Plaid

Plaid

Senior Security Analyst, Customer Assurance

New York City Office · Senior

Sponsorship not specified$53k-$800kDetected 22 days ago
CybersecurityPenetration TestingComplianceNegotiationAuditingContract ManagementLeadershipCommunicationInternal Audit

About the role

  • You will review security provisions in customer MSAs, DPAs, and security addenda, identify unacceptable clauses, and provide Legal and GTM with the actionable security feedback they need to move deals forward.
  • The Security Governance, Risk, and Compliance (GRC) team is part of Plaid's security organization, focused on enabling the business by proactively managing information security risks and maintaining effective controls.

Responsibilities

  • Lead Security Contract Reviews: Review security provisions in customer MSAs, DPAs, security addenda, and security exhibits - identifying unacceptable clauses, forming a clear security position, and providing Legal with actionable feedback they can take directly into negotiations.
  • Shape the Security Contract Review Strategy: Design and own the end-to-end program infrastructure - intake process, tiered SLAs, security positions runbooks, and handoff protocols with Legal and GTM.
  • Drive Strategic Intelligence: Track security contract asks across deals, identify recurring patterns, and determine whether they reflect a gap in Plaid's program or a non-standard customer request.
  • Accelerate Deals: Join customer and data partner calls as Plaid's security subject matter expert - comfortable navigating the formality and pace of traditional financial institutions, building trust through patience and clear, collaborative communication.
  • Scale Through AI and Tooling: Build and scale AI-assisted workflows for security assurance, pattern analysis, and reporting - and share what works across the team.
  • Design and own the end-to-end program infrastructure - intake process, tiered SLAs, security positions runbooks, and handoff protocols with Legal and GTM.

Requirements

  • Experience reviewing security provisions in MSAs, DPAs, and security addenda - and translating that expertise into clear positions Legal can take directly into negotiations.
  • Ability to translate a company's security posture and risk appetite into clear, defensible contract positions and hold those positions through multiple negotiation cycles.
  • Working knowledge of SOC 2, ISO 27001, NIST CSF, PCI DSS, GLBA, GDPR/CCPA, NIST 800-53, etc.
  • Strong analytical skills: ability to identify patterns across a high volume of security contract asks, track pushback rates and cycle counts, and translate findings into process improvements.
  • Security contract review and negotiation:
  • Deep familiarity with common security clause types: e.g. incident notification windows, audit rights, encryption requirements, subprocessor obligations, data retention, and penetration testing provisions.
  • Experience representing a company's security program directly to customers and financial institution partners on calls - fielding questions about security controls, compliance posture, and contractual obligations.
  • Security Compliance and regulatory knowledge:
  • Deep understanding of what "standard" security contract language looks like in fintech and banking agreements
  • Prior experience in fintech, payments, or financial services - you understand the security expectations of data partners and regulated entities, and know how to navigate those relationships with the patience and credibility they require.
  • Program design and operational maturity:
  • Experience building security trust enablement programs - designing intake processes, tiered SLAs, escalation paths, and runbooks, not just executing within existing ones.
  • Experience with metrics ownership: defining KPIs, building tracking infrastructure, and reporting on program health to cross-functional stakeholders.

Nice to have

  • Experience redlining security contract language directly, beyond providing advisory feedback.
  • We recognize that strong qualifications can come from both prior work experiences and lived experiences.
  • We encourage you to apply to a role even if your experience doesn't fully match the job description.
  • Plaid is proud to be an equal opportunity employer and values diversity at our company.
  • We also consider qualified applicants with criminal histories, consistent with applicable federal, state, and local laws.
  • Plaid is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process.

Skills

  • Communication and cross-functional effectiveness:
  • Experience working directly with Legal and GTM teams as a security subject matter expert.
  • AI fluency and tooling:
  • Plaid powers the tools millions of people rely on to live a healthier financial life.
  • Plaid's network covers 12,000 financial institutions across the US, Canada, UK and Europe.

Compensation

  • Additional compensation in the form(s) of equity and/or commission are dependent on the position offered.

Benefits

  • Define the KPIs, build the dashboards, and deliver regular reporting on program health to Security and GTM leadership.
  • defining KPIs, building tracking infrastructure, and reporting on program health to cross-functional stakeholders.

Company info

  • Our mission is to reduce the likelihood and impact of security risks while operating a robust assurance program that builds trust with our customers, consumers, and data partners.
  • We partner closely across the company to ensure Plaid's platform remains secure, resilient, and aligned with industry and regulatory expectations.
  • The Security Contracts workstream is a core part of our Security Assurance and Trust Enablement program - ensuring Plaid's contractual security obligations with customers and data partners are defensible, consistent, and never a bottleneck to deal velocity, all while building trust.
  • About the Role
  • You will own Plaid's Security Contracts workstream end-to-end-the DRI for how security contract reviews get done, how fast they move, and how the program improves over time.
  • You will build the playbooks, processes, and program infrastructure that make the Security Contracts workstream scalable - so the team moves faster on every deal that follows.
  • You will use pattern analysis and data to proactively reduce deal friction over time, own program metrics and reporting, and operate as an AI power user to maximize throughput.
  • You will also support broader security trust enablement activities - responding to customer security questionnaires and joining external audit calls with customers and data partners - with the same rigor and responsiveness you bring to the contracts workstream.
  • Lead Security Contract Reviews: Review security provisions in customer MSAs, DPAs, security addenda, and security exhibits - identifying unacceptable clauses, forming a clear security position, and providing Legal with actionable feedback they can take directly into negotiations. Your positions will give Legal and GTM a consistent, defensible security voice at the table and directly reduce deal cycle times.
  • Shape the Security Contract Review Strategy: Design and own the end-to-end program infrastructure - intake process, tiered SLAs, security positions runbooks, and handoff protocols with Legal and GTM. Your work will transform security reviews from an ad-hoc bottleneck into a predictable, scalable function that the business can rely on.
  • Drive Strategic Intelligence: Track security contract asks across deals, identify recurring patterns, and determine whether they reflect a gap in Plaid's program or a non-standard customer request. For identified gaps, assess feasibility and propose recommendations to leadership. For existing capabilities, codify them in the standard security addendum to eliminate future negotiation cycles.
  • Accelerate Deals: Join customer and data partner calls as Plaid's security subject matter expert - comfortable navigating the formality and pace of traditional financial institutions, building trust through patience and clear, collaborative communication. Your involvement will shorten security contract review cycles from weeks to days and directly unblock revenue.

This listing is sourced directly from Plaid's careers page and normalized into a canonical job model.