Talent.com
Plaid
Security Analyst, Third-Party Ecosystem Risk ManagementPlaid • Raleigh, NC, United States
Security Analyst, Third-Party Ecosystem Risk Management

Security Analyst, Third-Party Ecosystem Risk Management

Plaid • Raleigh, NC, United States
2 days ago
Job type
  • Full-time
Job description

Security Risk Management Role

We believe that the way people interact with their finances will drastically improve in the next few years. We're dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid's network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam.

The Security Governance, Risk, and Compliance (GRC) team is part of Plaid's security organization, focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission is to reduce the likelihood and impact of security risks while operating a robust assurance program that builds trust with our customers, consumers, and data partners. We partner closely across the company to ensure Plaid's platform remains secure, resilient, and aligned with industry and regulatory expectations.

Third-party ecosystem risk is a core part of how we keep Plaid safewe vet the security of both the vendors we rely on and the customers and partners who connect to our platform, so trust runs in both directions.

Role

You will run security risk assessments for Plaid's third parties end-to-endfrom intake and questionnaire through risk rating, findings, and tracked exceptions.

You will assess the security posture of customers and partners onboarding to the platform with the same rigor we apply to vendors.

You will keep the third-party risk lifecycle movingrisk tiering, reassessment cadence, remediation follow-through, and a clean, current risk register.

You will help mature the programquestionnaires, tiering criteria, intake, and runbooksso reviews get faster and more consistent as volume grows, drawing on how you've improved third-party risk programs before.

You will report on ecosystem risk to Security and cross-functional stakeholders, and operate as an AI power user to raise your own throughput.

Responsibilities

  • Run Vendor Security Risk Assessments : Triage inbound vendor requests, run security reviews scaled to risk tier, rate the risk, and document findings and exceptions. Your assessments keep Plaid from inheriting a vendor's security gaps and give Procurement, Privacy, and Legal a clear risk signal before contracts are signed.

  • Vet Customer and Partner Security Posture : Review the security practices of customers and partners onboarding to the platform, applying the same standards you use for vendors. Your reviews make sure who connects to Plaid meets the bar before they touch dataprotecting consumers and the ecosystem.

  • Keep the Third-Party Risk Lifecycle Current : Maintain risk tiering, drive reassessments on cadence, chase remediation to closure, and keep the risk register accurate. Your follow-through keeps third-party risk a live, trustworthy picture rather than a point-in-time checkbox.

  • Mature the Program : Improve questionnaires, tiering criteria, intake, runbooks, and tooling as review volume growsbringing patterns from third-party risk programs you've matured before. Your work moves the function from ad hoc toward fast, consistent, and scalable.

  • Report on Ecosystem Risk : Track assessment cycle times, backlog, open exceptions, and reassessment coverage, and report program health to stakeholders. Your reporting gives leadership real visibility into where third-party risk concentrates.

  • Scale Through AI and Tooling : Build and scale AI-assisted workflows for assessment review, questionnaire analysis, and reportingand share what works. Your approach sets how the team uses AI to handle more reviews without adding headcount.

Qualifications

Must-haves

  • 4+ years of experience in vendor risk management

  • Third-party and vendor security risk assessment: Experience running security risk assessments of third partiesreviewing questionnaires, SOC 2 and ISO reports, and security documentation, and translating them into a defensible risk rating.

  • Familiarity with the third-party risk lifecycle: intake, tiering, exceptions and risk acceptance, remediation tracking, and periodic reassessment.

  • Security and compliance knowledge: Working knowledge of SOC 2, ISO 27001, NIST CSF, and common control domains (access control, encryption, incident response, BC/DR). Ability to read a control environment and tell a real gap from an acceptable compensating control.

  • Program maturation and operational execution: Experience maturing a third-party or vendor risk programimproving how it works (tiering criteria, questionnaires, workflow, automation), not just executing an existing one. Track record running assessments at volume without dropping rigor. Strong analytical and documentation skills: clear findings, clean tracking, and defensible risk decisions others can follow.

  • Communication and cross-functional effectiveness: Clear written and verbal communicationable to explain a security risk to Procurement, Legal, or a customer without overstating or hand-waving. Comfortable working across Security, Legal, Procurement, and GTM as the third-party risk point of contact.

  • AI fluency and tooling: Demonstrated ability to apply AI tooling to assessment review, questionnaire analysis, and reporting to materially increase throughputand to share what works with the team.

Nice-to-have

  • A third-party-risk or audit credential (CTPRP, CISA, or CISSP), or hands-on ownership of a TPRM platform (e.g. OneTrust, ProcessUnity, Whistic, SecurityScorecard) beyond using it as an end user.

Our mission at Plaid is to unlock financial freedom for everyone. To support that mission, we seek to build a diverse team of driven individuals who care deeply about making the financial ecosystem more equitable. We recognize that strong qualifications can come from both prior work experiences and lived experiences. We encourage you to apply to a role even if your experience doesn't fully match the job description. We are always looking for team members that will bring something unique to Plaid!

Plaid is proud to be an equal opportunity employer and values diversity at our company. We do not discriminate based on race, color, national origin, ethnicity, religion or religious belief, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, military or veteran status, disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state, and local laws. Plaid is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance with your application or interviews due to a disability, please let us know at accommodations@plaid.com.

Please review our Candidate Privacy Notice here.

Additional compensation in the form(s) of equity and/or commission are dependent on the position offered. Plaid provides a comprehensive benefit plan, including medical, dental, vision, and 401(k). Pay is based on factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience and skillset, and location. Pay and benefits are subject to change at any time, consistent with the terms of any applicable compensation or benefit plans.

Create a job alert for this search

Security Analyst, Third-Party Ecosystem Risk Management • Raleigh, NC, United States

Similar jobs

Research and Technology Protection (RTP) and Risk Based Review Specialist (5947)

Three Saints BayRaleigh, NC, United States
Full-time

Research and Technology Protection Specialist.Bennett Aerospace, a subsidiary of Three Saints Bay, LLC and a Federal Government Contractor industry leader, is seeking a Research and Technology Prot... Show more

 • Promoted

Consumer Opinion Research Participant

GL IncDunn, North Carolina
$15.00 hourly
Part-time +1

Product Testers are wanted to work from home nationwide in the US to fulfill upcoming contracts with national and international companies.We guarantee 15-25 hours per week with an hourly pay of bet... Show more

 • Promoted

Market Research Participant

GL IncDunn, North Carolina
$15.00 hourly
Part-time +1

Product Testers are wanted to work from home nationwide in the US to fulfill upcoming contracts with national and international companies.We guarantee 15-25 hours per week with an hourly pay of bet... Show more

 • Promoted

Project Management Information Security

Global Channel ManagementRaleigh, NC, United States
Full-time

Project Management Information Security.Raleigh, North Carolina, United States.Project Manager Information Security needs 6 years of experience in Advanced Project Management and technology knowled... Show more

 • Promoted

Risk Analysis

Diverse LynxRaleigh, NC, United States
Full-time

Risk identification, assessment, mitigation, and continuous monitoring across business and technology functions.Experienced in implementing and strengthening enterprise risk management frameworks, ... Show more

 • Promoted

Epic Systems Analyst II Grand Central/Prelude/RTE *hybrid remote*

WakeMedRaleigh, NC, United States
Remote
Full-time

Epic Systems Analyst II - Business Application Join to apply for the Epic Systems Analyst II - Business Application role at WakeMed Epic Systems Analyst II - Business Application Join to apply for ... Show more

 • Promoted

Security Consultant - Engineering

SHI GmbHRaleigh, NC, United States
Full-time

About UsSince 1989, SHI International Corp.We've grown every year since, and today we're proud to be a $16 billion global provider of IT solutions and services.Over 17,000 organizations worldwide r... Show more

 • Promoted

Risk Analyst

ArtechRaleigh, NC, United States
Full-time

This role involves risk identification, assessment, mitigation, and continuous monitoring across business and technology functions.The candidate will be responsible for implementing and strengtheni... Show more

 • Promoted

Manager Security Compliance and Risk Management

RELXRaleigh, NC, United States
Full-time

Manager, Security Security Compliance & Risk Management.Own and operate the enterprise technology and security risk management program, including risk identification, scoring, tracking, and mainte... Show more

 • Promoted

Disaster Recovery Analyst

ACL DigitalRaleigh, NC, United States
Full-time

The MissionThe exists to provide compassionate care to those in need.Our network of generous donors, volunteers and employees share a mission of preventing and relieving suffering, here at home and... Show more

 • Promoted

Epic Systems Analyst II - Grand Central / Prelude / RTE ohybrid remote o

WakeMedRaleigh, NC, United States
Remote
Full-time

OverviewThe Systems Analyst II, Epic Business Applications leads the build, rollout, and support of the assigned application(s).Responsible for all aspects of application support to include but not... Show more

 • Promoted

Operational Readiness Analyst (Remote)

First Citizens BancSharesRaleigh, NC, United States
Remote
Full-time

Operational Readiness SpecialistThis is a remote role that may be hired in several markets across the United States.As First Citizens Bank continues to grow and mature within the Large Financial In... Show more

 • Promoted

Security Specialist- Mid Level // Raleigh, NC // Remote

My3TechRaleigh, NC, United States
Remote
Full-time +1

Security Specialist- Mid Level.Location: 221 E Lane Street, Raleigh, NC 27601.The Compliance Officer will be familiar with risk management, comfortable leading internal risk assessments, and posses... Show more

 • Promoted

NCDIT - Business & Policy Analyst @ 3700 Wake Forest Rd, Raleigh NC 27609 (Local Remote)

My3TechRaleigh, NC, United States
Remote
Full-time

NCDIT - Business & Policy Analyst.Able to articulate IT value propositions from both a business and technical perspective.Experience writing and reviewing IT, privacy, and/or security policies.Abil... Show more

 • Promoted

Third Party Risk Management Analyst II

State Employeescredit UnionRaleigh, NC, United States
Full-time

Third-Party Risk Management Analyst II.If you are motivated and believe in the credit union philosophy of "People Helping People," join our team!.The Third-Party Risk Management (TPRM) program prov... Show more

 • Promoted

Senior, Technology 3rd Party Risk - Tax Transformation

DeloitteRaleigh, NC, United States
Full-time

Senior Consultant - Technology Third Party Risk Management.The Deloitte Tax LLP's (Deloitte Tax) Tax Transformation Office (TTO) is pivotal to supporting Deloitte Tax client service delivery by opt... Show more

 • Promoted

Principal Product Operations and Risk Analyst

CircleRaleigh, NC, United States
Full-time

Principal Product Operations And Risk Analyst.Circle (NYSE: CRCL) is one of the world's leading internet financial platform companies, building the foundation of a more open, global economy through... Show more

 • Promoted

Lead Identity & Access Management Security Specialist

AccentureRaleigh, NC, United States
Full-time

Join Our TeamAt Accenture Security, we empower organizations to enhance their cybersecurity measures at every stage, from preparation to recovery.Recognizing the unique challenges faced in differen... Show more

 • Promoted

Remote Legal Expert

Turing Dunn, North Carolina
Remote
Full-time
Quick Apply

Turing invites Legal Experts to join projects that fine-tune AI models like ChatGPT.If you enjoy applying legal reasoning, analyzing complex cases, and providing clear, structured feedback, this is... Show more

 • Promoted

Remote Chemistry Expert (PhD) - $100+ per hour

Turing Dunn, North Carolina
Remote
Full-time
Quick Apply

Remote contract for PhDs in Chemistry, Chemical Engineering, or related fields.Work on cutting-edge projects with top AI labs while earning up to $100+/hour, fully remote, with flexible weekly hour... Show more