Security Engineer GRC

Plaid is a financial data network and fintech infrastructure company that helps people securely connect financial accounts to digital financial services.

Series D0 current maintainers0 active leadsTeam intelligence

Maintainer signals as of 9/2/2026

San Francisco, United States

Funding history

About Plaid Inc.

Plaid provides developer infrastructure and financial tools for account connectivity, financial data access, bank payments, identity verification, AML monitoring, credit and underwriting, and fraud prevention. Its network supports thousands of fintech companies and more than 12,000 financial institutions across the United States, Canada, the United Kingdom, and Europe.

View jobs by Plaid Inc.

Skills

Candidate Availability

Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

Own GRC Engineering at Plaid by defining its architecture, building codified sources of truth and live evidence pipelines, automating continuous controls monitoring, creating risk dashboards and reporting, conducting risk assessments, automating operational work, embedding compliance checks into CI/CD, and developing AI-assisted compliance workflows.

Requirements

  • Strong Python and SQL
  • Experience building API and webhook integrations
  • Experience owning an internal tool or service end to end
  • Hands-on experience with AWS and cloud-native security controls
  • Experience querying cloud, GitHub, and SaaS logs
  • Proficiency with dashboarding and data visualization tools
  • Experience building continuous controls monitoring
  • Experience modeling controls, policies, and framework mappings as structured data
  • Experience with Terraform and policy-as-code using OPA/Rego or Sentinel
  • Knowledge of SOC 2, ISO 27001/27701, and NIST CSF/800-53
  • Experience conducting security or technology risk assessments
  • Experience building AI-assisted workflows

Responsibilities

  • Define the GRC Engineering discipline and architecture
  • Build pipelines and codified sources of truth for controls and policies
  • Automate evidence collection, control testing, and monitoring
  • Write and tune detection logic for drift and misconfiguration
  • Build dashboards and SQL-driven risk reporting
  • Conduct security and technology risk assessments
  • Automate evidence pulls, access reviews, vendor reviews, questionnaires, and risk-register upkeep
  • Embed compliance checks into CI/CD
  • Prototype self-healing policies
  • Build continuously validated machine-readable evidence

Benefits

  • Equity
  • Medical insurance
  • Dental insurance
  • Vision insurance
  • 401(k)