurance

Jack Henry & Associates

Remote 7 days ago
SOC FFIEC SOX ISO PCI NIST Google Cloud Microsoft Azure Vulnerability Management Risk Management Audit Readiness Cloud Compliance Information Security CISA CISM CCSK CISSP GIAC
6+ yrs exp Remote

Senior IT Auditor

Global Payments (TSYS)

Alpharetta, GA 101 days ago
Sarbanes-Oxley SSAE 18 SOC 1 SOC 2 NIST Cloud Controls Matrix AWS Cloud Adoption Framework COBIT FFIEC PCI-DSS ISO27001 ITIL AuditBoard Microsoft Teams Google Workspace Data Analysis Project Management
3+ yrs exp

Senior Risk Specialist, Compliance Governance Analyst

Capital One Financial

McLean, VA +1 18 days ago $96,500–$110,100
Risk Management Compliance Management Program Data Analysis Tableau Google Workspace Gemini NotebookLM AI Tools Process Management Project Management Audit Reporting Dashboard Governance Quality Assurance Change Management
3+ yrs exp

Information Security Risk Analyst

Lam Research

Tualatin, OR 83 days ago
SIEM KQL SPL SQL Python PowerShell Microsoft Sentinel Splunk Exabeam Securonix Microsoft Defender XDR Entra ID Azure AWS Cloud Platform MITRE ATT&CK UEBA STIX/TAXII MISP Logic Apps