Talent.com
Plaid
Security Analyst, Third-Party Ecosystem Risk ManagementPlaid • New York, NY, United States
Security Analyst, Third-Party Ecosystem Risk Management

Security Analyst, Third-Party Ecosystem Risk Management

Plaid • New York, NY, United States
11 days ago
Job type
  • Full-time
Job description

Security Risk Assessment Manager

We believe that the way people interact with their finances will drastically improve in the next few years. We're dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid's network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Seattle, Washington D.C., Raleigh, London, and Amsterdam.

The Security Governance, Risk, and Compliance (GRC) team is part of Plaid's security organization, focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission is to reduce the likelihood and impact of security risks while operating a robust assurance program that builds trust with our customers, consumers, and data partners. We partner closely across the company to ensure Plaid's platform remains secure, resilient, and aligned with industry and regulatory expectations.

Third-party ecosystem risk is a core part of how we keep Plaid safewe vet the security of both the vendors we rely on and the customers and partners who connect to our platform, so trust runs in both directions.

Role:

  • You will run security risk assessments for Plaid's third parties end-to-endfrom intake and questionnaire through risk rating, findings, and tracked exceptions.
  • You will assess the security posture of customers and partners onboarding to the platform with the same rigor we apply to vendors.
  • You will keep the third-party risk lifecycle movingrisk tiering, reassessment cadence, remediation follow-through, and a clean, current risk register.
  • You will help mature the programquestionnaires, tiering criteria, intake, and runbooksso reviews get faster and more consistent as volume grows, drawing on how you've improved third-party risk programs before.
  • You will report on ecosystem risk to Security and cross-functional stakeholders, and operate as an AI power user to raise your own throughput.

Responsibilities:

  • Run Vendor Security Risk Assessments: Triage inbound vendor requests, run security reviews scaled to risk tier, rate the risk, and document findings and exceptions. Your assessments keep Plaid from inheriting a vendor's security gaps and give Procurement, Privacy, and Legal a clear risk signal before contracts are signed.
  • Vet Customer and Partner Security Posture: Review the security practices of customers and partners onboarding to the platform, applying the same standards you use for vendors. Your reviews make sure who connects to Plaid meets the bar before they touch dataprotecting consumers and the ecosystem.
  • Keep the Third-Party Risk Lifecycle Current: Maintain risk tiering, drive reassessments on cadence, chase remediation to closure, and keep the risk register accurate. Your follow-through keeps third-party risk a live, trustworthy picture rather than a point-in-time checkbox.
  • Mature the Program: Improve questionnaires, tiering criteria, intake, runbooks, and tooling as review volume growsbringing patterns from third-party risk programs you've matured before. Your work moves the function from ad hoc toward fast, consistent, and scalable.
  • Report on Ecosystem Risk: Track assessment cycle times, backlog, open exceptions, and reassessment coverage, and report program health to stakeholders. Your reporting gives leadership real visibility into where third-party risk concentrates.
  • Scale Through AI and Tooling: Build and scale AI-assisted workflows for assessment review, questionnaire analysis, and reportingand share what works. Your approach sets how the team uses AI to handle more reviews without adding headcount.

Qualifications:

Must-haves

  • 4+ years of experience in vendor risk management

  • Third-party and vendor security risk assessment:

    • Experience running security risk assessments of third partiesreviewing questionnaires, SOC 2 and ISO reports, and security documentation, and translating them into a defensible risk rating.

    • Familiarity with the third-party risk lifecycle: intake, tiering, exceptions and risk acceptance, remediation tracking, and periodic reassessment.

  • Security and compliance knowledge:

    • Working knowledge of SOC 2, ISO 27001, NIST CSF, and common control domains (access control, encryption, incident response, BC/DR).

    • Ability to read a control environment and tell a real gap from an acceptable compensating control.

  • Program maturation and operational execution:

    • Experience maturing a third-party or vendor risk programimproving how it works (tiering criteria, questionnaires, workflow, automation), not just executing an existing one.

    • Track record running assessments at volume without dropping rigor.

    • Strong analytical and documentation skills: clear findings, clean tracking, and defensible risk decisions others can follow.

  • Communication and cross-functional effectiveness:

    • Clear written and verbal communicationable to explain a security risk to Procurement, Legal, or a customer without overstating or hand-waving.

    • Comfortable working across Security, Legal, Procurement, and GTM as the third-party risk point of contact.

  • AI fluency and tooling:

    • Demonstrated ability to apply AI tooling to assessment review, questionnaire analysis, and reporting to materially increase throughputand to share what works with the team.

Nice-to-have

  • A third-party-risk or audit credential (CTPRP, CISA, or CISSP), or hands-on ownership of a TPRM platform (e.g. OneTrust, ProcessUnity, Whistic, SecurityScorecard) beyond using it as an end user.

Our mission at Plaid is to unlock financial freedom for everyone. To support that mission, we seek to build a diverse team of driven individuals who care deeply about making the financial ecosystem more equitable. We recognize that strong qualifications can come from both prior work experiences and lived experiences. We encourage you to apply to a role even if your experience doesn't fully match the job description. We are always looking for team members that will bring something unique to Plaid!

Plaid is proud to be an equal opportunity employer and values diversity at our company. We do not discriminate based on race, color, national origin, ethnicity, religion or religious belief, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, military or veteran status, disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state, and local laws. Plaid is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance with your application or interviews due to a disability, please let us know at accommodations@plaid.com.

Please review our Candidate Privacy Notice here.

Additional compensation in the form(s) of equity and/or commission are dependent on the position offered. Plaid provides a comprehensive benefit plan, including medical, dental, vision, and 401(k). Pay is based on factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience and skillset, and location. Pay and benefits are subject to change at any time, consistent with the terms of any applicable compensation or benefit plans.

Create a job alert for this search

Security Analyst, Third-Party Ecosystem Risk Management • New York, NY, United States

Similar jobs

Cybersecurity and Third-Party Risk Manager

Lord AbbettJersey City, NJ, United States
Full-time

Founded in 1929, Lord Abbett is an independent firm with a singular focus on the management of money.Over the course of our history, we've earned a sterling reputation for our leadership, influence... Show more

 • Promoted

Remote Physics Expert

Micro1Eatontown, New Jersey, US
Remote
Full-time

AI data lab for training frontier models and evaluating AI agents.Experts contribute their diverse subject matter knowledge across domains such as finance, healthcare, STEM engineering, and more.AI... Show more

 • Promoted

Security & Law Enforcement (Master-at-Arms)

US NavyLeonardo, NJ, United States
Full-time

Security & Law Enforcement (Master-at-Arms).This role is open to both entry-level applicants and candidates with prior experience.Those with a background in Law Enforcement, Corrections/Parole, or ... Show more

 • Promoted

Security Manager FO2 & F80 Bronx

WesthabBronx, NY, United States
Full-time

The Security Manager is responsible for maintaining the safety and security of clients and staff in a family (with children) shelter operation.This position reports to the Program Director and is r... Show more

 • Promoted

Ecosystem Product Security Director

TechChain TalentNew York, NY, United States
Full-time

Ecosystem Product Security Director.New York, New York, United States.About the Job Ecosystem Product Security Director.Stellar is a decentralized, public blockchain that gives developers the tools... Show more

 • Promoted

Security Practice Lead (Nationwide)

PresidioNew York City, NY, United States
Full-time

DescriptionPresidio, Where Teamwork and Innovation Shape the Future AtPresidio, we're at the forefront of a global technology revolution, transforming industries throughcutting-edge digital solutio... Show more

 • Promoted

Engineering Manager - Corporate Security - Remote (US only)

BrightCrew LtdNew York City, NY, United States
Remote
Full-time

About the RoleWe are seeking a hands-on software and security engineering leader to strengthen the security of user endpoints, enterprise applications, and network communications at scale.In this r... Show more

 • Promoted

Compliance Analyst

Solar LandscapeAsbury Park, NJ, United States
Part-time

Compliance AnalystSolar Landscape is the leading commercial rooftop solar developer in the U.Only 4% of commercial rooftops host solar today we're changing that, fast.Commercial rooftop solar is th... Show more

 • Promoted

RISK ANALYST- Exchange Place, NJ

StaffingJersey City, NJ, United States
Full-time

Ensure assessments, project and task deliverable dates are met.Conduct Information Security, Information Technology, Cyber Security, application risk, Disaster Recovery Planning, Risk Control Self-... Show more

 • Promoted

Senior Risk Management Specialist

Excel GensNew York, NY, United States
Full-time

Senior Specialist, Third-Party Risk Management.Client is seeking a Senior Specialist, Third-Party Risk Management (TPRM), to support the identification, assessment, and oversight of third-party ris... Show more

 • Promoted

Specialist Solutions Engineer - Security

AHEAD USANew York City, NY, United States
Full-time

AHEAD builds platforms for digital business.By weaving together advances in cloud infrastructure, automation and analytics, and software delivery, we help enterprises deliver on the promise of digi... Show more

 • Promoted

Director, Research Americas Equity US Software Analyst

UBSNew York City, NY, United States
Permanent

Your roleUBS SECURITIES LLC is seeking a Director, Research Americas Equity US Software Analyst in New York, NY.Are you an innovative thinker? Are you focused on the details, even when under pressu... Show more

 • Promoted

FT Associate Asset Protection - Security - 2814

Stop & ShopNeptune, NJ, United States
Full-time

At Stop & Shop, we are dedicated to creating and maintaining a culture where the diverse backgrounds and experiences of our associates are celebrated.We believe that our strength lies in our differ... Show more

 • Promoted

Loss Prevention Clerk

Costco Wholesale Corp.Asbury Park, NJ, United States
Full-time

Responsibilities: Protect company assets by reducing shrink and preventing theft; Patrol warehouse and perimeter to monitor safety and security; Investigate theft, detain suspects when warranted, a... Show more

 • Promoted

Security Officer - PT & FT available

Inter-con SecurityNeptune, NJ, United States
Full-time

Security Guard / Safety Officer / Patrol] - Industry Leading Pay / Opportunity for Medical-Dental-Holidays-Vacation-Sick Pay-401(k) / Uniform and equipment provided / Recognition and Reward Program... Show more

 • Promoted

Risk Analyst

Cleary Gottlieb Steen & Hamilton LLPNew York, NY, United States
Full-time

Cleary Gottlieb is a pioneer in globalizing the legal profession.We have 14 offices in major financial centers around the world, but we operate as a single, integrated global partnership and not as... Show more

 • Promoted

Director, Cyber Security

Veracity SolutionsMontvale, NJ, United States
Full-time

Montvale, NJ, Ogden, UT - Multiple locations (Must be onsite at least 3 days/week Non-negotiable) Full Time Work Model: Hybrid (Flexible WFH days).The Director of Cyber Security will lead our info... Show more

 • Promoted

Compliance Analyst- Corporate

INTERSTATE WASTE SERVICESTeaneck, NJ, United States
Full-time

Compliance AnalystInterstate Waste Services is the most progressive and innovative provider of solid waste and recycling services in the greater New York, New Jersey and Connecticut markets with a ... Show more

 • Promoted

Senior Data Center Risk Management Specialist

PkazaNew York, NY, United States
Full-time

Senior Data Center Risk Management Specialist - NYC.This opportunity is working directly with an established best-in-class insurance broker in the NYC region whose focus is in providing mission-cri... Show more

 • Promoted

Store Protection Specialist

Ross StoresMiddletown, NJ, United States
Full-time

General Purpose: This position provides a visible presence at the store entrances/exits, mitigating theft and fraud and maintaining a safe and secure environment for associates and customers.The sp... Show more