SlipstreamJobsFresh Startup & VC-Backed Jobs

Security Risk Governance Analyst

Chime - San Francisco, CA, United States - Hybrid - posted 2026-09-24

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 105,000 - 145,000 / annual

Chime is hiring a Security Risk Governance Analyst to strengthen how the company identifies, assesses, and manages security risk across its third-party ecosystem and internal control environment. You will work on vendor security reviews, risk assessments, controls testing, and key compliance initiatives while helping turn security requirements into clear, repeatable processes. You will partner closely with teams across Security, Risk, Compliance, Engineering, Application Security, and Infrastructure Security to identify gaps, manage risk, and move assessments through to completion. You will work alongside Senior Analysts who hold risk coverage for Chime's business domains, taking secondary coverage for one of them as you build depth. Key responsibilities include: - Run third-party security reviews end to end: due diligence assessments, evidence collection, vendor interviews, and ongoing monitoring - Support SOX IT General Controls, PCI DSS, SOC 2, and ISO 27001 programs with audit preparation, evidence collection, and walkthrough coordination - Conduct risk assessments, gap analyses, and controls testing, including reviews of new tools, AI systems, and new lines of business arriving through Security intake - Record findings, remediation owners, and risk exceptions in the SRG risk register and track them to closure - Run quarterly user access reviews for applications in scope for SOX, SOC 2, PCI, and ISO 27001, including population builds in ConductorOne, reviewer follow-up, revocation and lookback handling, and evidence retention - Help define and maintain security KPIs, KRIs, and dashboards that give leadership clear visibility into risk and program performance - Develop or source security training content and support delivery to employees and contractors through a learning management system - Create and maintain operational runbooks, security baselines, and standards, and work with SRG engineering to move manual evidence collection into automated workflows - Move Security Architecture Reviews through the process with Security Engineering, Application Security, and Infrastructure Security, and help document the steps as they stabilize Chime is a financial technology company (not a bank) that empowers members to take control of their finances. The company operates with an entrepreneurial culture focused on integrity, collaboration, and delivering the best member experience. Workplace: Four days per week in office, Fridays from home for those near an office location, plus team and company-wide events depending on location. Fully remote options available for some candidates. REQUIREMENTS: - 2–4 years of experience in security, IT audit, risk, or compliance, or equivalent experience in a regulated environment - Hands-on experience with at least one of: third-party security reviews, risk assessments, or controls testing - Professional experience focused on information security, security risk, and/or security program management - Experience using vulnerability management tooling and managing security risk exceptions through their lifecycle - Working knowledge of security and compliance frameworks such as SOX, SOC 2, NIST 800-series or NIST Cybersecurity Framework, ISO 27001, and PCI DSS - Experience documenting security procedures, operational processes, standards, and runbooks - Evidence of driving work to closure through people you don't manage: chasing owners, unblocking, and escalating when it stalls - Comfort working without a fully defined path, and a habit of raising problems early with a proposed next step - Progress toward a security or audit certification such as CISA, CRISC, or Security+ is a plus - Experience working with AWS, GitHub, and/or GCP is a plus

Similar roles