Security Engineer GRC
Plaid is a financial technology company providing APIs and network connectivity for businesses to build financial products. Its platform supports bank-account linking, financial data access, identity verification, fraud and risk tools, credit underwriting, and bank payments.
Maintainer signals as of 8/12/2026
Funding history
Projects
About Plaid
Plaid operates a financial data network and API platform that lets businesses connect to financial institutions and build financial experiences. Its products support account and identity verification, real-time balance and transaction data, investment and liability data, income and underwriting workflows, fraud and AML risk checks, and multi-rail bank payments. It serves developers, businesses, financial institutions, platforms, lenders, banks, and consumer-facing financial-product providers.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You own GRC Engineering, define its architecture, build codified sources of truth and live evidence pipelines, automate continuous controls monitoring, create risk dashboards and reporting, conduct risk assessments, automate operational work, embed compliance checks into CI/CD, and develop AI-assisted compliance workflows.
Requirements
- Strong Python and SQL
- Experience building API and webhook integrations
- Experience owning an internal tool or service end to end
- Hands-on experience with AWS and cloud-native security controls
- Experience querying cloud, GitHub, and SaaS logs
- Proficiency with dashboarding and data visualization tools
- Experience building continuous controls monitoring
- Experience modeling controls, policies, and framework mappings as structured data
- Experience with Terraform and policy-as-code using OPA/Rego or Sentinel
- Knowledge of SOC 2, ISO 27001/27701, and NIST CSF/800-53
- Experience conducting security or technology risk assessments
- Experience building AI-assisted workflows
Responsibilities
- Define the GRC Engineering discipline and architecture
- Build pipelines and codified sources of truth for controls and policies
- Automate evidence collection, control testing, and monitoring
- Write and tune detection logic for drift and misconfiguration
- Build dashboards and SQL-driven risk reporting
- Conduct security and technology risk assessments
- Automate evidence pulls, access reviews, vendor reviews, questionnaires, and risk-register upkeep
- Embed compliance checks into CI/CD
- Prototype self-healing policies
- Build continuously validated machine-readable evidence
Benefits
- Equity
- Medical insurance
- Dental insurance
- Vision insurance
- 401(k)
