安全分析师,第三方生态系统风险管理
Security Analyst, Third-Party Ecosystem Risk Management
我们相信,人们与财务的互动方式将在未来几年发生巨大变化。我们致力于通过构建数千名开发者用来创建自己产品的工具和体验,推动这一变革。Plaid 为数以百万计的人们依赖的工具提供支持,帮助他们过上更健康的财务生活。我们与 Venmo、SoFi、多家财富 500 强公司以及许多大型银行合作,让人们能够轻松地将他们的财务账户连接到他们想要使用的应用和服务。Plaid 的网络覆盖美国、加拿大、英国和欧洲的 12,000 家金融机构。公司成立于 2013 年,总部位于旧金山,并在纽约、西雅图、华盛顿特区、罗利、伦敦和阿姆斯特丹设有办事处。
团队:
安全治理、风险与合规(GRC)团队是 Plaid 安全组织的一部分,专注于通过主动管理信息安全风险并保持有效的控制措施来赋能业务。我们的使命是在降低安全风险的可能性和影响的同时,运营一个强大的保证计划,以建立客户、消费者和数据合作伙伴的信任。我们与公司内部紧密合作,确保 Plaid 平台保持安全、稳健,并符合行业和监管要求。
第三方生态系统风险是我们保障 Plaid 安全的核心部分——我们对依赖的供应商以及连接到我们平台的客户和合作伙伴进行安全评估,以确保信任双向流动。
职位:
- 你将对 Plaid 的第三方进行端到端的安全风险评估——从需求收集和问卷调查到风险评级、发现的问题和跟踪的例外情况。
- 你将用与我们评估供应商相同的严谨性,评估客户和合作伙伴接入平台时的安全态势。
- 你将推动第三方风险生命周期——风险分级、重新评估频率、整改跟进以及一份清晰、最新的风险登记表。
- 你将帮助完善该计划——问卷、分级标准、需求收集和操作手册,使随着规模增长,审查速度更快、更一致,借鉴你之前改进第三方风险计划的经验。
- 你将向安全团队和跨职能利益相关者报告生态系统风险,并作为 AI 高级用户提高自己的处理效率。
职责:
- 运行供应商安全风险评估:处理供应商的请求,执行安全风险评估
查看英文原文
We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Seattle, Washington D.C., Raleigh, London, and Amsterdam.
Team:
The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security organization, focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission is to reduce the likelihood and impact of security risks while operating a robust assurance program that builds trust with our customers, consumers, and data partners.We partner closely across the company to ensure Plaid’s platform remains secure, resilient, and aligned with industry and regulatory expectations.
Third-party ecosystem risk is a core part of how we keep Plaid safe—we vet the security of both the vendors we rely on and the customers and partners who connect to our platform, so trust runs in both directions.
Role:
- You will run security risk assessments for Plaid’s third parties end-to-end—from intake and questionnaire through risk rating, findings, and tracked exceptions.
- You will assess the security posture of customers and partners onboarding to the platform with the same rigor we apply to vendors.
- You will keep the third-party risk lifecycle moving—risk tiering, reassessment cadence, remediation follow-through, and a clean, current risk register.
- You will help mature the program—questionnaires, tiering criteria, intake, and runbooks—so reviews get faster and more consistent as volume grows, drawing on how you’ve improved third-party risk programs before.
- You will report on ecosystem risk to Security and cross-functional stakeholders, and operate as an AI power user to raise your own throughput.
Responsibilities:
- Run Vendor Security Risk Assessments: Triage inbound vendor requests, run security reviews scaled to risk tier, rate the risk, and document findings and exceptions. Your assessments keep Plaid from inheriting a vendor’s security gaps and give Procurement, Privacy, and Legal a clear risk signal before contracts are signed.
- Vet Customer and Partner Security Posture: Review the security practices of customers and partners onboarding to the platform, applying the same standards you use for vendors. Your reviews make sure who connects to Plaid meets the bar before they touch data—protecting consumers and the ecosystem.
- Keep the Third-Party Risk Lifecycle Current: Maintain risk tiering, drive reassessments on cadence, chase remediation to closure, and keep the risk register accurate. Your follow-through keeps third-party risk a live, trustworthy picture rather than a point-in-time checkbox.
- Mature the Program: Improve questionnaires, tiering criteria, intake, runbooks, and tooling as review volume grows—bringing patterns from third-party risk programs you’ve matured before. Your work moves the function from ad hoc toward fast, consistent, and scalable.
- Report on Ecosystem Risk: Track assessment cycle times, backlog, open exceptions, and reassessment coverage, and report program health to stakeholders. Your reporting gives leadership real visibility into where third-party risk concentrates.
- Scale Through AI and Tooling: Build and scale AI-assisted workflows for assessment review, questionnaire analysis, and reporting—and share what works. Your approach sets how the team uses AI to handle more reviews without adding headcount.
Qualifications:
Must-haves
- 4+ years of experience in vendor risk management
- Third-party and vendor security risk assessment:
- Experience running security risk assessments of third parties—reviewing questionnaires, SOC 2 and ISO reports, and security documentation, and translating them into a defensible risk rating.
- Familiarity with the third-party risk lifecycle: intake, tiering, exceptions and risk acceptance, remediation tracking, and periodic reassessment.
- Security and compliance knowledge:
- Working knowledge of SOC 2, ISO 27001, NIST CSF, and common control domains (access control, encryption, incident response, BC/DR).
- Ability to read a control environment and tell a real gap from an acceptable compensating control.
- Program maturation and operational execution:
- Experience maturing a third-party or vendor risk program—improving how it works (tiering criteria, questionnaires, workflow, automation), not just executing an existing one.
- Track record running assessments at volume without dropping rigor.
- Strong analytical and documentation skills: clear findings, clean tracking, and defensible risk decisions others can follow.
- Communication and cross-functional effectiveness:
- Clear written and verbal communication—able to explain a security risk to Procurement, Legal, or a customer without overstating or hand-waving.
- Comfortable working across Security, Legal, Procurement, and GTM as the third-party risk point of contact.
- AI fluency and tooling:
- Demonstrated ability to apply AI tooling to assessment review, questionnaire analysis, and reporting to materially increase throughput—and to share what works with the team.
Nice-to-have
- A third-party-risk or audit credential (CTPRP, CISA, or CISSP), or hands-on ownership of a TPRM platform (e.g. OneTrust, ProcessUnity, Whistic, SecurityScorecard) beyond using it as an end user.
Our mission at Plaid is to unlock financial freedom for everyone. To support that mission, we seek to build a diverse team of driven individuals who care deeply about making the financial ecosystem more equitable. We recognize that strong qualifications can come from both prior work experiences and lived experiences. We encourage you to apply to a role even if your experience doesn't fully match the job description. We are always looking for team members that will bring something unique to Plaid!
Plaid is proud to be an equal opportunity employer and values diversity at our company. We do not discriminate based on race, color, national origin, ethnicity, religion or religious belief, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, military or veteran status, disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state, and local laws. Plaid is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance with your application or interviews due to a disability, please let us know at accommodations@plaid.com.
Please review our Candidate Privacy Notice here https://plaid.com/legal/#candidate-privacy-notice.
Additional compensation in the form(s) of equity and/or commission are dependent on the position offered. Plaid provides a comprehensive benefit plan, including medical, dental, vision, and 401(k). Pay is based on factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience and skillset, and location. Pay and benefits are subject to change at any time, consistent with the terms of any applicable compensation or benefit plans.