Senior Business Analyst, TPRM
About the role
As a Senior Business Analyst, TPRM, you will support the assessment and ongoing oversight of third party relationships, including vendors and partners, throughout the third party risk management lifecycle.
You will assess third party risk, conduct business due diligence, and coordinate additional risk assessments with cross-functional partners. You will help ensure risks are appropriately identified, documented, and addressed while working closely with business owners, risk partners, and Chime’s bank partners.
This role requires strong analytical judgment, attention to detail, and the ability to manage multiple assessments and stakeholders. You will serve as a trusted partner to the business while contributing to the continued development and maturity of Chime’s TPRM program.
The base salary offered for this role and level of experience will begin at $105,000.00 and up to $145,000.00. Full-time employees are also eligible for a bonus, competitive equity package, and benefits. The actual base salary offered may be higher, depending on your location, skills, qualifications, and experience.
In this role, you can expect to:
Review and challenge Inherent Risk Questionnaires (IRQs), working with business owners to understand vendor relationships, validate information, and determine appropriate inherent risk and criticality ratings.
Coordinate due diligence activities with cross-functional risk partners and subject matter experts across areas such as Information Security, Privacy, Compliance, Enterprise Risk Management, and Legal.
Conduct business due diligence, including reviews of corporate registration, reputational information, insurance coverage, and other relevant documentation, and coordinate additional activities such as background checks.
Manage assigned third party assessments through completion, coordinating with business owners and cross-functional risk partners to address questions, follow up on outstanding requirements, and escalate concerns as appropriate.
Facilitate vendor approval processes with Chime’s bank partners, including coordinating assessment information, responding to follow-up requests, and tracking approvals through completion.
Identify and document issues arising from TPRM assessments and partner with relevant stakeholders to track third party risk issues and remediation activities through resolution.
Support ongoing monitoring and periodic reassessments of third party relationships, including reviewing changes that may impact the inherent risk rating, criticality rating, or due diligence requirements.
Clearly document TPRM assessments, risk decisions, and supporting rationale in accordance with program requirements.
Provide guidance to business owners and stakeholders on TPRM requirements, processes, and expectations.
Contribute to the continued development and maturity of the TPRM program through process improvements, tooling enhancements, reporting, and updates to policies, procedures, standards, and supporting documentation.
Support internal audits, regulatory examinations, bank partner oversight, and other program activities as needed.
To thrive in this role, you have:
4+ years of experience in Third Party Risk Management, Vendor Risk Management, Operational Risk, Compliance, Audit, or a related risk management function.
Experience with third party risk assessments, due diligence, and related third party risk management activities.
Strong analytical and critical-thinking skills, with the ability to challenge information, identify gaps or inconsistencies, synthesize information from multiple sources, and make well-supported risk-based decisions.
Strong stakeholder management and communication skills, with experience working across business owners, risk and control functions, and cross-functional teams.
Strong organizational skills and the ability to manage multiple assessments, approvals, and competing priorities.
Experience contributing to risk program initiatives such as process improvement, policy and procedure development, tooling enhancements, reporting, audit support, or similar activities.
Familiarity with regulatory expectations and industry practices for third party risk management, including applicable interagency guidance.
Experience in financial services, fintech, banking, or another regulated environment is preferred.
Familiarity with Third Party Risk Management platforms, workflow tools, and reporting solutions is a plus.
#LI-Onsite #LI-LB1