368,746open jobs
9,444companies
47,506added this week
Browse all
Salary
$119k – $176k per year
Location
Remote/Hybrid (New York, San Francisco, Seattle, Raleigh, United States)
Seniority
Middle · 4+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Plaid Inc. is a financial technology company headquartered in San Francisco, California, and founded in 2013. The company develops a data transfer network and application programming interfaces that allow consumers to securely connect their bank accounts to financial applications and services. It operates globally across North America and Europe, serving over 12,000 financial institutions and powering thousands of digital finance tools for millions of users.

We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam.

Team:

The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security organization, focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission is to reduce the likelihood and impact of security risks while operating a robust assurance program that builds trust with our customers, consumers, and data partners.We partner closely across the company to ensure Plaid’s platform remains secure, resilient, and aligned with industry and regulatory expectations.

Third-party ecosystem risk is a core part of how we keep Plaid safe-we vet the security of both the vendors we rely on and the customers and partners who connect to our platform, so trust runs in both directions.

Role:

  • You will run security risk assessments for Plaid’s third parties end-to-end-from intake and questionnaire through risk rating, findings, and tracked exceptions.

  • You will assess the security posture of customers and partners onboarding to the platform with the same rigor we apply to vendors.

  • You will keep the third-party risk lifecycle moving-risk tiering, reassessment cadence, remediation follow-through, and a clean, current risk register.

  • You will help mature the program-questionnaires, tiering criteria, intake, and runbooks-so reviews get faster and more consistent as volume grows, drawing on how you’ve improved third-party risk programs before.

  • You will report on ecosystem risk to Security and cross-functional stakeholders, and operate as an AI power user to raise your own throughput.

Responsibilities:

  • Run Vendor Security Risk Assessments: Triage inbound vendor requests, run security reviews scaled to risk tier, rate the risk, and document findings and exceptions. Your assessments keep Plaid from inheriting a vendor’s security gaps and give Procurement, Privacy, and Legal a clear risk signal before contracts are signed.

  • Vet Customer and Partner Security Posture: Review the security practices of customers and partners onboarding to the platform, applying the same standards you use for vendors. Your reviews make sure who connects to Plaid meets the bar before they touch data-protecting consumers and the ecosystem.

  • Keep the Third-Party Risk Lifecycle Current: Maintain risk tiering, drive reassessments on cadence, chase remediation to closure, and keep the risk register accurate. Your follow-through keeps third-party risk a live, trustworthy picture rather than a point-in-time checkbox.

  • Mature the Program: Improve questionnaires, tiering criteria, intake, runbooks, and tooling as review volume grows-bringing patterns from third-party risk programs you’ve matured before. Your work moves the function from ad hoc toward fast, consistent, and scalable.

  • Report on Ecosystem Risk: Track assessment cycle times, backlog, open exceptions, and reassessment coverage, and report program health to stakeholders. Your reporting gives leadership real visibility into where third-party risk concentrates.

  • Scale Through AI and Tooling: Build and scale AI-assisted workflows for assessment review, questionnaire analysis, and reporting-and share what works. Your approach sets how the team uses AI to handle more reviews without adding headcount.

Qualifications:

Must-haves

  • 4+ years of experience in vendor risk management

  • Third-party and vendor security risk assessment:

    • Experience running security risk assessments of third parties-reviewing questionnaires, SOC 2 and ISO reports, and security documentation, and translating them into a defensible risk rating.

    • Familiarity with the third-party risk lifecycle: intake, tiering, exceptions and risk acceptance, remediation tracking, and periodic reassessment.

  • Security and compliance knowledge:

    • Working knowledge of SOC 2, ISO 27001, NIST CSF, and common control domains (access control, encryption, incident response, BC/DR).

    • Ability to read a control environment and tell a real gap from an acceptable compensating control.

  • Program maturation and operational execution:

    • Experience maturing a third-party or vendor risk program-improving how it works (tiering criteria, questionnaires, workflow, automation), not just executing an existing one.

    • Track record running assessments at volume without dropping rigor.

    • Strong analytical and documentation skills: clear findings, clean tracking, and defensible risk decisions others can follow.

  • Communication and cross-functional effectiveness:

    • Clear written and verbal communication-able to explain a security risk to Procurement, Legal, or a customer without overstating or hand-waving.

    • Comfortable working across Security, Legal, Procurement, and GTM as the third-party risk point of contact.

  • AI fluency and tooling:

    • Demonstrated ability to apply AI tooling to assessment review, questionnaire analysis, and reporting to materially increase throughput-and to share what works with the team.

Nice-to-have

  • A third-party-risk or audit credential (CTPRP, CISA, or CISSP), or hands-on ownership of a TPRM platform (e.g. OneTrust, ProcessUnity, Whistic, SecurityScorecard) beyond using it as an end user.

Our mission at Plaid is to unlock financial freedom for everyone. To support that mission, we seek to build a diverse team of driven individuals who care deeply about making the financial ecosystem more equitable. We recognize that strong qualifications can come from both prior work experiences and lived experiences. We encourage you to apply to a role even if your experience doesn't fully match the job description. We are always looking for team members that will bring something unique to Plaid!

Plaid is proud to be an equal opportunity employer and values diversity at our company. We do not discriminate based on race, color, national origin, ethnicity, religion or religious belief, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, military or veteran status, disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state, and local laws. Plaid is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance with your application or interviews due to a disability, please let us know at [email protected].

Please review our Candidate Privacy Notice here.

Additional compensation in the form(s) of equity and/or commission are dependent on the position offered. Plaid provides a comprehensive benefit plan, including medical, dental, vision, and 401(k). Pay is based on factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience and skillset, and location. Pay and benefits are subject to change at any time, consistent with the terms of any applicable compensation or benefit plans.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,746 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
New York
$38k – $91k per year (Estimated) • Remote • Full-Time • 8+ years exp • PhD • Guadalajara
PowerShell
Python
Databases
Amazon Aurora
DynamoDB
AI/ML
Amazon SageMaker
AWS Bedrock
AWS Bedrock AgentCore
Ray
DevOps
Amazon CloudWatch
Amazon EC2
Amazon ECS
Amazon EKS
Amazon EventBridge
Amazon S3
AWS
AWS Lambda
AWS Step Functions
Azure
CI/CD
Datadog
FinOps
GCP
Git
GitLab
GitLab CI
IAM
Jenkins
JFrog Artifactory
Kubernetes
New Relic
Service Mesh
Splunk
Terraform
Cybersecurity
HIPAA
ISO 27001
PCI DSS
SOC 2
Apply
$100k – $180k per year • Equity • Remote • Full-Time • 7+ years exp • Bachelor's Degree • Austin
DevOps
VMWare
Cybersecurity
ISO 27001
SOC 2
Zero Trust
Apply
$60k – $108k per year • Remote/Hybrid • Full-Time • Bachelor's Degree • United States
PowerShell
Python
DevOps
AWS
Azure
IAM
Splunk
Cybersecurity
Crowdstrike
ISO 27001
Microsoft Defender
Microsoft Entra ID
Microsoft Sentinel
NIST CSF
Qualys Cloud Platform
Apply
$285k per year • Equity • Remote • Hanover
AI/ML
AI Agents
Cybersecurity
ISO 27001
SOC 2
Apply
$119k – $199k per year • Remote/Hybrid • Full-Time • 3+ years exp • Bachelor's Degree • Atlanta
Cybersecurity
ISO 27001
NIST 800-171
NIST 800-53
Apply
Data Scientist 3 days ago
$191k – $263k per year • Remote/Hybrid • Full-Time • 8+ years exp • San Francisco • Seattle • New York
Python
SQL
Databases
Amazon Redshift
Databricks
AI/ML
dbt
Apply
$216k – $219k per year • Remote/Hybrid • Full-Time • 8+ years exp • New York
Apply
$208k – $274k per year • Remote/Hybrid • Full-Time • 8+ years exp • San Francisco • New York • Seattle
AI/ML
AI Agents
Apply
$208k – $274k per year • Remote/Hybrid • Full-Time • 8+ years exp • New York • San Francisco
Go
DevOps
ArgoCD
Kubernetes
Platform Engineering
Progressive Delivery
Prometheus
Service Mesh
SLI/SLO/SLA
Apply
$265k – $370k per year • Remote/Hybrid • Full-Time • San Francisco • New York
JavaScript
AI/ML
AI Agents
Fine-tuning
Prompt Engineering
RAG
Reinforcement Learning
RLHF
Semantic Search
Human-in-the-Loop
Model Context Protocol
Semantic Search
Apply
$197k – $374k per year (Estimated) • In office • Full-Time • 8+ years exp • PhD • New York
AI/ML
AI Agents
Claude
LangChain
OpenAI
Vertex AI
Management
n8n
Zapier
Apply
Senior Data Analyst 2 hours ago
$86k – $171k per year (Estimated) • Equity • Remote • Full-Time • 5+ years exp • Bachelor's Degree • New York
Python
SQL
Databases
Snowflake
AI/ML
Anomaly Detection
Claude
Copilot
Cursor
dbt
Edge AI
DevOps
AWS
Analytics
Tableau
Marketing
Salesforce
Apply
$96k – $134k per year • Remote/Hybrid • Full-Time • Bachelor's Degree • New York
JavaScript
Swift
TypeScript
Java
Java
Spring Framework
Databases
Apache Kafka
PostgreSQL
AI/ML
AI Agents
Claude
Copilot
Fine-tuning
Flink
LangChain
LangGraph
Llama
LlamaIndex
Prompt Engineering
PyTorch
RAG
TensorFlow
Transformers
Devin
Hugging Face
OpenAI
Frontend
Angular
React.js
Mobile
MVC
DevOps
AWS
CI/CD
Docker
Kubernetes
OpenShift
Splunk
Vector
GitHub
Analytics
Tableau
Apply
$150k – $180k per year • In office • Full-Time • PhD • New York
Python
AI/ML
Anthropic
Anthropic SDK
Computer Vision
Fine-tuning
LangChain
LlamaIndex
LLM
OpenAI
OpenAI SDK
RAG
DevOps
AWS
Azure
GCP
Apply
Senior AI Architect 3 hours ago
$131k – $136k per year • In office • Full-Time • 4+ years exp • Master's Degree • New York
Python
Databases
Databricks
AI/ML
Anthropic
Computer Vision
EU AI Act
LLMOps
OpenAI
DevOps
AWS
Azure
GCP
Terraform
Cybersecurity
GDPR
Apply
See all jobs
This is one of many
368,746 more open roles from verified company boards, updated every day.