Jobs / United States / Chime Financial INC
Security Risk Governance Analyst
Chime Financial INC · 🇺🇸 San Francisco, CA, USA
Sponsorship verdict
Sponsorship possible
One solid signal, not two — worth applying, and worth asking about sponsorship early.
- Employer is on a government sponsor recordThe US Department of Labor certified 81 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 20 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).
- The posting doesn’t mention sponsorshipSilence isn’t a refusal — ask the recruiter before investing much time.
- No salary bar for this routeH-1B has no fixed salary bar: the employer must pay at least the prevailing wage for the role and area. Cap-subject employers enter a lottery weighted by wage level. Source: https://www.federalregister.gov/documents/2025/12/29/2025-23853/weighted-selection-process-for-registrants-and-petitioners-seeking-to-file-cap-subject-h-1b, rules effective 2026-02-27.
- What Chime Financial INC paid sponsored hires in similar roles4 certified filings for “Senior Data Analyst, Credit Risk” (Financial Risk Specialists) in CA: $153k–$200k, median $157k. Most were filed at wage level III (50%) — 3 lottery entries, ≈46% projected selection odds for cap-subject employers. The pay stated here ($105,000 — $145,000 USD) is below what this employer usually pays sponsored hires for this role. Source: US Department of Labor LCA disclosure data (Oct 2025 – Jun 2026).
- Confirmed live todayWhen a source last listed this job as open.
US H-1B: cap-subject employers enter a lottery weighted by wage level — Level I gets 1 entry, Level IV gets 4 (DHS projected selection odds ≈15% at Level I to ≈61% at Level IV). Universities and non-profit research employers are cap-exempt. The $100,000 fee for new petitions from abroad is currently blocked by a court order (appeal pending).
A verdict summarises public evidence; it is not legal advice and never a guarantee — the employer and the immigration authority decide. Sign in to factor in where you can already work.
Or apply yourself on the official page →
Sponsor Radar — Chime Financial INC
The US Department of Labor certified 81 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 20 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).
Past sponsorship or register membership never guarantees sponsorship for this vacancy or for you. Full Sponsor Radar for Chime Financial INC →
About the role
About the role We’re hiring a Security Risk Governance Analyst to help strengthen how Chime identifies, assesses, and manages security risk across our third-party ecosystem and internal control environment. You’ll work across vendor security reviews, risk assessments, controls testing, and key compliance initiatives, while helping turn security requirements into clear, repeatable processes. You’ll partner closely with teams across Security, Risk, Compliance, Engineering, Application Security, and Infrastructure Security to identify gaps, manage risk, and move assessments through to completion. You'll work alongside Senior Analysts who hold risk coverage for Chime's business domains, taking secondary coverage for one of them as you build depth. This role is a strong fit for someone building a security risk career who is organized, curious, and follows an assessment through to a documented decision. In this role, you can expect to • Run third-party security reviews end to end: due diligence assessments, evidence collection, vendor interviews, and ongoing monitoring. • Support SOX IT General Controls, PCI DSS, SOC 2, and ISO 27001 programs with audit preparation, evidence collection, and walkthrough coordination. • Conduct risk assessments, gap analyses, and controls testing, including reviews of new tools, AI systems, and new lines of business arriving through Security intake. Record findings, remediation owners, and risk exceptions in the SRG risk register and track them to closure. • Run quarterly user access reviews for applications in scope for SOX, SOC 2, PCI, and ISO 27001, including population builds in ConductorOne, reviewer follow-up, revocation and lookback handling, and evidence retention. • Help define and maintain security KPIs, KRIs, and dashboards that give leadership clear visibility into risk and program performance. • Develop or source security training content and support delivery to employees and contractors through a learning management system. • Create and maintain operational runbooks, security baselines, and standards, and work with SRG engineering to move manual evidence collection into automated workflows. • Move Security Architecture Reviews through the process with Security Engineering, Application Security, and Infrastructure Security, and help document the steps as they stabilize. To thrive in this role, you have • 2–4 years of experience in security, IT audit, risk, or compliance, or equivalent experience in a regulated environment. • Hands-on experience with at least one of: third-party security reviews, risk assessments, or controls testing. • Professional experience focused on information security, security risk, and/or security program management. • Experience using vulnerability management tooling and managing security risk exceptions through their lifecycle. • Working knowledge of security and compliance frameworks such as SOX, SOC 2, NIST 800-series or NIST Cybersecurity Framework, ISO 27001, and PCI DSS. • Experience documenting security procedures, operational processes, standards, and runbooks. • Evidence of driving work to closure through people you don't manage: chasing owners, unblocking, and escalating when it stalls. • Comfort working without a fully defined path, and a habit of raising problems early with a proposed next step. • Progress toward a security or audit certification such as CISA, CRISC, or Security+ is a plus. We support analysts in earning them. • Experience working with AWS, GitHub, and/or GCP is a plus. #LI-Onsite #LI-TP1 Below is the base salary offered for this role and level of experience. Full-time employees may also be eligible for bonus(es), competitive equity, and benefits. For commissioned roles, the base salary listed in this job description