Plaid
Senior Security Analyst, Customer Assurance
New York City Office · Senior
Sponsorship not specified$53k-$800kDetected 22 days ago
CybersecurityPenetration TestingComplianceNegotiationAuditingContract ManagementLeadershipCommunicationInternal Audit
About the role
- The Security Governance, Risk, and Compliance team is part of Plaid's security organization, focused on enabling the business by proactively managing information security risks and maintaining effective controls.
- You'll be the direct owner of Plaid's Security Contracts work-stream, responsible for how security contract reviews get done, how quickly they move, and how the program improves over time.
- You'll review security provisions in customer MSAs, DPAs, and security addenda, identify unacceptable clauses, and provide Legal and GTM with clear, actionable feedback that helps move deals forward.
Responsibilities
- Lead security contract reviews across customer MSAs, DPAs, security addenda, and security exhibits by identifying unacceptable clauses, forming a clear security position, and providing Legal with actionable feedback they can take directly into negotiations.
- Design and own the end-to-end Security Contracts program infrastructure, including intake processes, tiered SLAs, security positions runbooks, and handoff protocols with Legal and GTM.
- Join customer and data partner calls as Plaid's security subject matter expert, building trust through patient, clear, and collaborative communication.
- Build and scale AI-assisted workflows for security assurance, contract review, questionnaire completion, clause library maintenance, pattern analysis, and reporting.
- You'll also build the playbooks, processes, and program infrastructure that make the work-stream scalable, use data and pattern analysis to proactively reduce friction, and operate as an AI power user to maximize throughput.
Requirements
- 6+ years of experience in security assurance, security GRC, security compliance, or a related information security role with meaningful ownership of customer- or partner-facing security workflows.
- Experience reviewing security provisions in MSAs, DPAs, and security addenda - and translating that expertise into clear positions Legal can take directly into negotiations.
- Ability to translate a company's security posture and risk appetite into clear, defensible contract positions and hold those positions through multiple negotiation cycles.
- Working knowledge of SOC 2, ISO 27001, NIST CSF, PCI DSS, GLBA, GDPR/CCPA, NIST 800-53, etc.
- Strong analytical skills: ability to identify patterns across a high volume of security contract asks, track pushback rates and cycle counts, and translate findings into process improvements.
- Security contract review and negotiation:
- Deep familiarity with common security clause types: e.g. incident notification windows, audit rights, encryption requirements, subprocessor obligations, data retention, and penetration testing provisions.
- Experience representing a company's security program directly to customers and financial institution partners on calls - fielding questions about security controls, compliance posture, and contractual obligations.
- Security Compliance and regulatory knowledge:
- Deep understanding of what "standard" security contract language looks like in fintech and banking agreements
- Prior experience in fintech, payments, or financial services - you understand the security expectations of data partners and regulated entities, and know how to navigate those relationships with the patience and credibility they require.
- Program design and operational maturity:
- Experience building security assurance programs - designing intake processes, tiered SLAs, escalation paths, and runbooks, not just executing within existing ones.
- Experience with metrics ownership: defining KPIs, building tracking infrastructure, and reporting on program health to cross-functional stakeholders.
Nice to have
- Experience redlining security contract language directly, beyond providing advisory feedback.
- We recognize that strong qualifications can come from both prior work experiences and lived experiences.
- We encourage you to apply to a role even if your experience doesn't fully match the job description.
- Plaid is proud to be an equal opportunity employer and values diversity at our company.
- We also consider qualified applicants with criminal histories, consistent with applicable federal, state, and local laws.
- Plaid is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process.
Skills
- Communication and cross-functional effectiveness:
- Experience working directly with Legal and GTM teams as a security subject matter expert.
- AI fluency and tooling:
- Plaid powers the tools millions of people rely on to live a healthier financial life.
- Plaid's network covers 12,000 financial institutions across the US, Canada, UK and Europe.
Compensation
- Additional compensation in the form(s) of equity and/or commission are dependent on the position offered.
Benefits
- defining KPIs, building tracking infrastructure, and reporting on program health to cross-functional stakeholders.
- Define KPIs, build dashboards, and deliver regular reporting on program health to Security and GTM leadership, including visibility into deal friction, SLA adherence, and improvement opportunities.
Company info
- Our mission is to reduce the likelihood and impact of security risks while operating a robust assurance program that builds trust with our customers, consumers, and data partners.
- We partner closely across the company to ensure Plaid's platform remains secure, resilient, and aligned with industry and regulatory expectations.
- The Security Contracts workstream is a core part of our Security Assurance program, ensuring Plaid's contractual security obligations with customers and data partners are defensible, consistent, and never a bottleneck to deal velocity, all while building trust.
- Beyond contracts, you'll support broader Security Assurance work by responding to customer security questionnaires and joining external audit calls with customers and data partners.
- Track security contract asks across deals, identify recurring patterns, and determine whether they represent gaps in Plaid's program or non-standard customer requests.
- Assess feasibility and propose recommendations to leadership when recurring asks point to program gaps, and codify existing capabilities into standard security addenda where appropriate to reduce future negotiation cycles.
This listing is sourced directly from Plaid's careers page and normalized into a canonical job model.