Jobs › California › San Francisco Bay Area › Senior Business Analyst, TPRM
Senior Business Analyst, TPRM
Chime is hiring for the job of Senior Business Analyst, TPRM, San Francisco, CA (On-site). This is a Third-Party Risk job in the governance, risk, and compliance field, with a posted range of $105,000 - $145,000. Review the full details below and apply directly with Chime.
About the role
As a Senior Business Analyst, TPRM, you will support the assessment and ongoing oversight of third party relationships, including vendors and partners, throughout the third party risk management lifecycle.
You will assess third party risk, conduct business due diligence, and coordinate additional risk assessments with cross-functional partners. You will help ensure risks are appropriately identified, documented, and addressed while working closely with business owners, risk partners, and Chime’s bank partners.
This role requires strong analytical judgment, attention to detail, and the ability to manage multiple assessments and stakeholders. You will serve as a trusted partner to the business while contributing to the continued development and maturity of Chime’s TPRM program.
In this role, you can expect to
Review and challenge Inherent Risk Questionnaires (IRQs), working with business owners to understand vendor relationships, validate information, and determine appropriate inherent risk and criticality ratings.
Coordinate due diligence activities with cross-functional risk partners and subject matter experts across areas such as Information Security, Privacy, Compliance, Enterprise Risk Management, and Legal.
Conduct business due diligence, including reviews of corporate registration, reputational information, insurance coverage, and other relevant documentation, and coordinate additional activities such as background checks.
Manage assigned third party assessments through completion, coordinating with business owners and cross-functional risk partners to address questions, follow up on outstanding requirements, and escalate concerns as appropriate.
Facilitate vendor approval processes with Chime’s bank partners, including coordinating assessment information, responding to follow-up requests, and tracking approvals through completion.
Identify and document issues arising from TPRM assessments and partner with relevant stakeholders to track third party risk issues and remediation activities through resolution.
Support ongoing monitoring and periodic reassessments of third party relationships, including reviewing changes that may impact the inherent risk rating, criticality rating, or due diligence requirements.
Clearly document TPRM assessments, risk decisions, and supporting rationale in accordance with program requirements.
Provide guidance to business owners and stakeholders on TPRM requirements, processes, and expectations.
Contribute to the continued development and maturity of the TPRM program through process improvements, tooling enhancements, reporting, and updates to policies, procedures, standards, and supporting documentation.
Support internal audits, regulatory examinations, bank partner oversight, and other program activities as needed.
To thrive in this role, you have
4+ years of experience in Third Party Risk Management, Vendor Risk Management, Operational Risk, Compliance, Audit, or a related risk management function.
Experience with third party risk assessments, due diligence, and related third party risk management activities.
Strong analytical and critical-thinking skills, with the ability to challenge information, identify gaps or inconsistencies, synthesize information from multiple sources, and make well-supported risk-based decisions.
Strong stakeholder management and communication skills, with experience working across business owners, risk and control functions, and cross-functional teams.
Strong organizational skills and the ability to manage multiple assessments, approvals, and competing priorities.
Experience contributing to risk program initiatives such as process improvement, policy and procedure development, tooling enhancements, reporting, audit support, or similar activities.
Familiarity with regulatory expectations and industry practices for third party risk management, including applicable interagency guidance.
Experience in financial services, fintech, banking, or another regulated environment is preferred.
Familiarity with Third Party Risk Management platforms, workflow tools, and reporting solutions is a plus.
#LI-Onsite #LI-LB1
Below is the base salary offered for this role and level of experience. Full-time employees may also be eligible for bonus(es), competitive equity, and benefits. For commissioned roles, the base salary listed in this job description does not include incentive/variable pay. The actual base salary offered may be higher, depending on your location, skills, qualifications, and experience.
Wage Notice
$105,000 - $145,000 USD
A little about us
At Chime, we believe that everyone can achieve financial progress. We created Chime, a financial technology company, not a bank*, on the premise that core banking services should be helpful, easy, and free. Through our user-friendly tools and intuitive platforms, we empower our members to take control of their finances and work towards their goals. Whether it's starting a savings account, purchasing a first car or home, launching a business, or pursuing higher education, we're proud to have helped millions unlock their financial potential.
We're a team of problem solvers, dreamers, and builders with one shared o
Location and market context
This job is based in San Francisco on-site. Local candidates benefit from being close to Chime's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.
About third-party risk jobs
Third-party and vendor risk teams assess and monitor the security, privacy, and compliance posture of suppliers, an area under sharp regulatory and operational focus as AI vendors proliferate. Jobs like this one are typically evaluated against frameworks such as third-party risk frameworks, SOC 2, ISO/IEC 27001, and vendor due-diligence and monitoring practices.
How to position yourself for this third-party risk job
Strong candidates emphasize vendor due diligence and assessment, ongoing monitoring, contract and control requirements, and coordinating across security, privacy, and procurement. In your resume and outreach, tie your experience to how Chime would apply third-party risk frameworks, SOC 2, ISO/IEC 27001, and vendor due-diligence and monitoring practices, and lead with concrete outcomes rather than duties.
Similar GRC jobs
- Third-Party Risk Management (TPRM) Risk Analyst · MongoDB · Dublin, Ireland
- DIRECTOR FOR SUPPLY CHAIN PERFORMANCE AND INTEGRATION · Naval Supply Systems Command · Naval Support Activity, Mechanicsburg, Pennsylvania
- Supervisory Supply Management Specialist (Assistant Chief Supply Chain Officer) · Veterans Health Administration · Battle Creek, Michigan
- Counsel - Third Party Risk Management · Everest Re Group · London, UK
- Central Outsourcing Control Office (COCO) · Morgan Stanley · Frankfurt, Germany
- Risk Business Partner - Third Party Risk Management · FNZ · Edinburgh, UK
- Supervisor, IT Security Vendor Risk Management · Raymond James · St. Petersburg, FL
- Head of KYC · Coinbase · Remote
More jobs at Chime
- Lead Analyst, Financial Crimes · Chime · Chicago, IL
- Senior Associate, Compliance Advisory · Chime · San Francisco, CA
More GRC jobs in San Francisco
- Model Policy Manager, National Security · OpenAI · San Francisco
- Research Program Manager, Frontier Assurance · OpenAI · San Francisco
- Senior Regulatory Counsel, Americas · Airwallex · San Francisco
- Data Scientist, Trust & Safety · Replit · Foster City, CA
- Manager, Regulatory Operations · Airwallex · San Francisco
- Senior Manager, Regulatory Accounting & Disclosures · Anthropic · San Francisco, CA
Hiring for Third-Party Risk?
Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.
Post a job Pricing from $99 · About GRC Careers · Hiring toolkit
Want to be next in a job like this?
Jobs like Senior Business Analyst, TPRM in San Francisco, CA open regularly. Be first to know, privately. No current employer ever sees you looking.
Employer, or see something wrong with this posting? Report this posting and we will review it promptly.