VXI Global Solutions

Security Risk Governance Analyst

VXI Global Solutions • $105K — $145K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 2-4 years of experience in security, IT audit, risk, or compliance.
  • Hands-on experience with third-party security reviews or risk assessments.
  • Professional experience in information security or security program management.
  • Experience with vulnerability management tooling.
  • Knowledge of compliance frameworks like SOX, SOC 2, ISO 27001, and PCI DSS.

Responsibilities

  • Run third-party security reviews end to end, including due diligence assessments and vendor interviews.
  • Support SOX IT General Controls and other compliance programs with audit preparation.
  • Conduct risk assessments and controls testing, documenting findings and remediation plans.
  • Run quarterly user access reviews for compliance applications.
  • Help define and maintain security KPIs and dashboards for leadership.
  • Develop security training content and support its delivery.
  • Create operational runbooks and standards, moving evidence collection to automated workflows.

Benefits

  • In-office work policy with a hybrid schedule of four days in office and one day remote.
  • Comprehensive health and wellbeing benefits for all life stages.
  • Generous vacation and company-wide paid days off.
  • 1% of time off to support community organizations of choice.
  • Annual wellness stipend for eligible expenses.
Full Job Description
About the role

We're hiring a Security Risk Governance Analyst to help strengthen how Chime identifies, assesses, and manages security risk across our third-party ecosystem and internal control environment. You'll work across vendor security reviews, risk assessments, controls testing, and key compliance initiatives, while helping turn security requirements into clear, repeatable processes. You'll partner closely with teams across Security, Risk, Compliance, Engineering, Application Security, and Infrastructure Security to identify gaps, manage risk, and move assessments through to completion. You'll work alongside Senior Analysts who hold risk coverage for Chime's business domains, taking secondary coverage for one of them as you build depth. This role is a strong fit for someone building a security risk career who is organized, curious, and follows an assessment through to a documented decision.

The base salary offered for this role and level of experience will begin at $105,000.00 and up to $145,000.00. Full-time employees are also eligible for a bonus, competitive equity package, and benefits. The actual base salary offered may be higher, depending on your location, skills, qualifications, and experience.
In this role, you can expect to
  • Run third-party security reviews end to end: due diligence assessments, evidence collection, vendor interviews, and ongoing monitoring.
  • Support SOX IT General Controls, PCI DSS, SOC 2, and ISO 27001 programs with audit preparation, evidence collection, and walkthrough coordination.
  • Conduct risk assessments, gap analyses, and controls testing, including reviews of new tools, AI systems, and new lines of business arriving through Security intake. Record findings, remediation owners, and risk exceptions in the SRG risk register and track them to closure.
  • Run quarterly user access reviews for applications in scope for SOX, SOC 2, PCI, and ISO 27001, including population builds in ConductorOne, reviewer follow-up, revocation and lookback handling, and evidence retention.
  • Help define and maintain security KPIs, KRIs, and dashboards that give leadership clear visibility into risk and program performance.
  • Develop or source security training content and support delivery to employees and contractors through a learning management system.
  • Create and maintain operational runbooks, security baselines, and standards, and work with SRG engineering to move manual evidence collection into automated workflows.
  • Move Security Architecture Reviews through the process with Security Engineering, Application Security, and Infrastructure Security, and help document the steps as they stabilize.
To thrive in this role, you have
  • 2-4 years of experience in security, IT audit, risk, or compliance, or equivalent experience in a regulated environment.
  • Hands-on experience with at least one of: third-party security reviews, risk assessments, or controls testing.
  • Professional experience focused on information security, security risk, and/or security program management.
  • Experience using vulnerability management tooling and managing security risk exceptions through their lifecycle.
  • Working knowledge of security and compliance frameworks such as SOX, SOC 2, NIST 800-series or NIST Cybersecurity Framework, ISO 27001, and PCI DSS.
  • Experience documenting security procedures, operational processes, standards, and runbooks.
  • Evidence of driving work to closure through people you don't manage: chasing owners, unblocking, and escalating when it stalls.
  • Comfort working without a fully defined path, and a habit of raising problems early with a proposed next step.
  • Progress toward a security or audit certification such as CISA, CRISC, or Security+ is a plus. We support analysts in earning them.
  • Experience working with AWS, GitHub, and/or GCP is a plus.

#LI-Onsite #LI-TP1

What we offer for our full-time, regular employees
  • Our in-office work policy is designed to keep you connected - with four days a week in the office and Fridays from home for those near one of our offices, plus team and company-wide events depending on location. Whether you're coming in regularly or are part of our fully remote program, you'll stay engaged with your work and teammates.
  • Benefits that support your work and life, including backup child, elder, and pet care and subsidized commuter benefits for eligible employees.
  • Comprehensive health, financial, and wellbeing benefits designed to support you at every stage of life.
  • Generous vacation policy and company-wide paid days off
  • 1% of your time off to support local community organizations of your choice
  • Annual wellness stipend to use towards eligible wellness related expenses
  • Up to 22 weeks of paid parental leave for birthing parents and 12 weeks of paid parental leave for non-birthing parents
  • Access to family planning reimbursement
  • ♥ A challenging and fulfilling opportunity to join one of the most experienced teams in FinTech and help millions unlock financial progress

We know that great work can't be done without a diverse team and inclusive environment. That's why we specifically look for individuals of varying strengths, skills, backgrounds, and ideas to join our team. We believe this gives us a competitive advantage to better serve our members and helps us all grow as Chimers and individuals.

About VXI Global Solutions

VXI Global Solutions is a business process outsourcing company that provides customer care, technical support, and back-office services to its clients. The company was founded in 1998 and has since grown to have over 30,000 employees across 42 locations worldwide. VXI Global Solutions prides itself on its ability to provide high-quality customer service and support to its clients, which range from small startups to Fortune 500 companies. The company's services are designed to help its clients improve customer satisfaction, reduce costs, and increase revenue.
Learn more about VXI Global Solutions
Size
30,000 employees
Industry
Founded
1998

Similar Jobs

More Jobs at VXI Global Solutions

More Information Technology Jobs

Find similar Security Risk Governance Analyst jobs: