Security Analyst, Third-Party Ecosystem Risk Management
Plaid is a financial technology company providing APIs and network connectivity for businesses to build financial products. Its platform supports bank-account linking, financial data access, identity verification, fraud and risk tools, credit underwriting, and bank payments.
Maintainer signals as of 8/12/2026
Funding history
Projects
About Plaid
Plaid operates a financial data network and API platform that lets businesses connect to financial institutions and build financial experiences. Its products support account and identity verification, real-time balance and transaction data, investment and liability data, income and underwriting workflows, fraud and AML risk checks, and multi-rail bank payments. It serves developers, businesses, financial institutions, platforms, lenders, banks, and consumer-facing financial-product providers.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will run third-party security risk assessments from intake through risk rating and remediation, assess customers and partners, maintain risk tiering and the risk register, mature questionnaires and workflows, report on ecosystem risk, and build AI-assisted assessment and reporting workflows.
Requirements
- 4+ years of vendor risk management experience
- Third-party security risk assessment experience
- Vendor security risk assessment experience
- SOC 2 knowledge
- ISO 27001 knowledge
- NIST CSF knowledge
- Access control knowledge
- Encryption knowledge
- Incident response knowledge
- Business continuity and disaster recovery knowledge
- Third-party risk lifecycle knowledge
- Third-party risk program maturation experience
- Assessment execution at volume
- Analytical skills
- Documentation skills
- Written communication skills
- Verbal communication skills
- AI tooling experience
- CTPRP, CISA, or CISSP credential
- TPRM platform experience
Responsibilities
- Run vendor security risk assessments
- Review vendor questionnaires, SOC 2 reports, ISO reports, and security documentation
- Rate risk and document findings and exceptions
- Vet customer and partner security posture
- Maintain risk tiering and reassessment cadence
- Track remediation to closure
- Maintain the risk register
- Improve questionnaires, tiering criteria, intake, runbooks, and tooling
- Report on ecosystem risk and program health
- Build AI-assisted workflows for assessment review, questionnaire analysis, and reporting
Benefits
- Equity
- Medical insurance
- Dental insurance
- Vision insurance
- 401(k)
