Enter a job title or keyword

Security Analyst, Third-Party Ecosystem Risk Management

Plaid


Job Location:

New York City, NY - USA

Yearly Salary: USD 118680 - 175800
Posted: 15 August 2026 (19 days ago)
Application Deadline: 12 November 2026
Vacancies: 1 Vacancy

Job Summary

We believe that the way people interact with their finances will drastically improve in the next few years. Were dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo SoFi several of the Fortune 500 and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaids network covers 12000 financial institutions across the US Canada UK and Europe. Founded in 2013 the company is headquartered in San Francisco with offices in New York Washington D.C. London and Amsterdam.

Team:

The Security Governance Risk and Compliance (GRC) team is part of Plaids security organization focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission is to reduce the likelihood and impact of security risks while operating a robust assurance program that builds trust with our customers consumers and data partner closely across the company to ensure Plaids platform remains secure resilient and aligned with industry and regulatory expectations.

Third-party ecosystem risk is a core part of how we keep Plaid safewe vet the security of both the vendors we rely on and the customers and partners who connect to our platform so trust runs in both directions.

Role:

  • You will run security risk assessments for Plaids third parties end-to-endfrom intake and questionnaire through risk rating findings and tracked exceptions.

  • You will assess the security posture of customers and partners onboarding to the platform with the same rigor we apply to vendors.

  • You will keep the third-party risk lifecycle movingrisk tiering reassessment cadence remediation follow-through and a clean current risk register.

  • You will help mature the programquestionnaires tiering criteria intake and runbooksso reviews get faster and more consistent as volume grows drawing on how youve improved third-party risk programs before.

  • You will report on ecosystem risk to Security and cross-functional stakeholders and operate as an AI power user to raise your own throughput.

Responsibilities:

  • Run Vendor Security Risk Assessments: Triage inbound vendor requests run security reviews scaled to risk tier rate the risk and document findings and exceptions. Your assessments keep Plaid from inheriting a vendors security gaps and give Procurement Privacy and Legal a clear risk signal before contracts are signed.

  • Vet Customer and Partner Security Posture: Review the security practices of customers and partners onboarding to the platform applying the same standards you use for vendors. Your reviews make sure who connects to Plaid meets the bar before they touch dataprotecting consumers and the ecosystem.

  • Keep the Third-Party Risk Lifecycle Current: Maintain risk tiering drive reassessments on cadence chase remediation to closure and keep the risk register accurate. Your follow-through keeps third-party risk a live trustworthy picture rather than a point-in-time checkbox.

  • Mature the Program: Improve questionnaires tiering criteria intake runbooks and tooling as review volume growsbringing patterns from third-party risk programs youve matured before. Your work moves the function from ad hoc toward fast consistent and scalable.

  • Report on Ecosystem Risk: Track assessment cycle times backlog open exceptions and reassessment coverage and report program health to stakeholders. Your reporting gives leadership real visibility into where third-party risk concentrates.

  • Scale Through AI and Tooling: Build and scale AI-assisted workflows for assessment review questionnaire analysis and reportingand share what works. Your approach sets how the team uses AI to handle more reviews without adding headcount.

Qualifications:

Must-haves

  • 4 years of experience in vendor risk management

  • Third-party and vendor security risk assessment:

    • Experience running security risk assessments of third partiesreviewing questionnaires SOC 2 and ISO reports and security documentation and translating them into a defensible risk rating.

    • Familiarity with the third-party risk lifecycle: intake tiering exceptions and risk acceptance remediation tracking and periodic reassessment.

  • Security and compliance knowledge:

    • Working knowledge of SOC 2 ISO 27001 NIST CSF and common control domains (access control encryption incident response BC/DR).

    • Ability to read a control environment and tell a real gap from an acceptable compensating control.

  • Program maturation and operational execution:

    • Experience maturing a third-party or vendor risk programimproving how it works (tiering criteria questionnaires workflow automation) not just executing an existing one.

    • Track record running assessments at volume without dropping rigor.

    • Strong analytical and documentation skills: clear findings clean tracking and defensible risk decisions others can follow.

  • Communication and cross-functional effectiveness:

    • Clear written and verbal communicationable to explain a security risk to Procurement Legal or a customer without overstating or hand-waving.

    • Comfortable working across Security Legal Procurement and GTM as the third-party risk point of contact.

  • AI fluency and tooling:

    • Demonstrated ability to apply AI tooling to assessment review questionnaire analysis and reporting to materially increase throughputand to share what works with the team.

Nice-to-have

  • A third-party-risk or audit credential (CTPRP CISA or CISSP) or hands-on ownership of a TPRM platform (e.g. OneTrust ProcessUnity Whistic SecurityScorecard) beyond using it as an end user.

Our mission at Plaid is to unlock financial freedom for everyone. To support that mission we seek to build a diverse team of driven individuals who care deeply about making the financial ecosystem more equitable. We recognize that strong qualifications can come from both prior work experiences and lived experiences. We encourage you to apply to a role even if your experience doesnt fully match the job description. We are always looking for team members that will bring something unique to Plaid!

Plaid is proud to be an equal opportunity employer and values diversity at our company. We do not discriminate based on race color national origin ethnicity religion or religious belief sex (including pregnancy childbirth or related medical conditions) sexual orientation gender gender identity gender expression transgender status sexual stereotypes age military or veteran status disability or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories consistent with applicable federal state and local laws. Plaid is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance with your application or interviews due to a disability please let us know at

Please review our Candidate Privacy Notice here.

Additional compensation in the form(s) of equity and/or commission are dependent on the position offered. Plaid provides a comprehensive benefit plan including medical dental vision and 401(k). Pay is based on factors such as (but not limited to) scope and responsibilities of the position candidates work experience and skillset and location. Pay and benefits are subject to change at any time consistent with the terms of any applicable compensation or benefit plans.


Required Experience:

IC


About Company

Company Logo

Plaid helps all companies build fintech solutions by making it easy, safe and reliable for people to connect their financial data to apps and services.

View Profile View Profile