Security Engineer, GRC
Plaid Financial
We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam.The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security organization, focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission is to reduce the likelihood and impact of security risks while operating a robust assurance program that builds trust with our customers, consumers, and data partners. We own Plaid’s security compliance frameworks, run our audits and risk programs, and partner across the company to keep Plaid’s platform secure, resilient, and aligned with industry and regulatory expectations. GRC Engineering is how we make all of that scale — turning compliance into code, evidence into telemetry, and audits into a continuous, automated capability.The Role:You will own GRC Engineering at Plaid — a foundational, high-ownership role defining an emerging discipline from the ground up. Today most of our compliance work is manual and point-in-time; you will turn it into an engineered system that is continuous, data-driven, and scalable, and set the technical direction for the field.You will:Define the discipline and the architecture — how GRC Engineering works at Plaid, not just execute within it.Build the foundation the function runs on — a codified source of truth for controls, policies, and evidence, fed by live pipelines and continuous controls monitoring.Be the engineering backbone for Security Assurance & Trust Enablement, Third-Party Ecosystem Risk, and Risk ManagementMake risk visible and data-driven — turning control and risk data into real-time signals for the team and leadership.Pioneer where compliance is heading — compliance-agents-as-code in the SDLC, AI- and agent-driven workflows, and machine-readable continuous compliance (FedRAMP 20x).This role is perfect for you if:You think in systems: you'd rather design the thing that eliminates a whole class of manual work than automate one task at a time.You love building and shipping internal tools and solutions that people actually use.You're relentlessly curious — you poke, you investigate, and you dig into how controls can silently fail, drift, or get bypassed so you can catch it automatically.You treat every roadblock as just an obstacle to route around — you don't back down, because there's always a path.You like range — juggling several problems across security, risk, compliance, and engineering beats grinding on a single one.You're energized by turning compliance from a documentation exercise into demonstrable, continuous, machine-readable evidence.Responsibilities:Architect GRC's Engineering Foundation: Build the pipelines and codified source of truth the function runs on — controls, policies, and framework mappings captured as structured, version-controlled data and fed by live control and system state — so one control maps evidence across SOC 2, ISO, NIST, and beyond instead of being re-collected for every audit.Build Continuous Controls Monitoring: Automate evidence collection, control testing, and monitoring across cloud and internal systems, and write and tune the detection that flags drift and misconfiguration against baseline — so audit readiness is continuous and gaps surface the moment they appear, not at audit time.Turn Data into Risk Signal: Build dashboards and SQL-driven reporting that turn raw control and risk data into KPIs, giving the team and leadership real-time visibility into risk posture.Drive Data-Informed Risk Assessments: Conduct security and technology risk assessments and recommend mitigations using data — keeping the risk management program running while cutting its manual overhead.Automate Operational Toil: Eliminate the recurring manual work the team carries — evidence pulls, access and vendor reviews, questionnaires, risk-register upkeep, status reporting — with durable automation that gives time back across every workstream.Shift Compliance Left with Code and AI: Embed compliance checks into the CI/CD flow as policy-as-code so controls are validated as code ships, prototype self-healing policies reconciled against live infrastructure, and scale agentic / AI-assisted workflows across the function.Future-proof for Continuous Compliance: Build toward machine-readable, continuously validated evidence (FedRAMP 20x-style Key Security Indicators), positioning Plaid to meet continuous-compliance expectations as we enter new markets and pursue new authorizations.Qualifications:Software & Data Engineering Foundations:Strong Python and SQL, with a proven track record of building API/webhook integrations that connect disparate systems.Experience owning an internal tool or service end to end — design, build, operate, and maintain — with real users depending on it.Hands-on experience with AWS and cloud-native security controls, including the ability to query cloud, GitHub, and SaaS logs.Proficiency with dashboarding / data-visualization tools (e.g., Mode) to turn control and risk data into KPIs and signal.Applied GRC Engineering:Experience building and operating continuous controls monitoring end to end — collecting signal from live systems, writing and tuning the detection logic that compares state to a baseline, alerting, and driving remediation.Demonstrated ability to model controls, policies, and framework mappings as structured, version-controlled data rather than docs and spreadsheets.Hands-on experience with IaC (Terraform) and policy-as-code (OPA/Rego, Sentinel), including embedding compliance checks into CI/CD.Proven ability to eliminate recurring operational toil — evidence pulls, access and vendor reviews, questionnaires, risk-register upkeep, status reports — with durable automation rather than one-off scripts.Compliance & risk knowledge:Working knowledge of SOC 2, ISO 27001/27701, and NIST CSF/800-53, with the ability to map controls to evidence and crosswalk a single control across frameworks.Experience conducting security or technology risk assessments and translating findings into data-driven mitigation.Familiarity with the shift to continuous compliance (FedRAMP 20x, machine-readable Key Security Indicators) and how it changes evidence and control design.AI fluency & tooling:Demonstrated ability to build and scale agentic / AI-assisted workflows (Claude, OpenAI) as leverage for the whole team.Cross-functional effectiveness:Ability to work independently and cross-functionally across security, infrastructure, and engineering, with strong prioritization and the ability to influence without authority.Nice to have:Direct experience with FedRAMP or FedRAMP 20x, or other public-sector / continuous-compliance authorizations.Experience with audit ›/ compliance automation platforms (Anecdotes, Drata, Vanta, Paramify, or similar).Exposure to security incident response and triage.Experience in a high-growth fintech or financial-services environment.Degree in Computer Science, Cybersecurity, or a related field.Our mission at Plaid is to unlock financial freedom for everyone. To support that mission, we seek to build a diverse team of driven individuals who care deeply about making the financial ecosystem more equitable. We recognize that strong qualifications can come from both prior work experiences and lived experiences. We encourage you to apply to a role even if your experience doesn't fully match the job description. We are always looking for team members that will bring something unique to Plaid!Plaid is proud to be an equal opportunity employer and values diversity at our company. We do not discriminate based on race, color, national origin, ethnicity, religion or religious belief, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, military or veteran status, disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state, and local laws. Plaid is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance with your application or interviews due to a disability, please let us know at View email address on click.appcast.io review our Candidate Privacy Notice here.Additional compensation in the form(s) of equity and/or commission are dependent on the position offered. Plaid provides a comprehensive benefit plan, including medical, dental, vision, and 401(k). Pay is based on factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience and skillset, and location. Pay and benefits are subject to change at any time, consistent with the terms of any applicable compensation or benefit plans.Compensation Range: $156K - $213.6KLocationSan Francisco HQ; New York City Office; Seattle OfficeAddress1098 Harrison Street, San Francisco, California, 94103Employment TypeFull timeLocation TypeHybridDepartmentAll DepartmentsSecurityCompensation$156K – $213.6KAdditional compensation in the form(s) of equity and/or commission are dependent on the position offered. Plaid provides a comprehensive benefit plan, including medical, dental, vision, and 401(k). Pay is based on factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience and skillset, and location. Pay and benefits are subject to change at any time, consistent with the terms of any applicable compensation or benefit plans.
$200k - $220k
...they rely on every day.We are looking for a hands-on Corporate Security Engineer to own and improve the technical controls that keep our... ...easier to use. You'll partner closely with IT, Infrastructure, GRC, and Detection & Response to improve the security foundations...SuggestedWork at officeLocal area$189k - $303k
...efficient and accessible for all. We’re searching for a Staff Security Engineer, Enterprise Security Architecture.This position is open to the... ...technical architecture and implementation guidance.Partner with GRC to operationalize security policies, standards, and control...SuggestedWork at officeLocal area3 days per week$208k - $312k
...move from idea to production with speed, security, and exceptional developer experience.Now... ...About the Role:We are looking for a Security Engineer to join our Detection Response team. In... ...and collaborating with Engineering, GRC and the broader Security Division.Proactively...SuggestedWork at officeRemote workWork from homeWorldwideMonday to FridayFlexible hoursShift work$200k - $330k
...and design teams for Google Workspace. What you'll doLead Security for Our Platform. Take charge of application, cloud,... ...Collaborate with Cross-Functional Teams. Partner closely with engineering, product, and GRC to embed security throughout the software development...SuggestedFull timeFlexible hours- ...Corporate Security Engineer Millions of people rely on Notion to do their most important work. Protecting that trust starts with protecting... ...easier to use. You'll partner closely with IT, Infrastructure, GRC, and Detection & Response to improve the security foundations...SuggestedLocal area
- ...Mission and Culture doc here. Position Summary As a Security Engineer at HeyGen, you will own the security posture of one of the... ...rollouts are designed and deployed with strong security controls. GRC & Compliance: Oversee our SOC 2 compliance operations (...
- ...currently Tuesday. About the Role Lambda Security protects some of the world's most... ...artificial intelligence. As a Security Engineer at Lambda, you'll touch many areas across... .../tooling, vulnerability management, GRC operations, etc.). Experience driving...Work at officeLocal areaWork from homeFlexible hoursShift work
$130k
About the roleWe are looking for a versatile Security Software Engineer to join our team and operate across product security, application security... ...)Pen testing or bug bounty experienceFamiliarity with GRC tools and frameworks#LI-Hybrid #LI-JL1A little about usAt Chime...Full timeWork at officeLocal areaRemote work$192k - $240k
...and support you need to grow your career.Engineering at BrexEngineering at Brex is about... ...intention. Our teams span Software, Data, Security, and IT, and operate with high autonomy... ...Application Security, Corporate Engineering, GRC and IT and to improve security...Work at officeRemote workWork from home$300k - $405k
...Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build... .... In this role, you will have the opportunity to shape our security capabilities from the ground up alongside our world-class research...Full timeWork at officeVisa sponsorshipFlexible hours$232k - $290k
...join us, and build real world value.THE WORK:As a Senior Staff Security Engineer, you will be one of Ripple's most senior technical security... ...infrastructure standards as Treasury integrates.Partner with GRC to ensure Treasury meets its compliance obligations across SOC...Full timeWork at officeLocal area$134k - $184.8k
Secure Every Identity, from AI to HumanIdentity is the key to unlocking the potential of AI... ...and Intelligence (TDI) organization is the engine that powers Okta's global workforce,... ...the organization.Partner with Security and GRC to communicate our risk posture and remediation...Local areaWorldwideFlexible hoursShift work$275k - $300k
...at Postman.About the TeamThe Information Security organization at Postman operates across three... ...pillars: Governance Risk & Compliance (GRC), Product Security, and Security... ...looking for a Principal Offensive Security Engineer who is as much a strategist as they are a...Work at officeFlexible hours3 days per week$237.6k - $297k
We are seeking a highly technical Security Engineer to join our Product Security team. This role is integral to ensuring the security and integrity of our products and services. You will conduct in-depth code reviews, implement security best practices, and influence the...Full time$234.4k - $385k
...artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are... ...engaging a robust security culture. About the RoleAs a Security Engineer, Application Security you will be responsible for identifying and...Work at officeRemote workRelocation packageFlexible hours$146.3k - $257.7k
...scalers to join us on our journey to create a better future of work with AI. About the roleThis is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, you'll be building the security foundations that protect the AI systems...Full timeWork at officeLocal area$130k
...Security Software Engineer We are looking for a versatile Security Software Engineer to join our team and operate across product security, application... ...Pen testing or bug bounty experience Familiarity with GRC tools and frameworks A Little About Us At Chime, we...Full timeWork at officeLocal areaRemote work$180k - $200k
...bigger picture and our vision at Postman.The Opportunity The Security GRC team is responsible for the overall security posture of Postman... ...initiatives to further the growth of Postman.We seek a Senior GRC Engineer who combines deep GRC expertise with strong engineering skills...Work at officeFlexible hours3 days per week$230k - $385k
...that artificial general intelligence benefits all of humanity.The Security team protects OpenAI’s technology, people, and products. We are... ...security culture.About the RoleOpenAI is seeking a Security Engineer to join our Infrastructure Security (InfraSec) team. InfraSec protects...Work at officeLocal areaFlexible hours- Factory is seeking a talented Security Engineer to join our team. In this role, you will play a critical role in developing and maintaining the security foundation of our platform. You will conduct in-depth code reviews, implement security best practices, and influence...Work at office
$165k - $200k
...single API, Merge Agent Handler, which empowers AI agents with secure access to thousands of third-party tools, and Merge Gateway,... ...product development, unblock sales, reduce customer churn, and save engineering resources—allowing them to focus on their core product.Merge...Full timeWork at officeHome office$237.6k - $297k
We are seeking a Senior Security Engineer with a specialty in Detection and Incident Response to join our Security Engineering team. This role sits at the intersection of security operations and software engineering — you won't just investigate incidents, you'll build the...Full time$180k - $258k
...today!Curious to learn more about our story? Check out this blog post written by our founders. The RoleWe're looking for a Senior Security Engineer who is ready to elevate the safety and security of our systems and networks. You will serve as our guardian, ensuring our...Flexible hours$146.3k - $257.7k
...scalers to join us on our journey to create a better future of work with AI. About the roleJoin WRITER's security team as a staff detection and response engineer and help protect the AI infrastructure that's transforming how the world works. You'll build sophisticated...Full timeWork at officeLocal area$122.5k - $165k
...everyone is a stakeholder.What you’ll be responsible for:The Circle Security Team works to protect Circle; our customers, clients, and... ...:2+ years of experience in detection, response, or security engineering.Experience working security incidents, especially those involving...Work experience placementFlexible hoursShift workNight shift$153k - $376k
...together in real time from anywhere in the world. If you're excited to shape the future of design and collaboration, join us!As a Security Engineer you will identify and drive impactful projects to improve the security of Figma’s product, platform, and IT systems. We are...Minimum wageFull timeLocal areaRemote workFlexible hours- ...Modernisation, and Industry-Specific Software Solutions, DXC modernises, secures, and operates some of the world’s most complex technology... ...and New Zealand market, we are enhancing the Security Engineering Team who work within the Secured Infrastructure capacity to deliver...Full timeLocal area
- ...Persona builds identity verification infrastructure where security isn't a layer we add later, it's core to everything we ship. When... ...generalist security team. You'll work alongside experienced security engineers to defend Persona's people, devices, and systems against...Full timeFor contractorsInternshipWork at officeWork from homeRelocation packageMonday to FridayFlexible hours
$148.5k - $260.1k
...! Agentforce is the future of AI, and you are the future of Salesforce.The ExperienceSalesforce Enterprise Security is hiring a Senior and Lead Security Engineer for our Secure AI team to help assess and maintain the security of using AI tooling securely.In this role,...Full time$189k - $303k
...get crucial goods where they need to go, and make mobility more efficient and accessible for all.We're searching for a Staff Security Engineer to join our Enterprise Security Engineering team, reporting to the Technical Lead Manager of Security Engineering.This position...Work at officeLocal area3 days per weekEarly shift
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Engineer, GRC. Be the first to apply!
- staff security engineer San Francisco, CA
- network security engineer San Francisco, CA
- product security engineer San Francisco, CA
- senior application security engineer San Francisco, CA
- sr security engineer San Francisco, CA
- security infrastructure engineer San Francisco, CA
- entry level security engineer San Francisco, CA
- senior security operations engineer San Francisco, CA
- dlp security engineer San Francisco, CA
- cloud security engineer San Francisco, CA

