Get more replies from employers
Send a job-specific resume in minutes.
Plaid is seeking a Security Analyst in Third-Party Ecosystem Risk Management to safeguard our interconnected digital landscape. You will oversee security risk assessments for Plaid's third parties from initiation to closure, evaluating vendors, customers, and partners with consistent rigor.
You will mature the program by refining questionnaires, tiering criteria, intake processes, and runbooks while leveraging AI tools to boost throughput.
The role of Security Analyst in Third-Party Ecosystem Risk Management at Plaid invites candidates to safeguard our interconnected digital landscape. You will oversee security risk assessments for Plaid's third parties from initiation to closure, evaluating vendors, customers, and partners with consistent rigor. This position keeps the third-party risk lifecycle agile, managing risk tiering, reassessment schedules, remediation tracking, and a precise, current risk register. You will mature the program by refining questionnaires, tiering criteria, intake processes, and runbooks, accelerating reviews as volume increases, drawing on prior program enhancements. The role reports ecosystem risk to Security and cross-functional stakeholders while operating as an AI power user to boost individual throughput.
Candidates will run Vendor Security Risk Assessments by triaging inbound vendor requests, conducting security reviews aligned with risk tiers, rating risk, and documenting findings and exceptions. Your assessments prevent Plaid from inheriting vendor security gaps and provide Procurement, Privacy, and Legal with a clear risk signal before contracts are finalized. You will vet Customer and Partner Security Posture by reviewing security practices for those onboarding to the platform, applying the same standards used for vendors. These reviews ensure that anyone connecting to Plaid meets the required bar before accessing data, protecting consumers and the broader ecosystem.
This role maintains the third-party risk lifecycle as a living process, driving risk tiering, enforcing reassessment cadence, chasing remediation to closure, and preserving an accurate risk register. Your follow-through ensures third-party risk remains a current, trustworthy indicator rather than a point-in-time checkbox. You will mature the program by improving questionnaires, tiering criteria, intake, and runbooks, especially as review volume grows, shifting the function from ad hoc to fast, consistent, and scalable. Reporting on ecosystem risk involves tracking assessment cycle times, backlog, open exceptions, and reassessment coverage, then communicating program health to stakeholders. Your insights give leadership real visibility into where third-party risk concentrates.
The position scales through AI and tooling, building and expanding AI-assisted workflows for assessment review, questionnaire analysis, and reporting, then sharing effective methods. You will set the standard for how the team uses AI to handle more reviews without adding headcount. Plaid empowers this role to leverage tools such as Jira, ServiceNow, ServiceNow GRC, OneTrust, MetricStream, Archer, and Qualys, alongside products like Plaid Link, Plaid API, and Plaid Intelligence.
Candidates must bring 4+ years of experience in vendor risk management. Third-party and vendor security risk assessment capability is essential, experience reviewing questionnaires, SOC 2 and ISO reports, and security documentation, then translating findings into defensible risk ratings. You must understand the third-party risk lifecycle, including intake, tiering, exceptions and risk acceptance, remediation tracking, and periodic reassessment. Security and compliance knowledge should cover SOC 2, ISO 27001, NIST CSF, and common control domains such as access control, encryption, incident response, and BC/DR.
Program maturation and operational execution are required, experience improving how a third-party or vendor risk program works through better tiering criteria, questionnaires, workflows, and automation, not merely executing an existing process. A track record of running assessments at volume without sacrificing rigor is vital. Strong analytical and documentation skills must produce clear findings, clean tracking, and defensible risk decisions that others can follow.
Communication and cross-functional effectiveness define success, explaining security risk to Procurement, Legal, or customers without overstating or minimizing. Comfort working across Security, Legal, Procurement, and GTM as the third-party risk point of contact is necessary. AI fluency and tooling experience should demonstrate the ability to apply AI tools to assessment review, questionnaire analysis, and reporting, increasing throughput and sharing methods with the team.
A third-party-risk or audit credential (CTPRP, CISA, or CISSP), or hands-on ownership of a TPRM platform such as OneTrust, ProcessUnity, Whistic, or SecurityScorecard beyond basic usage, is a nice-to-have.
Plaid's mission is to unlock financial freedom for everyone. To support that mission, the company seeks to build a diverse team of driven individuals who care deeply about making the financial ecosystem more equitable. Plaid encourages applications from candidates whose qualifications stem from both prior work experiences and lived experiences, even when backgrounds do not perfectly match the job description. The company welcomes team members who bring unique perspectives.
Plaid is an equal opportunity employer that values diversity. Employment decisions do not discriminate based on race, color, national origin, ethnicity, religion or religious belief, sex including pregnancy, childbirth, or related medical conditions, sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, military or veteran status, disability, or other legally protected characteristics. The company also considers qualified applicants with criminal histories, consistent with applicable law. Plaid provides reasonable accommodations for candidates with disabilities during recruiting. Those needing assistance with the application or interviews due to a disability should contact accommodations@plaid.com.
Equity and/or commission may form part of the compensation package, depending on the role. Plaid offers a comprehensive benefits plan, including medical, dental, vision, and a 401(k). Compensation is based on role scope and responsibilities, candidate work experience and skills, and location. Pay and benefits are subject to change, consistent with any applicable compensation or benefit plans.