Security Risk Governance AnalystPosted today

The opportunity

We’re hiring a Security Risk Governance Analyst to help strengthen how Chime identifies, assesses, and manages security risk across our third-party ecosystem and internal control environment. You’ll work across vendor security reviews, risk assessments, controls testing, and key…

What you'll do

  • Run third-party security reviews end to end: due diligence assessments, evidence collection, vendor interviews, and ongoing monitoring.

  • Support SOX IT General Controls, PCI DSS, SOC 2, and ISO 27001 programs with: audit preparation, evidence collection, and walkthrough coordination.

  • Conduct risk assessments, gap analyses, and controls testing, including: reviews of new tools, AI systems, and new lines of business arriving through Security intake. Record findings, remediation owners, and risk exceptions in the SRG risk register and track them to closure.

  • Run quarterly user access reviews for applications in scope for SOX, SOC 2,: PCI, and ISO 27001, including population builds in ConductorOne, reviewer follow-up, revocation and lookback handling, and evidence retention.

  • Help define and maintain security KPIs, KRIs, and dashboards that give: leadership clear visibility into risk and program performance.

  • Develop or source security training content and support delivery to employees: and contractors through a learning management system.

What they're looking for

  • Create and maintain operational runbooks, security baselines, and standards,: and work with SRG engineering to move manual evidence collection into automated workflows.
  • Move Security Architecture Reviews through the process with Security: Engineering, Application Security, and Infrastructure Security, and help document the steps as they stabilize.
  • –4 years of experience in security, IT audit, risk, or compliance, or: equivalent experience in a regulated environment.
  • Hands-on experience with at least one of: third-party security reviews, risk assessments, or controls testing.