Plaid

Security Analyst, Third-Party Ecosystem Risk Management

Plaid$95K — $115K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 4+ years of experience in vendor risk management
  • Experience running security risk assessments, including reviewing questionnaires and translating findings into risk ratings.
  • Familiarity with the third-party risk lifecycle, including intake and remediation tracking.
  • Working knowledge of SOC 2, ISO 27001, NIST CSF, and common control domains.
  • Experience maturing a third-party risk program and improving operational workflows.
  • Strong analytical skills for clear documentation and defensible risk decisions.
  • Effective communication skills to explain security risks to cross-functional teams.

Responsibilities

  • Run vendor security risk assessments, triaging requests and documenting findings to signal risks before signing contracts.
  • Vet the security posture of customers and partners, ensuring they meet required standards before accessing data.
  • Maintain the third-party risk lifecycle with up-to-date risk tiering, reassessments, and accurate risk registers.
  • Mature the risk management program, improving tools and workflows for consistent and scalable reviews.
  • Report on ecosystem risk to provide visibility into assessment cycles, backlogs, and exceptions.
  • Scale workflows through AI and tooling to increase throughput without adding headcount.

Benefits

  • Comprehensive medical, dental, and vision plans.
  • 401(k) plan to support retirement savings.
  • Equity and/or commission opportunities, based on the position offered.
Full Job Description
Team:

The Security Governance, Risk, and Compliance (GRC) team is part of Plaid's security organization, focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission is to reduce the likelihood and impact of security risks while operating a robust assurance program that builds trust with our customers, consumers, and data partners.We partner closely across the company to ensure Plaid's platform remains secure, resilient, and aligned with industry and regulatory expectations.

Third-party ecosystem risk is a core part of how we keep Plaid safe-we vet the security of both the vendors we rely on and the customers and partners who connect to our platform, so trust runs in both directions.

Role:
  • You will run security risk assessments for Plaid's third parties end-to-end-from intake and questionnaire through risk rating, findings, and tracked exceptions.
  • You will assess the security posture of customers and partners onboarding to the platform with the same rigor we apply to vendors.
  • You will keep the third-party risk lifecycle moving-risk tiering, reassessment cadence, remediation follow-through, and a clean, current risk register.
  • You will help mature the program-questionnaires, tiering criteria, intake, and runbooks-so reviews get faster and more consistent as volume grows, drawing on how you've improved third-party risk programs before.
  • You will report on ecosystem risk to Security and cross-functional stakeholders, and operate as an AI power user to raise your own throughput.


Responsibilities:
  • Run Vendor Security Risk Assessments: Triage inbound vendor requests, run security reviews scaled to risk tier, rate the risk, and document findings and exceptions. Your assessments keep Plaid from inheriting a vendor's security gaps and give Procurement, Privacy, and Legal a clear risk signal before contracts are signed.
  • Vet Customer and Partner Security Posture: Review the security practices of customers and partners onboarding to the platform, applying the same standards you use for vendors. Your reviews make sure who connects to Plaid meets the bar before they touch data-protecting consumers and the ecosystem.
  • Keep the Third-Party Risk Lifecycle Current: Maintain risk tiering, drive reassessments on cadence, chase remediation to closure, and keep the risk register accurate. Your follow-through keeps third-party risk a live, trustworthy picture rather than a point-in-time checkbox.
  • Mature the Program: Improve questionnaires, tiering criteria, intake, runbooks, and tooling as review volume grows-bringing patterns from third-party risk programs you've matured before. Your work moves the function from ad hoc toward fast, consistent, and scalable.
  • Report on Ecosystem Risk: Track assessment cycle times, backlog, open exceptions, and reassessment coverage, and report program health to stakeholders. Your reporting gives leadership real visibility into where third-party risk concentrates.
  • Scale Through AI and Tooling: Build and scale AI-assisted workflows for assessment review, questionnaire analysis, and reporting-and share what works. Your approach sets how the team uses AI to handle more reviews without adding headcount.


Qualifications:

Must-haves
  • 4+ years of experience in vendor risk management
  • Third-party and vendor security risk assessment:
    • Experience running security risk assessments of third parties-reviewing questionnaires, SOC 2 and ISO reports, and security documentation, and translating them into a defensible risk rating.
    • Familiarity with the third-party risk lifecycle: intake, tiering, exceptions and risk acceptance, remediation tracking, and periodic reassessment.
  • Security and compliance knowledge:
    • Working knowledge of SOC 2, ISO 27001, NIST CSF, and common control domains (access control, encryption, incident response, BC/DR).
    • Ability to read a control environment and tell a real gap from an acceptable compensating control.
  • Program maturation and operational execution:
    • Experience maturing a third-party or vendor risk program-improving how it works (tiering criteria, questionnaires, workflow, automation), not just executing an existing one.
    • Track record running assessments at volume without dropping rigor.
    • Strong analytical and documentation skills: clear findings, clean tracking, and defensible risk decisions others can follow.
  • Communication and cross-functional effectiveness:
    • Clear written and verbal communication-able to explain a security risk to Procurement, Legal, or a customer without overstating or hand-waving.
    • Comfortable working across Security, Legal, Procurement, and GTM as the third-party risk point of contact.
  • AI fluency and tooling:
    • Demonstrated ability to apply AI tooling to assessment review, questionnaire analysis, and reporting to materially increase throughput-and to share what works with the team.


Nice-to-have
  • A third-party-risk or audit credential (CTPRP, CISA, or CISSP), or hands-on ownership of a TPRM platform (e.g. OneTrust, ProcessUnity, Whistic, SecurityScorecard) beyond using it as an end user.


Additional compensation in the form(s) of equity and/or commission are dependent on the position offered. Plaid provides a comprehensive benefit plan, including medical, dental, vision, and 401(k). Pay is based on factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience and skillset, and location. Pay and benefits are subject to change at any time, consistent with the terms of any applicable compensation or benefit plans.

About Plaid

Plaid is a financial services company based in New York City. The company builds a technology platform, which enables applications to connect with users' bank accounts. Plaid focuses on enabling consumers and businesses to interact with their bank accounts, check balances, and make payments through financial technology applications. The company was founded in 2013 by Zach Perret and William Hockey. In January 2020, Visa announced that it would acquire Plaid for $5.3 billion. The acquisition was completed in January 2021.
Learn more about Plaid
Size
600 employees
Industry
Founded
2011

Similar Jobs

More Jobs at Plaid

More Information Technology Jobs

Find similar Security Analyst, Third-Party Ecosystem Risk Management jobs: