Plaid

Plaid

Security Analyst, Third-Party Ecosystem Risk Management

New York City Office

Sponsorship not specifiedDetected 22 days ago
CybersecurityIncident ResponseComplianceProcurementCadenceLeadershipCommunicationCISSP

Stay score

odds of building a lasting career here

40Risky
Cap-exempt (no lottery)0
Sponsors this role90
Entry-level history0
PERM / green-card track0
Lottery odds40
Fits your clock70

Thin sponsorship signal and lottery-bound. A low-probability bet with your clock running. Prioritize cap-exempt roles and proven entry-level sponsors first.

Lottery odds assume a STEM candidate.

Personalize to your clock →

Employer immigration record

from this employer's Department of Labor filings

DOL often reclassifies their job titles

The Department of Labor assigned a different occupation than this employer requested on 42% of its 12 wage determinations — against a 18% norm. The occupation sets the prevailing wage floor.Reclassification is routine and can reflect genuinely hybrid roles; it is not by itself evidence of underpayment.

Files H-1B transfers

19 transfer filings in the last year, covering 19 workers. Median labor-condition decision: 7 days. An employer that already files transfers is one that can take over an existing H-1B.

Sourced from Department of Labor LCA, PERM and prevailing-wage disclosure data. Employer matching is by name, so figures may be split across an employer's legal entities. Absence of a filing means none appears in our copy of the data, not that none exists.

Community outcomes

No reports yet — be the first to help the next applicant.

About the role

  • We believe that the way people interact with their finances will drastically improve in the next few years.
  • Plaid powers the tools millions of people rely on to live a healthier financial life.
  • We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use.

Responsibilities

  • Run Vendor Security Risk Assessments: Triage inbound vendor requests, run security reviews scaled to risk tier, rate the risk, and document findings and exceptions.
  • Keep the Third-Party Risk Lifecycle Current: Maintain risk tiering, drive reassessments on cadence, chase remediation to closure, and keep the risk register accurate.
  • Scale Through AI and Tooling: Build and scale AI-assisted workflows for assessment review, questionnaire analysis, and reporting-and share what works. Your approach sets how the team uses AI to handle more reviews without adding headcount.
  • Triage inbound vendor requests, run security reviews scaled to risk tier, rate the risk, and document findings and exceptions.
  • Vet Customer and Partner Security Posture:
  • Maintain risk tiering, drive reassessments on cadence, chase remediation to closure, and keep the risk register accurate.
  • Build and scale AI-assisted workflows for assessment review, questionnaire analysis, and reporting-and share what works.

Requirements

  • 4+ years of experience in vendor risk management
  • Experience running security risk assessments of third parties-reviewing questionnaires, SOC 2 and ISO reports, and security documentation, and translating them into a defensible risk rating.
  • Familiarity with the third-party risk lifecycle: intake, tiering, exceptions and risk acceptance, remediation tracking, and periodic reassessment.
  • Working knowledge of SOC 2, ISO 27001, NIST CSF, and common control domains (access control, encryption, incident response, BC/DR).
  • Ability to read a control environment and tell a real gap from an acceptable compensating control.
  • Experience maturing a third-party or vendor risk program-improving how it works (tiering criteria, questionnaires, workflow, automation), not just executing an existing one.
  • Track record running assessments at volume without dropping rigor.
  • Demonstrated ability to apply AI tooling to assessment review, questionnaire analysis, and reporting to materially increase throughput-and to share what works with the team.
  • Must-haves
  • Third-party and vendor security risk assessment:
  • Security and compliance knowledge:
  • Program maturation and operational execution:
  • Strong analytical and documentation skills: clear findings, clean tracking, and defensible risk decisions others can follow.
  • Clear written and verbal communication-able to explain a security risk to Procurement, Legal, or a customer without overstating or hand-waving.

Nice to have

  • A third-party-risk or audit credential (CTPRP, CISA, or CISSP), or hands-on ownership of a TPRM platform (e.g. OneTrust, ProcessUnity, Whistic, SecurityScorecard) beyond using it as an end user.
  • We recognize that strong qualifications can come from both prior work experiences and lived experiences.
  • We encourage you to apply to a role even if your experience doesn't fully match the job description.
  • We also consider qualified applicants with criminal histories, consistent with applicable federal, state, and local laws.
  • Plaid is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process.

Skills

  • Comfortable working across Security, Legal, Procurement, and GTM as the third-party risk point of contact.
  • clear findings, clean tracking, and defensible risk decisions others can follow.
  • Communication and cross-functional effectiveness:
  • AI fluency and tooling:
  • Nice-to-have
  • Plaid is proud to be an equal opportunity employer and values diversity at our company.

Compensation

  • Additional compensation in the form(s) of equity and/or commission are dependent on the position offered.

Benefits

  • Report on Ecosystem Risk: Track assessment cycle times, backlog, open exceptions, and reassessment coverage, and report program health to stakeholders.

Company info

  • Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam.
  • Team: The Security Governance, Risk, and Compliance (GRC) team is part of Plaid's security organization, focused on enabling the business by proactively managing information security risks and maintaining effective controls.
  • Our mission at Plaid is to unlock financial freedom for everyone.
  • Vet Customer and Partner Security Posture: Review the security practices of customers and partners onboarding to the platform, applying the same standards you use for vendors.
  • Review the security practices of customers and partners onboarding to the platform, applying the same standards you use for vendors.

This listing is sourced directly from Plaid's careers page and normalized into a canonical job model.