GRC Careers: AI Governance, Risk and Compliance JobsGovernance · Risk · Compliance Careers

Jobs › California › San Francisco Bay Area › Security Risk Governance Analyst

Security Risk Governance Analyst

Chime Financial, Inc
RiskOn-siteFull-timeSan Francisco, CA$105,000

Chime Financial, Inc is hiring for the job of Security Risk Governance Analyst, San Francisco, CA (On-site). This is a Risk job in the governance, risk, and compliance field, with a posted range of $105,000. Review the full details below and apply directly with Chime Financial, Inc.

Organization: Chime Financial, IncLocation: San Francisco, CAWorkplace: On-siteFocus: RiskSalary: $105,000Posted: Oct 1, 2026
Chime Financial, Inc is hiring for this Risk job in San Francisco, one of the metros GRC Careers tracks for governance, risk, and compliance hiring. See other GRC jobs in San Francisco →

About the role

We’re hiring a Security Risk Governance Analyst to help strengthen how Chime identifies, assesses, and manages security risk across our third-party ecosystem and internal control environment. You’ll work across vendor security reviews, risk assessments, controls testing, and key compliance initiatives, while helping turn security requirements into clear, repeatable processes. You’ll partner closely with teams across Security, Risk, Compliance, Engineering, Application Security, and Infrastructure Security to identify gaps, manage risk, and move assessments through to completion. You ll work alongside Senior Analysts who hold risk coverage for Chime s business domains, taking secondary coverage for one of them as you build depth. This role is a strong fit for someone building a security risk career who is organized, curious, and follows an assessment through to a documented decision.

The base salary offered for this role and level of experience will begin at $105,000.00 and up to $145,000.00. Full-time employees are also eligible for a bonus, competitive equity package, and benefits. The actual base salary offered may be higher, depending on your location, skills, qualifications, and experience.

In this role, you can expect to

Run third-party security reviews end to end: due diligence assessments, evidence collection, vendor interviews, and ongoing monitoring.
Support SOX IT General Controls, PCI DSS, SOC 2, and ISO 27001 programs with audit preparation, evidence collection, and walkthrough coordination.
Conduct risk assessments, gap analyses, and controls testing, including reviews of new tools, AI systems, and new lines of business arriving through Security intake. Record findings, remediation owners, and risk exceptions in the SRG risk register and track them to closure.
Run quarterly user access reviews for applications in scope for SOX, SOC 2, PCI, and ISO 27001, including population builds in ConductorOne, reviewer follow-up, revocation and lookback handling, and evidence retention.
Help define and maintain security KPIs, KRIs, and dashboards that give leadership clear visibility into risk and program performance.
Develop or source security training content and support delivery to employees and contractors through a learning management system.
Create and maintain operational runbooks, security baselines, and standards, and work with SRG engineering to move manual evidence collection into automated workflows.
Move Security Architecture Reviews through the process with Security Engineering, Application Security, and Infrastructure Security, and help document the steps as they stabilize.

To thrive in this role, you have

2–4 years of experience in security, IT audit, risk, or compliance, or equivalent experience in a regulated environment.
Hands-on experience with at least one of: third-party security reviews, risk assessments, or controls testing.
Professional experience focused on information security, security risk, and/or security program management.
Experience using vulnerability management tooling and managing security risk exceptions through their lifecycle.
Working knowledge of security and compliance frameworks such as SOX, SOC 2, NIST 800-series or NIST Cybersecurity Framework, ISO 27001, and PCI DSS.
Experience documenting security procedures, operational processes, standards, and runbooks.
Evidence of driving work to closure through people you don t manage: chasing owners, unblocking, and escalating when it stalls.
Comfort working without a fully defined path, and a habit of raising problems early with a proposed next step.
Progress toward a security or audit certification such as CISA, CRISC, or Security+ is a plus. We support analysts in earning them.
Experience working with AWS, GitHub, and/or GCP is a plus.

# -Onsite # -TP1

span helvetica, arial, sans-serif; A little about us

span helvetica, arial, sans-serif; At Chime, we believe that everyone can achieve financial progress. We created Chime, a financial technology company, not a bank*, on the premise that core banking services should be helpful, easy, and free. Through our user-friendly tools and intuitive platforms, we empower our members to take control of their finances and work towards their goals. Whether it s starting a savings account, purchasing a first car or home, launching a business, or pursuing higher education, we re proud to have helped millions unlock their financial potential.

span helvetica, arial, sans-serif; We re a team of problem solvers, dreamers, and builders with one shared obsession: our members. From day one, Chimers have worked tirelessly to out-hustle and out-execute competitors to bring our mission to life. Their grit and determination inspire us to work harder every day to deliver the very best experience possible. We each bring an owner s mindset to our work, refusing to be outdone and holding ourselves accountable to meet and exceed the highest bars for our teams, our company, and our members.

span helvetica, arial, sans-serif; We believe in being bold, dreaming big, and taking risks, while also working together, embracing our diverse perspectives, and giving each other honest feedback. Our culture remains deeply entrepreneurial, encouraging every Chimer to see themselves as stewards of our mission to help everyday Americans unlock their financial progress.

span helvetica, arial, sans-serif; We know that to achieve our mission, we must earn and keep people s trust, so we hold ourselves to the highest standards of integrity in everything we do. These aren t just words on a wall, our values are embedded in every aspect of our business, serving as a north star that guides us as we work to help millions achieve their financial potential.

span helvetica, arial, sans-serif; Because if we don t, who will?

span helvetica, arial, sans-serif; *Chime is a financial technology company, not a bank. Banking services provided by The Bancorp Bank, N.A. or Stride Bank, N.A., Members FDIC.

span helvetica, arial, sans-serif; What we offer for our full-time, regular employees

helvetica, arial, sans-serif; span helvetica, arial, sans-serif; 🏢 Our in-office work policy is designed to keep you connected - with four days a week in the office and Fridays from home for those near one of our offices, plus team and company-wide events depending on location. Whether you’re coming in regularly or are part of our fully remote program, you’ll stay engaged with your work and teammates.
helvetica, arial, sans-serif; span helvetica, arial, sans-serif; 💻 Benefits that support your work and life, including backup child, elder, and pet care and subsidized commuter benefits for eligible employees.
helvetica, arial, sans-serif; span helvetica, arial, sans-serif; ✨ Comprehensive health, financial, and wellbeing benefits designed to support you at every stage of life.
helvetica, arial, sans-serif; span helvetica, arial, sans-serif; 🏝 Generous vacation policy and company-wide paid days off
helvetica, arial, sans-serif; span helvetica, arial, sans-serif; 🫂 1% of your time off to support local community organizations of your choice
helvetica, arial, sans-serif; span helvetica, arial, sans-serif; 👟 Annual wellness stipend to use towards eligible wellness related expenses
helvetica, arial, sans-serif; span helvetica, arial, sans-serif; 👶 Up to 22 weeks of paid parental leave for birthing parents and 12 weeks of paid parental leave for non-birthing parents
helvetica, arial, sans-serif; span helvetica, arial, sans-serif; 👪 Access to family planning reimbursement
helvetica, arial, sans-serif; span helvetica, arial, sans-serif; 💚 A challenging and fulfilling opportunity to join one of the most experienced teams in FinTech and help millions unlock financial progress

span helvetica, arial, sans-serif; We know that great work can’t be done without a diverse team and inclusive environment. That’s why we specifically look for individuals of varying strengths, skills, backgrounds, and ideas to join our team. We believe this gives us a competitive advantage to better serve our members and helps us all grow as Chimers and individuals.

span helvetica, arial, sans-serif; Chime is proud to be an Equal Opportunity Employer. We consider qualified applicants without regard to race, color, ancestry, religion, sex, national origin, sexual orientation, gender identity, age, marital or family status, disability, genetic information, veteran status, or any other legally protected basis under provincial, federal, state, and local laws, regulations, or ordinances. We will also consider qualified applicants with criminal histories in a manner consistent with the requirements of state and local laws, including the San Francisco Fair Chance Ordinance, Cook County Ordinance, NYC Fair Chance Act, and the LA City Fair Chance Ordinance, and consistent with Canadian provincial and federal laws. If you have a disability or special need that requires accommodation during any stage of the application process, please contact: span underline; color: rgb(35, 111, 161); a rgb(35, 111, 161); text-decoration: underline; accommodations@chime.com.

span helvetica, arial, sans-serif; To learn more about how Chime collects and uses your personal information during the application process, please see the a span underline; color: rgb(35, 111, 161); Chime Applicant Privacy Notice.

Location and market context

This job is based in San Francisco on-site. Local candidates benefit from being close to Chime Financial, Inc's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.

About risk management jobs

Risk jobs own the methodology for identifying, assessing, and escalating enterprise, operational, and technology risk. Second-line teams set risk appetite and challenge the first line. Jobs like this one are typically evaluated against frameworks such as enterprise and operational risk frameworks, NIST AI RMF, and risk-appetite and escalation practices.

How to position yourself for this risk management job

Strong candidates emphasize risk assessment methodology, appetite and escalation, cross-functional partnership, and clear reporting to senior leadership and the board. In your resume and outreach, tie your experience to how Chime Financial, Inc would apply enterprise and operational risk frameworks, NIST AI RMF, and risk-appetite and escalation practices, and lead with concrete outcomes rather than duties.

Similar GRC jobs

More jobs at Chime Financial, Inc

More GRC jobs in San Francisco

Hiring for Risk?

Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.

Post a job  Pricing from $99 · About GRC Careers · Hiring toolkit

Want to be next in a job like this?

Jobs like Security Risk Governance Analyst in San Francisco, CA open regularly. Be first to know, privately. No current employer ever sees you looking.

New Risk jobs, the moment they post.

One click unsubscribe.
Know your GRC? Take the 2-minute AI Governance Challenge. No signup needed.
Play now →

Employer, or see something wrong with this posting? Report this posting and we will review it promptly.