Security Analyst

CV in

Northern (KY)

Hybrid

USD 120,000 - 150,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Equity
Benefits package
401(k)

Job summary

Plaid is seeking a Security Analyst in Third-Party Ecosystem Risk Management to safeguard our interconnected digital landscape. You will oversee security risk assessments for Plaid's third parties from initiation to closure, evaluating vendors, customers, and partners with consistent rigor.

You will mature the program by refining questionnaires, tiering criteria, intake processes, and runbooks while leveraging AI tools to boost throughput.

Qualifications

  • 4+ years of vendor risk management experience.
  • Experience reviewing SOC 2 and ISO 27001 reports and security docs.
  • Understanding of third-party risk lifecycle including intake, tiering, exceptions, and remediation.
  • Strong analytical and documentation skills to produce clear risk findings and justified decisions.
  • Ability to communicate risk to Procurement, Legal, and GTM teams.

Responsibilities

  • Oversee security risk assessments for third parties from initiation to closure.
  • Triage vendor requests and conduct security reviews by risk tier.
  • Document findings, exceptions, and remediation plans for leadership and partners.
  • Mature the program by refining questionnaires, tiering, intake processes, and runbooks.
  • Report program health and risk posture to stakeholders.

Skills

Vendor risk management
Security assessments
SOC 2
ISO 27001
AI tooling

Tools

Jira
ServiceNow
OneTrust
MetricStream
Archer
Qualys

Job description

Security Analyst, Third-Party Ecosystem Risk Management

The role of Security Analyst in Third-Party Ecosystem Risk Management at Plaid invites candidates to safeguard our interconnected digital landscape. You will oversee security risk assessments for Plaid's third parties from initiation to closure, evaluating vendors, customers, and partners with consistent rigor. This position keeps the third-party risk lifecycle agile, managing risk tiering, reassessment schedules, remediation tracking, and a precise, current risk register. You will mature the program by refining questionnaires, tiering criteria, intake processes, and runbooks, accelerating reviews as volume increases, drawing on prior program enhancements. The role reports ecosystem risk to Security and cross-functional stakeholders while operating as an AI power user to boost individual throughput.

Candidates will run Vendor Security Risk Assessments by triaging inbound vendor requests, conducting security reviews aligned with risk tiers, rating risk, and documenting findings and exceptions. Your assessments prevent Plaid from inheriting vendor security gaps and provide Procurement, Privacy, and Legal with a clear risk signal before contracts are finalized. You will vet Customer and Partner Security Posture by reviewing security practices for those onboarding to the platform, applying the same standards used for vendors. These reviews ensure that anyone connecting to Plaid meets the required bar before accessing data, protecting consumers and the broader ecosystem.

This role maintains the third-party risk lifecycle as a living process, driving risk tiering, enforcing reassessment cadence, chasing remediation to closure, and preserving an accurate risk register. Your follow-through ensures third-party risk remains a current, trustworthy indicator rather than a point-in-time checkbox. You will mature the program by improving questionnaires, tiering criteria, intake, and runbooks, especially as review volume grows, shifting the function from ad hoc to fast, consistent, and scalable. Reporting on ecosystem risk involves tracking assessment cycle times, backlog, open exceptions, and reassessment coverage, then communicating program health to stakeholders. Your insights give leadership real visibility into where third-party risk concentrates.

The position scales through AI and tooling, building and expanding AI-assisted workflows for assessment review, questionnaire analysis, and reporting, then sharing effective methods. You will set the standard for how the team uses AI to handle more reviews without adding headcount. Plaid empowers this role to leverage tools such as Jira, ServiceNow, ServiceNow GRC, OneTrust, MetricStream, Archer, and Qualys, alongside products like Plaid Link, Plaid API, and Plaid Intelligence.

Candidates must bring 4+ years of experience in vendor risk management. Third-party and vendor security risk assessment capability is essential, experience reviewing questionnaires, SOC 2 and ISO reports, and security documentation, then translating findings into defensible risk ratings. You must understand the third-party risk lifecycle, including intake, tiering, exceptions and risk acceptance, remediation tracking, and periodic reassessment. Security and compliance knowledge should cover SOC 2, ISO 27001, NIST CSF, and common control domains such as access control, encryption, incident response, and BC/DR.

Program maturation and operational execution are required, experience improving how a third-party or vendor risk program works through better tiering criteria, questionnaires, workflows, and automation, not merely executing an existing process. A track record of running assessments at volume without sacrificing rigor is vital. Strong analytical and documentation skills must produce clear findings, clean tracking, and defensible risk decisions that others can follow.

Communication and cross-functional effectiveness define success, explaining security risk to Procurement, Legal, or customers without overstating or minimizing. Comfort working across Security, Legal, Procurement, and GTM as the third-party risk point of contact is necessary. AI fluency and tooling experience should demonstrate the ability to apply AI tools to assessment review, questionnaire analysis, and reporting, increasing throughput and sharing methods with the team.

A third-party-risk or audit credential (CTPRP, CISA, or CISSP), or hands-on ownership of a TPRM platform such as OneTrust, ProcessUnity, Whistic, or SecurityScorecard beyond basic usage, is a nice-to-have.

Plaid's mission is to unlock financial freedom for everyone. To support that mission, the company seeks to build a diverse team of driven individuals who care deeply about making the financial ecosystem more equitable. Plaid encourages applications from candidates whose qualifications stem from both prior work experiences and lived experiences, even when backgrounds do not perfectly match the job description. The company welcomes team members who bring unique perspectives.

Plaid is an equal opportunity employer that values diversity. Employment decisions do not discriminate based on race, color, national origin, ethnicity, religion or religious belief, sex including pregnancy, childbirth, or related medical conditions, sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, military or veteran status, disability, or other legally protected characteristics. The company also considers qualified applicants with criminal histories, consistent with applicable law. Plaid provides reasonable accommodations for candidates with disabilities during recruiting. Those needing assistance with the application or interviews due to a disability should contact accommodations@plaid.com.

Equity and/or commission may form part of the compensation package, depending on the role. Plaid offers a comprehensive benefits plan, including medical, dental, vision, and a 401(k). Compensation is based on role scope and responsibilities, candidate work experience and skills, and location. Pay and benefits are subject to change, consistent with any applicable compensation or benefit plans.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Analyst, Third-Party Ecosystem Risk Management
Security Analyst, Third-Party Ecosystem Risk Management

MoneyLion • San Francisco (CA)

On-site
USD 140,000 - 190,000
Security Analyst, Third-Party Ecosystem Risk Management
Security Analyst, Third-Party Ecosystem Risk Management

Plaid • New York (NY)

On-site
USD 140,000 - 200,000
Security Analyst, Third-Party Ecosystem Risk Management
Security Analyst, Third-Party Ecosystem Risk Management

Plaid Inc • New York (NY)

On-site
USD 120,000 - 180,000
Security Analyst, Third-Party Ecosystem Risk Management
Security Analyst, Third-Party Ecosystem Risk Management

Plaid • San Francisco (CA)

On-site
USD 119,000 - 176,000
Equity
Medical, dental, vision benefits
401(k)
+1
Security Analyst, Third-Party Ecosystem Risk Management
Security Analyst, Third-Party Ecosystem Risk Management

Plaid • Seattle (WA)

On-site
USD 119,000 - 176,000
Medical insurance
401(k)
Equity options
+1
Staff Software Engineer - Security Engineering
Staff Software Engineer - Security Engineering

MoneyLion • San Francisco (CA)

On-site
USD 180,000 - 250,000
Staff Software Engineer (Security Engineering)
Staff Software Engineer (Security Engineering)

Plaid • United States

On-site
USD 180,000 - 240,000
Equity
401(k)
Health insurance
New York City Office, Seattle Office, San Francisco HQ
New York City Office, Seattle Office, San Francisco HQ

Plaid Inc • New York (NY)

On-site
USD 180,000 - 240,000
Staff Software Engineer - Security Engineering
Staff Software Engineer - Security Engineering

Segment (Twilio) • New York (NY)

On-site
USD 150,000 - 210,000
Equity
401(k)
Medical insurance
+2
Security Engineer, GRC
Security Engineer, GRC

Plaid • United States

On-site
USD 150,000 - 190,000