Security Analyst, Third-Party Ecosystem Risk Management

Plaid
New York, Seattle, Raleigh, San Francisco
Workplace: HybridFull timeUSD 118,680 - 175,800 annuallyFunction: CybersecurityExperience: 4+ yearsSkills: ["Analytical skills","Documentation","Written communication","Verbal communication","Cross-functional collaboration"]

Own end-to-end security risk assessments for Plaid’s third parties, from intake and questionnaires through risk rating, findings, and tracked exceptions. Assess the security posture of customers and partners onboarding, maintain a current risk register, and drive reassessments and remediation follow-through. Help mature the third-party risk program (tiering criteria, intake, runbooks) and report on ecosystem risk health, while leveraging AI-assisted workflows to increase throughput.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Plaid
Plaid
1 day ago

Security Analyst, Third-Party Ecosystem Risk Management

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 19 hours agoStatus: Live

Job Summary

Own end-to-end security risk assessments for Plaid’s third parties, from intake and questionnaires through risk rating, findings, and tracked exceptions. Assess the security posture of customers and partners onboarding, maintain a current risk register, and drive reassessments and remediation follow-through. Help mature the third-party risk program (tiering criteria, intake, runbooks) and report on ecosystem risk health, while leveraging AI-assisted workflows to increase throughput.
Location: New York, Seattle, Raleigh, San Francisco
Workplace: Hybrid
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Run vendor security risk assessments end-to-end: triage inbound requests, conduct scaled reviews by risk tier, rate risk, and document findings and exceptions.
  • •Vet customer and partner security posture during onboarding, applying the same standards used for vendors.
  • •Maintain and update the third-party risk lifecycle: risk tiering, reassessment cadence, remediation follow-through, and a clean, current risk register.
  • •Mature the program by improving questionnaires, tiering criteria, intake, runbooks, and tooling as volume grows.
  • •Report on ecosystem risk (cycle times, backlog, open exceptions, and reassessment coverage) and use AI to increase assessment throughput.

Pay and Benefits

Salary: USD 118,680 - 175,800 annually
Perks:Health InsuranceDentalVision401k

Key Requirements

  • •4+ years of experience in vendor risk management.
  • •Run security risk assessments for third parties, translating questionnaires and security documentation (e.g., SOC 2, ISO reports) into defensible risk ratings.
  • •Understand the third-party risk lifecycle: intake, tiering, exceptions/risk acceptance, remediation tracking, and periodic reassessment.
  • •Working knowledge of SOC 2, ISO 27001, NIST CSF, and common control domains (access control, encryption, incident response, BC/DR).
  • •Mature and operate third-party risk programs at volume while maintaining rigor, with strong analytical and documentation skills.
Experience:4+ yearsVendor risk managementThird-party risk managementSecurity complianceInformation securitySecurity governance
Skills:Analytical skillsDocumentationWritten communicationVerbal communicationCross-functional collaboration
Tech Stack:SOC 2ISO 27001NIST CSFQuestionnairesRunbooksRisk registerOneTrustProcessUnityWhisticSecurityScorecardAI-assisted workflows

Company Brief

Plaid
Provides APIs that enable applications to connect with users’ bank accounts, verify financial data, and power payment and account verification workflows for fintechs and financial services companies.
Industry: Fintech Infrastructure
Company Size: Enterprise (1,001+ employees)
Growth: Scaleup
Valuation: Unicorn (USD 1B+)
Funding: Series D
Headquarters: San Francisco, United States
Founded: 2013
WebsiteLinkedIn