Назад
Company hidden
4 дня назад

Security Risk Governance Analyst (Fintech)

105 000 - 145 000$
Формат работы
remote (только USA)/hybrid
Тип работы
fulltime
Грейд
junior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Risk Governance Analyst (Fintech): Managing third-party security reviews, risk assessments, controls testing, and compliance programs across Chime’s internal control environment with an accent on SOX, SOC 2, PCI DSS, and ISO 27001. Focus on tracking findings and risk exceptions to closure, conducting access reviews, building risk metrics, and automating evidence collection.

Location: San Francisco, CA, USA; in-office policy includes four days per week in the office and Fridays from home for employees near an office, with a fully remote program also available depending on eligibility.

Base salary: $105,000–$145,000 per year, plus bonus, equity, and benefits.

Company

hirify.global is a financial technology company building user-friendly tools and platforms that help millions of members make financial progress.

What you will do

  • Run third-party security reviews, including due diligence, evidence collection, vendor interviews, and ongoing monitoring.
  • Support SOX IT General Controls, PCI DSS, SOC 2, and ISO 27001 programs through audit preparation, evidence collection, and walkthrough coordination.
  • Conduct risk assessments, gap analyses, and controls testing for tools, AI systems, and new lines of business.
  • Record findings, remediation owners, and risk exceptions in the security risk register and track them to closure.
  • Run quarterly user access reviews, maintain security KPIs and KRIs, and create leadership dashboards.
  • Maintain security runbooks, baselines, and standards while helping automate evidence collection and coordinate Security Architecture Reviews.

Requirements

  • 2–4 years of experience in security, IT audit, risk, compliance, or an equivalent regulated environment.
  • Hands-on experience with third-party security reviews, risk assessments, or controls testing.
  • Professional experience in information security, security risk, or security program management.
  • Experience with vulnerability management tooling and managing security risk exceptions through their lifecycle.
  • Working knowledge of SOX, SOC 2, NIST 800-series or the NIST Cybersecurity Framework, ISO 27001, and PCI DSS.
  • Experience documenting security procedures, operational processes, standards, and runbooks, and driving work to closure across teams.

Nice to have

  • Progress toward CISA, CRISC, Security+, or another security or audit certification.
  • Experience with AWS, GitHub, or GCP.

Culture & Benefits

  • Hybrid and fully remote work options depending on eligibility and location.
  • Comprehensive health, financial, and wellbeing benefits, including commuter support and backup care.
  • Generous vacation, company-wide paid days off, and paid parental leave of up to 22 weeks for birthing parents and 12 weeks for non-birthing parents.
  • Annual wellness stipend, family planning reimbursement, and community-support time off.
  • Entrepreneurial, collaborative environment focused on integrity, accountability, and financial inclusion.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →