SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Plaid is seeking a Security Analyst to lead third-party ecosystem risk management within its Security Governance, Risk, and Compliance (GRC) team. The role focuses on vetting the security posture of vendors, customers, and partners who connect to Plaid's financial platform, which powers connections for millions of users across 12,000 financial institutions in the US, Canada, UK, and Europe.
You will own the end-to-end third-party risk assessment lifecycle: intake and triage of vendor security requests, conducting rigorous security reviews scaled to risk tier, assigning defensible risk ratings, and documenting findings and exceptions. You'll assess both vendors Plaid relies on and customers/partners onboarding to the platform using consistent standards, ensuring trust flows in both directions. Your work protects Plaid from inheriting vendor security gaps and ensures platform users and data remain protected.
Beyond individual assessments, you will drive program maturation—improving questionnaires, tiering criteria, intake workflows, and runbooks to scale reviews faster and more consistently as volume grows. You'll maintain the third-party risk lifecycle by managing risk tiering, driving reassessments on schedule, tracking remediation to closure, and keeping the risk register current and trustworthy. You'll report on ecosystem risk metrics (cycle times, backlog, open exceptions, reassessment coverage) to Security and cross-functional stakeholders including Procurement, Legal, and GTM teams.
A key differentiator is your ability to leverage AI and tooling to increase throughput—building AI-assisted workflows for assessment review, questionnaire analysis, and reporting, then sharing best practices with the team. You'll operate as an AI power user to materially scale the program without adding headcount.
Required: 4+ years in vendor risk management with hands-on experience running security risk assessments, reviewing questionnaires and SOC 2/ISO reports, and translating findings into defensible risk ratings. You must understand the third-party risk lifecycle (intake, tiering, exceptions, remediation, reassessment) and have working knowledge of SOC 2, ISO 27001, NIST CSF, and control domains (access control, encryption, incident response, BC/DR). You need a track record maturing third-party risk programs—improving processes and automation, not just executing existing ones—while maintaining rigor at volume. Strong analytical and documentation skills are essential; you'll communicate security risks clearly to non-security stakeholders without overstating or hand-waving. You must be comfortable as the third-party risk point of contact across Security, Legal, Procurement, and GTM. Finally, you should demonstrate fluency with AI tooling applied to assessment workflows and the ability to share what works with the team.
Nice-to-have: third-party risk or audit credentials (CTPRP, CISA, CISSP) or hands-on experience with TPRM platforms (OneTrust, ProcessUnity, Whistic, Securi).