Plaid

Plaid

Security Engineer, GRC

San Francisco HQ

Sponsorship not specified$53k-$800kDetected 6 days ago
PythonGitSQLAWSTerraformCI/CDData EngineeringCybersecurityDetection EngineeringIncident ResponseComplianceLeadership

About the role

  • Today most of our compliance work is manual and point-in-time; you will turn it into an engineered system that is continuous, data-driven, and scalable, and set the technical direction for the field.
  • Define the discipline and the architecture - how GRC Engineering works at Plaid, not just execute within it.
  • Be the engineering backbone for Security Assurance & Trust Enablement, Third-Party Ecosystem Risk, and Risk Management

Responsibilities

  • Architect GRC's Engineering Foundation: Build the pipelines and codified source of truth the function runs on - controls, policies, and framework mappings captured as structured, version-controlled data and fed by live control and system state - so one control maps evidence across SOC 2, ISO, NIST, and beyond instead of being re-collected for every audit.
  • Build Continuous Controls Monitoring: Automate evidence collection, control testing, and monitoring across cloud and internal systems, and write and tune the detection that flags drift and misconfiguration against baseline - so audit readiness is continuous and gaps surface the moment they appear, not at audit time.
  • Turn Data into Risk Signal: Build dashboards and SQL-driven reporting that turn raw control and risk data into KPIs, giving the team and leadership real-time visibility into risk posture.
  • Drive Data-Informed Risk Assessments: Conduct security and technology risk assessments and recommend mitigations using data - keeping the risk management program running while cutting its manual overhead.
  • Future-proof for Continuous Compliance: Build toward machine-readable, continuously validated evidence (FedRAMP 20x-style Key Security Indicators), positioning Plaid to meet continuous-compliance expectations as we enter new markets and pursue new authorizations.
  • Build the foundation the function runs on - a codified source of truth for controls, policies, and evidence, fed by live pipelines and continuous controls monitoring.
  • Build dashboards and SQL-driven reporting that turn raw control and risk data into KPIs, giving the team and leadership real-time visibility into risk posture.

Requirements

  • Hands-on experience with AWS and cloud-native security controls, including the ability to query cloud, GitHub, and SaaS logs.
  • Proficiency with dashboarding / data-visualization tools (e.g., Mode) to turn control and risk data into KPIs and signal.
  • Demonstrated ability to model controls, policies, and framework mappings as structured, version-controlled data rather than docs and spreadsheets.
  • Hands-on experience with IaC (Terraform) and policy-as-code (OPA/Rego, Sentinel), including embedding compliance checks into CI/CD.
  • Proven ability to eliminate recurring operational toil - evidence pulls, access and vendor reviews, questionnaires, risk-register upkeep, status reports - with durable automation rather than one-off scripts.
  • Working knowledge of SOC 2, ISO 27001/27701, and NIST CSF/800-53, with the ability to map controls to evidence and crosswalk a single control across frameworks.
  • Experience conducting security or technology risk assessments and translating findings into data-driven mitigation.
  • Ability to work independently and cross-functionally across security, infrastructure, and engineering, with strong prioritization and the ability to influence without authority.
  • Software & Data Engineering Foundations:
  • Strong Python and SQL, with a proven track record of building API/webhook integrations that connect disparate systems.
  • Experience owning an internal tool or service end to end - design, build, operate, and maintain - with real users depending on it.
  • Applied GRC Engineering:
  • Experience building and operating continuous controls monitoring end to end - collecting signal from live systems, writing and tuning the detection logic that compares state to a baseline, alerting, and driving remediation.
  • Compliance & risk knowledge:
  • Familiarity with the shift to continuous compliance (FedRAMP 20x, machine-readable Key Security Indicators) and how it changes evidence and control design.

Nice to have

  • Direct experience with FedRAMP or FedRAMP 20x, or other public-sector / continuous-compliance authorizations.
  • Experience with audit ›/ compliance automation platforms (Anecdotes, Drata, Vanta, Paramify, or similar).
  • Exposure to security incident response and triage.
  • Experience in a high-growth fintech or financial-services environment.
  • Degree in Computer Science, Cybersecurity, or a related field.
  • We recognize that strong qualifications can come from both prior work experiences and lived experiences.
  • We encourage you to apply to a role even if your experience doesn't fully match the job description.
  • Plaid is proud to be an equal opportunity employer and values diversity at our company.

Skills

  • Plaid powers the tools millions of people rely on to live a healthier financial life.
  • Plaid's network covers 12,000 financial institutions across the US, Canada, UK and Europe.

Compensation

  • Additional compensation in the form(s) of equity and/or commission are dependent on the position offered.

This listing is sourced directly from Plaid's careers page and normalized into a canonical job model.