Plaid logo

Plaid

Security Analyst, Third-Party Ecosystem Risk Management

Hybrid

Part remote, part office, you need to live within commuting distance of a named location.

Hybrid · New York City Office

Employer listed it 6 weeks ago · Added 4 days ago

Been open since 6 weeks ago, still being checked, but it has been live a while.

Salary

$118,680–$175,800

Location

Hybrid · New York City Office

Timezone

Not stated

Contract

Full-time

Experience

Mid

Category

Software

Published by the employer

Remote flexibility

Hybrid

This role is only partly remote, the employer expects time in the office around New York City Office, Seattle Office, Raleigh Office, San Francisco HQ, Hybrid, so you need to live within commuting distance.

What the employer says

  • Source listing states candidate location: "New York City Office, Seattle Office, Raleigh Office, San Francisco HQ, Hybrid"
  • Listing mentions "Hybrid"

What Nomaders makes of it

  • Not suitable if you plan to move between countries

The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.

About the role

We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Seattle, Washington D.C., Raleigh, London, and Amsterdam.

Team:

The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security organization, focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission is to reduce the likelihood and impact of security risks while operating a robust assurance program that builds trust with our customers, consumers, and data partners.We partner closely across the company to ensure Plaid’s platform remains secure, resilient, and aligned with industry and regulatory expectations.

Third-party ecosystem risk is a core part of how we keep Plaid safe—we vet the security of both the vendors we rely on and the customers and partners who connect to our platform, so trust runs in both directions.

Role:

You will run security risk assessments for Plaid’s third parties end-to-end—from intake and questionnaire through risk rating, findings, and tracked exceptions.

You will assess the security posture of customers and partners onboarding to the platform with the same rigor we apply to vendors.

You will keep the third-party risk lifecycle moving—risk tiering, reassessment cadence, remediation follow-through, and a clean, current risk register.

You will help mature the program—questionnaires, tiering criteria, intake, and runbooks—so reviews get faster and more consistent as volume grows, drawing on how you’ve improved third-party risk programs before.

You will report on ecosystem risk to Security and cross-functional stakeholders, and operate as an AI power user to raise your own throughput.

Responsibilities:

Run Vendor Security Risk Assessments : Triage inbound vendor requests, run security reviews scaled to risk tier, rate the risk, and document findings and exceptions. Your assessments keep Plaid from inheriting a vendor’s security gaps and give Procurement, Privacy, and Legal a clear risk signal before contracts are signed.

Vet Customer and Partner Security Posture : Review the security practices of customers and partners onboarding to the platform, applying the same standards you use for vendors. Your reviews make sure who connects to Plaid meets the bar before they touch data—protecting consumers and the ecosystem.

Keep the Third-Party Risk Lifecycle Current : Maintain risk tiering, drive reassessments on cadence, chase remediation to closure, and keep the risk register accurate. Your follow-through keeps third-party risk a live, trustworthy picture rather than a point-in-time checkbox.

Mature the Program : Improve questionnaires, tiering criteria, intake, runbooks, and tooling as review volume grows—bringing patterns from third-party risk programs you’ve matured before. Your work moves the function from ad hoc toward fast, consistent, and scalable.

Report on Ecosystem Risk : Track assessment cycle times, backlog, open exceptions, and reassessment coverage, and report program health to stakeholders. Your reporting gives leadership real visibility into where third-party risk concentrates.

Scale Through AI and Tooling : Build and scale AI-assisted workflows for assessment review, questionnaire analysis, and reporting—and share what works. Your approach sets how the team uses AI to handle more reviews without adding headcount.

Qualifications:

Must-haves

4+ years of experience in vendor risk management

Third-party and vendor security risk assessment:

Experience running security risk assessments of third parties—reviewing questionnaires, SOC 2 and ISO reports, and security documentation, and translating them into a defensible risk rating.

Familiarity with the third-party risk lifecycle: intake, tiering, exceptions and risk acceptance, remediation tracking, and periodic reassessment.

Security and compliance knowledge:

Requirements

  • ·4+ years of experience in vendor risk management
  • ·Third-party and vendor security risk assessment:
  • ·Experience running security risk assessments of third parties—reviewing questionnaires, SOC 2 and ISO reports, and security documentation, and translating them into a defensible risk rating.
  • ·Familiarity with the third-party risk lifecycle: intake, tiering, exceptions and risk acceptance, remediation tracking, and periodic reassessment.
  • ·Security and compliance knowledge:

Benefits

No benefits package published with this listing. Ask about it at first interview.

How to apply

  1. 1Check the flexibility label above, hybrid, matches where you plan to live and work.
  2. 2Tailor your CV to the role at Plaid, mentioning your remote working experience.
  3. 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.

Found 5d ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.

Listing sourced from Company boards.

Similar roles

Other open software roles with comparable remote rules.

Browse all open roles

Free to apply, no account needed.

$118,680–$175,800 · You'll be taken to the employer's careers page.