Business Control Manager
About the role
We are hiring a Business Control Manager to join our Compliance team at Chime, where you will be responsible for strengthening the first line of defense by partnering with business units to ensure they operate in compliance with all applicable regulatory requirements and internal policies. You will own the control environment for an assigned Business Unit (identifying risks, designing controls with the business, and validating that those controls work) and contribute to the compliance and control frameworks the Business Control Management team is building. As a key player in our compliance team, you will support various departments, including product, engineering, legal, and operations, to ensure our business practices align with regulatory standards and best practices.
The Business Control Manager will work across product, engineering, legal, and operations, and you will monitor how regulatory change affects the controls in your domain as Chime continues to scale. This role offers the chance to build the control environment for a fast-moving product area from the ground up, at a company that values innovation and consumer protection.
The base salary offered for this role and level of experience will begin at $101,000.00 and up to $140,000.00. Full-time employees are also eligible for a bonus, competitive equity package, and benefits. The actual base salary offered may be higher, depending on your location, skills, qualifications, and experience.
In this role, you can expect to
Own the control environment for your assigned business unit - maintain the control library, keep control records current, and drive enhancements as products and processes change.
Evaluate new products, features, and material process changes for regulatory risk before launch - reviewing business requirements early in scoping, identifying regulatory touchpoints, and proposing control designs and residual risk summaries.
Run proactive reviews of existing processes and control environments - full risk identification, severity assessment, control gap analysis, and control maturity evaluation
Map identified risks to the specific regulatory obligations they implicate, and maintain risk, obligation, and control records in our GRC platform so that coverage and gaps are visible and auditable.
Design preventive, detective, and directive controls with the Engineering or Product owner who will build them - agreeing control type, frequency, automation level, and the evidence the control must produce - then validate after implementation that the control is operating as designed and the gap is closed.
Own the compliance control workstream for incidents in your business unit: perform gap analysis from the root cause analysis, identify the control gap and the obligation it affects, design the control with the Engineering or Product owner, track implementation against SLA, validate the control once live, and close the compliance issue.
Classify control gaps by root cause and use that data to surface systemic weaknesses - recurring patterns within your business unit and across business units - and turn them into recommendations that go beyond any individual control.
Translate regulatory change in your business unit into control impact - working with Regulatory Affairs and Compliance Advisory to assess what a change means for existing controls, and advising the business on the adjustments required.
Perform ongoing reviews of business procedures, member-facing disclosures, marketing, and complaint data to identify compliance risks, and partner with stakeholders on corrective action.
Build durable working relationships with product, engineering, legal, and operations partners, and support bank partner, internal audit, and regulatory examination requests relating to controls in your business unit.
Help business partners understand the controls they own and why they exist - through working sessions, documentation, and day-to-day partnership rather than formal training delivery.
Maintain auditable records of risk and control decisions - including recommendations the business declines, with the rationale and residual risk documented - to a standard that lets Legal, Compliance, or Internal Audit reconstruct how a decision was reached. Contribute to regular reporting to Compliance Governance on control changes, new risks, and open items.
To thrive in this role, you have
4+ years of experience in regulatory compliance, risk management, or internal controls within the financial services or fintech sector. At least 3+ years of experience working in consumer protection laws, including Reg Z, Reg E, UDAAP, or similar regulations.
Strong understanding of key consumer protection regulations, including but not limited to EFTA, TILA, UDAAP, and other financial regulatory frameworks.
Hands-on experience documenting risks, controls, and issues in a GRC platform - AuditBoard, Archer, ServiceNow IRM, LogicGate, or similar.
Demonstrated ability to advise product, engineering, risk, and operations teams on consumer protection and regulatory risk, including holding a position when a business partner pushes back.
Strong analytical skills - you can take an incident, a process, or a requirements document and identify where the control should sit and what it needs to produce as evidence.
Excellent verbal and written communication skills, with the ability to explain regulatory concepts to technical and non-technical partners and influence decisions.
A track record of taking a control from problem statement to validated and documented - independently, on a deadline, without needing the process defined for you.
#LI-Onsite #LI-LB1