Plaid
Security Engineer, GRC
San Francisco HQ
Sponsorship not specified$53k-$800kDetected 6 days ago
PythonGitSQLAWSTerraformCI/CDData EngineeringCybersecurityDetection EngineeringIncident ResponseComplianceLeadership
About the role
- Today most of our compliance work is manual and point-in-time; you will turn it into an engineered system that is continuous, data-driven, and scalable, and set the technical direction for the field.
- Define the discipline and the architecture - how GRC Engineering works at Plaid, not just execute within it.
- Be the engineering backbone for Security Assurance & Trust Enablement, Third-Party Ecosystem Risk, and Risk Management
Responsibilities
- Architect GRC's Engineering Foundation: Build the pipelines and codified source of truth the function runs on - controls, policies, and framework mappings captured as structured, version-controlled data and fed by live control and system state - so one control maps evidence across SOC 2, ISO, NIST, and beyond instead of being re-collected for every audit.
- Build Continuous Controls Monitoring: Automate evidence collection, control testing, and monitoring across cloud and internal systems, and write and tune the detection that flags drift and misconfiguration against baseline - so audit readiness is continuous and gaps surface the moment they appear, not at audit time.
- Turn Data into Risk Signal: Build dashboards and SQL-driven reporting that turn raw control and risk data into KPIs, giving the team and leadership real-time visibility into risk posture.
- Drive Data-Informed Risk Assessments: Conduct security and technology risk assessments and recommend mitigations using data - keeping the risk management program running while cutting its manual overhead.
- Future-proof for Continuous Compliance: Build toward machine-readable, continuously validated evidence (FedRAMP 20x-style Key Security Indicators), positioning Plaid to meet continuous-compliance expectations as we enter new markets and pursue new authorizations.
- Build the foundation the function runs on - a codified source of truth for controls, policies, and evidence, fed by live pipelines and continuous controls monitoring.
- Build dashboards and SQL-driven reporting that turn raw control and risk data into KPIs, giving the team and leadership real-time visibility into risk posture.
Requirements
- Hands-on experience with AWS and cloud-native security controls, including the ability to query cloud, GitHub, and SaaS logs.
- Proficiency with dashboarding / data-visualization tools (e.g., Mode) to turn control and risk data into KPIs and signal.
- Demonstrated ability to model controls, policies, and framework mappings as structured, version-controlled data rather than docs and spreadsheets.
- Hands-on experience with IaC (Terraform) and policy-as-code (OPA/Rego, Sentinel), including embedding compliance checks into CI/CD.
- Proven ability to eliminate recurring operational toil - evidence pulls, access and vendor reviews, questionnaires, risk-register upkeep, status reports - with durable automation rather than one-off scripts.
- Working knowledge of SOC 2, ISO 27001/27701, and NIST CSF/800-53, with the ability to map controls to evidence and crosswalk a single control across frameworks.
- Experience conducting security or technology risk assessments and translating findings into data-driven mitigation.
- Ability to work independently and cross-functionally across security, infrastructure, and engineering, with strong prioritization and the ability to influence without authority.
- Software & Data Engineering Foundations:
- Strong Python and SQL, with a proven track record of building API/webhook integrations that connect disparate systems.
- Experience owning an internal tool or service end to end - design, build, operate, and maintain - with real users depending on it.
- Applied GRC Engineering:
- Experience building and operating continuous controls monitoring end to end - collecting signal from live systems, writing and tuning the detection logic that compares state to a baseline, alerting, and driving remediation.
- Compliance & risk knowledge:
- Familiarity with the shift to continuous compliance (FedRAMP 20x, machine-readable Key Security Indicators) and how it changes evidence and control design.
Nice to have
- Direct experience with FedRAMP or FedRAMP 20x, or other public-sector / continuous-compliance authorizations.
- Experience with audit ›/ compliance automation platforms (Anecdotes, Drata, Vanta, Paramify, or similar).
- Exposure to security incident response and triage.
- Experience in a high-growth fintech or financial-services environment.
- Degree in Computer Science, Cybersecurity, or a related field.
- We recognize that strong qualifications can come from both prior work experiences and lived experiences.
- We encourage you to apply to a role even if your experience doesn't fully match the job description.
- Plaid is proud to be an equal opportunity employer and values diversity at our company.
Skills
- Plaid powers the tools millions of people rely on to live a healthier financial life.
- Plaid's network covers 12,000 financial institutions across the US, Canada, UK and Europe.
Compensation
- Additional compensation in the form(s) of equity and/or commission are dependent on the position offered.
This listing is sourced directly from Plaid's careers page and normalized into a canonical job model.