The board
JobStartup
Finance
Security Analyst, Third-Party Ecosystem Risk Management
Plaid · All Departments
- Pay
- $118,680–$175,800
- Where
- New York City Office
- Posted
- Aug 12
We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe.
What you'd do
- Run Vendor Security Risk Assessments: Triage inbound vendor requests, run security reviews scaled to risk tier, rate the risk, and document findings and exceptions.
- Your assessments keep Plaid from inheriting a vendor’s security gaps and give Procurement, Privacy, and Legal a clear risk signal before contracts are signed.
- Vet Customer and Partner Security Posture: Review the security practices of customers and partners onboarding to the platform, applying the same standards you use for vendors.
- Your reviews make sure who connects to Plaid meets the bar before they touch data—protecting consumers and the ecosystem.
- Keep the Third-Party Risk Lifecycle Current: Maintain risk tiering, drive reassessments on cadence, chase remediation to closure, and keep the risk register accurate.
- Your follow-through keeps third-party risk a live, trustworthy picture rather than a point-in-time checkbox.
- Mature the Program: Improve questionnaires, tiering criteria, intake, runbooks, and tooling as review volume grows—bringing patterns from third-party risk programs you’ve matured before.
- Your work moves the function from ad hoc toward fast, consistent, and scalable.
- Report on Ecosystem Risk: Track assessment cycle times, backlog, open exceptions, and reassessment coverage, and report program health to stakeholders.
- Your reporting gives leadership real visibility into where third-party risk concentrates.
- Scale Through AI and Tooling: Build and scale AI-assisted workflows for assessment review, questionnaire analysis, and reporting—and share what works. Your approach sets how the team uses AI to handle more reviews without adding headcount.
- 4+ years of experience in vendor risk management
- Experience running security risk assessments of third parties—reviewing questionnaires, SOC 2 and ISO reports, and security documentation, and translating them into a defensible risk rating.
- Familiarity with the third-party risk lifecycle: intake, tiering, exceptions and risk acceptance, remediation tracking, and periodic reassessment.