Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Analyst, Third-Party Ecosystem Risk Management [Remote]

$118.68k - $175.8k
Full-time

Plaid

New York, NY
  • Remote job

We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam. Team:

The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security organization, focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission is to reduce the likelihood and impact of security risks while operating a robust assurance program that builds trust with our customers, consumers, and data partners.We partner closely across the company to ensure Plaid’s platform remains secure, resilient, and aligned with industry and regulatory expectations.

Third-party ecosystem risk is a core part of how we keep Plaid safe—we vet the security of both the vendors we rely on and the customers and partners who connect to our platform, so trust runs in both directions.

Role:
  • You will run security risk assessments for Plaid’s third parties end-to-end—from intake and questionnaire through risk rating, findings, and tracked exceptions.
  • You will assess the security posture of customers and partners onboarding to the platform with the same rigor we apply to vendors.
  • You will keep the third-party risk lifecycle moving—risk tiering, reassessment cadence, remediation follow-through, and a clean, current risk register.
  • You will help mature the program—questionnaires, tiering criteria, intake, and runbooks—so reviews get faster and more consistent as volume grows, drawing on how you’ve improved third-party risk programs before.
  • You will report on ecosystem risk to Security and cross-functional stakeholders, and operate as an AI power user to raise your own throughput.
Responsibilities:
  • Run Vendor Security Risk Assessments : Triage inbound vendor requests, run security reviews scaled to risk tier, rate the risk, and document findings and exceptions. Your assessments keep Plaid from inheriting a vendor’s security gaps and give Procurement, Privacy, and Legal a clear risk signal before contracts are signed.
  • Vet Customer and Partner Security Posture : Review the security practices of customers and partners onboarding to the platform, applying the same standards you use for vendors. Your reviews make sure who connects to Plaid meets the bar before they touch data—protecting consumers and the ecosystem.
  • Keep the Third-Party Risk Lifecycle Current : Maintain risk tiering, drive reassessments on cadence, chase remediation to closure, and keep the risk register accurate. Your follow-through keeps third-party risk a live, trustworthy picture rather than a point-in-time checkbox.
  • Mature the Program : Improve questionnaires, tiering criteria, intake, runbooks, and tooling as review volume grows—bringing patterns from third-party risk programs you’ve matured before. Your work moves the function from ad hoc toward fast, consistent, and scalable.
  • Report on Ecosystem Risk : Track assessment cycle times, backlog, open exceptions, and reassessment coverage, and report program health to stakeholders. Your reporting gives leadership real visibility into where third-party risk concentrates.
  • Scale Through AI and Tooling : Build and scale AI-assisted workflows for assessment review, questionnaire analysis, and reporting—and share what works. Your approach sets how the team uses AI to handle more reviews without adding headcount.
Qualifications: Must-haves
  • 4+ years of experience in vendor risk management
  • Third-party and vendor security risk assessment:
  • Experience running security risk assessments of third parties—reviewing questionnaires, SOC 2 and ISO reports, and security documentation, and translating them into a defensible risk rating.
  • Familiarity with the third-party risk lifecycle: intake, tiering, exceptions and risk acceptance, remediation tracking, and periodic reassessment.
  • Security and compliance knowledge:
  • Working knowledge of SOC 2, ISO 27001, NIST CSF, and common control domains (access control, encryption, incident response, BC/DR).
  • Ability to read a control environment and tell a real gap from an acceptable compensating control.
  • Program maturation and operational execution:
  • Experience maturing a third-party or vendor risk program—improving how it works (tiering criteria, questionnaires, workflow, automation), not just executing an existing one.
  • Track record running assessments at volume without dropping rigor.
  • Strong analytical and documentation skills: clear findings, clean tracking, and defensible risk decisions others can follow.
  • Communication and cross-functional effectiveness:
  • Clear written and verbal communication—able to explain a security risk to Procurement, Legal, or a customer without overstating or hand-waving.
  • Comfortable working across Security, Legal, Procurement, and GTM as the third-party risk point of contact.
  • AI fluency and tooling:
  • Demonstrated ability to apply AI tooling to assessment review, questionnaire analysis, and reporting to materially increase throughput—and to share what works with the team.
Nice-to-have
  • A third-party-risk or audit credential (CTPRP, CISA, or CISSP), or hands-on ownership of a TPRM platform (e.g. OneTrust, ProcessUnity, Whistic, SecurityScorecard) beyond using it as an end user.

Our mission at Plaid is to unlock financial freedom for everyone. To support that mission, we seek to build a diverse team of driven individuals who care deeply about making the financial ecosystem more equitable. We recognize that strong qualifications can come from both prior work experiences and lived experiences. We encourage you to apply to a role even if your experience doesn't fully match the job description. We are always looking for team members that will bring something unique to Plaid!

Plaid is proud to be an equal opportunity employer and values diversity at our company. We do not discriminate based on race, color, national origin, ethnicity, religion or religious belief, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, military or veteran status, disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state, and local laws. Plaid is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance with your application or interviews due to a disability, please let us know at View email address on decentrajobs.com.

Please review our Candidate Privacy Notice [here](

Additional compensation in the form(s) of equity and/or commission are dependent on the position offered. Plaid provides a comprehensive benefit plan, including medical, dental, vision, and 401(k). Pay is based on factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience and skillset, and location. Pay and benefits are subject to change at any time, consistent with the terms of any applicable compensation or benefit plans.

Vacancy posted a month ago
Similar jobs that could be interesting for youBased on the Security Analyst, Third-Party Ecosystem Risk Management [Remote] in New York, NY vacancy
  •  ...one of the largest asset managers in Asia and number one among...  ...functions. Information Risk Governance (“IRG”)...  ...to information and cyber security risk by maintaining and improving...  ...Your Role Overview: The Third Party Information Security Analyst supports the Bank’s Third... 
    Suggested
    Work at office
    Work from home
    Flexible hours
    2 days per week

    SUMITOMO MITSUI TRUST BANK, LIMITED

    New York, NY
    20 days ago
  • $90k - $105k

     ...including financial advisers, employers, third-party administrators, financial...  ...meticulous and detail-oriented Information Security compliance analyst to be responsible for monitoring...  ...What Will You Be Doing? Manage cybersecurity risk processes, including risk... 
    Suggested
    Full time
    Contract work
    For subcontractor
    Work at office
    Local area

    Vestwell

    New York, NY
    8 days ago
  •  ..., well-governed decisions about third-party risk across a large, complex vendor ecosystem. You’ll turn technical assessment...  .... You will translate vendor security evidence into clear risk narratives...  ...material risks (identity and access management, encryption/key management,... 
    Suggested

    JP Morgan Chase

    New York, NY
    1 day ago
  • $190.9k - $254.6k

    Procurement Senior Manager - Third Party Risk Strategy Job ID: 110961 Atlanta Connecticut - Darien Denver London Miramar...  ...framework that supports a diverse and global third-party ecosystem. You will own the design and evolution of the firm's third... 
    Suggested
    Hourly pay
    Apprenticeship
    Work at office

    McKinsey & Company

    New York, NY
    17 hours ago
  • $96.6k - $185k

     ...and others. If you're as passionate about your future as we are, join our team.KPMG is currently seeking a Manager, Third Party Risk to join our Enterprise Security Services organization.Responsibilities:Apply a thorough knowledge of Third-Party and Supplier Risk to... 
    Suggested
    H1b
    Local area

    KPMG

    New York, NY
    15 hours ago
  • $160k - $228.5k

     ...week Corporate Vice President, Head of Third Party Risk ManagementRole Overview:New York Life...  ...to serve as Head of Third-Party Risk Management (TPRM). Sitting in the Second Line of...  ...closely with Procurement, Information Security, Legal, Compliance, Business Continuity... 
    Local area
    3 days per week

    New York Life Insurance Company

    New York, NY
    1 day ago
  • $191k - $305k

     ...seeking a Senior Lead Information Security Analyst in Cybersecurity to join the...  ...identity and access management services, support user transitions...  ...based on business impact, risk, and user experience.Provide...  ...and Hiring Requirements:a. Third-Party recordings are prohibited... 
    Full time
    Work experience placement
    Relocation package

    Wells Fargo

    New York, NY
    15 hours ago
  • $157k - $210k

     ...CoreWeave is responsible for executing and delivering security, trust, and assurance across our products,...  ...team is building leading Governance, Risk and Compliance (GRC) programs, including third party risk management (TPRM).As a TPRM Technical Program Manager, you... 
    Permanent employment
    Full time
    Contract work
    Temporary work
    Casual work
    Work at office
    Flexible hours

    CoreWeave

    New York, NY
    17 hours ago
  • $105.35k - $117.05k

    Third Party Vendor Risk Management Specialist - Remote Requisition Number R7986 Third Party Vendor Risk Management Specialist - Remote (Open) Location...  ...in Third Party Risk Management or information security is required. Self-directed, able to work independently,... 
    Remote job
    Contract work
    Work from home
    Flexible hours

    CSAA

    New York, NY
    5 days ago
  • $148k - $185k

     ...team ensures that appropriate security controls and data protections...  .... We conduct security risk assessments, consult with organizational...  ...Security program, facilitate third-party security audits, work with...  ...global markets. You\'ll manage relationships with external auditors... 
    Hourly pay
    Work at office
    Local area
    Flexible hours
    3 days per week

    Socotra, Inc.

    New York, NY
    1 day ago
  • $102.6k - $179.25k

    About the Role:As a Senior IT Security Analyst, you will engage in advanced...  ...and recovery efforts.• Manage access controls and monitor...  ...technologies.• Conduct security risk assessments and mitigation planning...  ...AI-generated responses or third-party support during interviews... 
    Full time
    Work at office

    Wolters Kluwer

    New York, NY
    17 hours ago
  • $75k - $110k

     ...About the Role The Application Security Analyst helps embed security into...  ...This role focuses on reducing risk through automation,...  ...security controls, vulnerability management, and modern DevSecOps methodologies...  ..., deployment patterns, third-party components, and cloud configurations... 
    Local area
    Immediate start
    Remote work
    Flexible hours

    Sound Physicians

    New York, NY
    2 days ago
  • $75k - $95k

     ...are seeking an Application Security Analyst to build security into how we...  ...secure code, fix pipelines, manage security tools and requests...  ...(DevSecOps) Assess security risks in AI/ML-enabled applications...  ...Secure AI APIs, plugins, and third-party integrations Tune security... 
    Work at office
    Remote work
    Flexible hours

    FSAStore.com

    New York, NY
    2 days ago
  • We are looking for an IT Security Analyst to help protect enterprise systems...  ...role focuses on identifying risk, detecting abnormal behavior...  ...and patching. Tune, manage, and audit security tools such...  ...Support regulatory, audit, and third-party risk assessment activities.... 

    The Phoenix Group

    New York, NY
    3 days ago
  •  ...Technology Controls / Information Security policies, programs, and tools...  ...and guidance on assessing risks, identifying gaps, and...  ...emerging threats, cybercriminal ecosystems, ransomware, initial access brokers...  ...risk-reducing behaviors, and manage priorities to meet production... 
    Work at office

    Jobtailor

    New York, NY
    1 day ago
  • $118.3k - $207.4k

    Third‑Party IT Risk Manager is responsible for leading and modernizing Wolters Kluwer’s global third‑party cyber risk management capability across...  ...engagements align with the organization’s risk appetite, security standards, and regulatory expectations and lead the... 
    Full time
    Contract work
    Work at office
    Shift work

    Wolters Kluwer

    New York, NY
    2 days ago
  • $90k - $110k

     ...26 at 4:00 AM Job Title: Security & Compliance Analyst Location: Home Office Compensation...  ..., conducts assessments, manages evidence collection, and...  ..., Operations, and third-party business partners to maintain...  ...the company’s Governance, Risk, and Compliance (GRC)... 
    Home office

    OTG

    New York, NY
    2 days ago
  • $97.59k - $142.99k

     ...opportunity to join our team as a Sr. II Security Analyst - Vulnerabilities. In this role, the...  ...Penetration Testing and Vulnerabilities Management team. The group is an agile team that effectively...  ...threat intelligence reports, write risk analysis report for zero-day critical... 
    Full time

    NYU Langone Medical Center

    New York, NY
    17 hours ago
  •  ...Academy is growing rapidly and security is at the forefront of...  ...are seeking a Senior Security Analyst to join our Information Security...  ...department. The Technology team manages a modern technology...  ...CrowdStrike, proactively identifying risks, leading investigations, driving... 
    Work at office
    Immediate start
    Visa sponsorship
    3 days per week

    Success Academy Charter Schools

    New York, NY
    3 days ago
  • $123k - $215.25k

     ...provides independent, risk-based assurance, advice...  ...company's Payments ecosystem. This role will lead and...  ...evaluating governance, risk management, and control...  ...technologies. Evaluate third-party relationships including...  ...brand promise of trust, security, and service.As part of... 

    American Express

    New York, NY
    4 days ago
  • $135.7k - $170.2k

     ...seasoned Senior Finance Systems Analyst to lead the strategic evolution...  ...for our CPG Supply Chain, Spend Management (Ramp), and Production Accounting ecosystems, ensuring our high-growth...  ...implementations, system migrations, or third-party integrations (WMS, EDI, etc.),... 
    Relocation package
    Flexible hours

    MrBeast

    New York, NY
    1 day ago
  • $117.2k - $176.7k

     ...are the future of Salesforce.The ExperienceEnterprise Security is looking for a Senior Analyst to support our Business Information Security Officers (...  ...to keep those engagements running smoothly — tracking risks and commitments, coordinating deliverables, and preparing... 
    Full time

    Salesforce

    New York, NY
    1 day ago
  • $135k - $140k

     ...uniquely Richemont Americas. Senior Security Operation Center (SOC) Analyst - L2Cyber | New York,...  ...teams, including IT, security risk, forensics, and legal, to ensure...  ..., and recommendations to management, stakeholders, and relevant parties.Participate and provide value... 
    Permanent employment
    Full time
    Local area
    Flexible hours

    Richemont

    New York, NY
    17 hours ago
  •  ...-ID31409788Reference25-31660Title : SOC Analyst Location : New York City, Boston MA, Atlanta...  ...first line of defense for information security operationsmonitoring, investigating, and...  ...of threat detection, vulnerability management, identity/access management, and endpoint... 
    Shift work

    Axelon

    New York, NY
    17 hours ago
  • $145k - $170k

    CLEAR is building THE secure identity company of the future. Our mission is to make experiences...  ...is seeking a Senior Security Operations Analyst III to join our SOC team to help...  ...threats, identify root causes, communicate risk, and drive timely remediation and improvements... 
    Casual work
    Work at office
    Flexible hours

    Secure Identity

    New York, NY
    17 hours ago
  • $100k - $235k

     ...Advisor (RIA) Custody Product, Managed Accounts Platform (including...  ...of the wealth management ecosystem, this senior leader will have...  ...high-value relationships with third-party SMA managers, Turnkey Asset Management...  ...process improvements.Risk, Compliance, & Governance: Partner... 
    Full time
    Temporary work
    Part time

    Goldman Sachs

    New York, NY
    1 day ago
  • $100k - $120k

    Our client is a leading manager of alternative investment solutions...  ...seek a Valuation/Portfolio Analyst to join their Manhattan, NY office...  ...including both internal and third-party valuationsProduce performance...  ...transactions, to determine security valuationsEvaluate the... 
    Work at office
    Remote work

    Abacus Group

    New York, NY
    17 hours ago
  • The Stellar Development Foundation is seeking a Director, Ecosystem & Product Security to lead security strategy across the Stellar ecosystem. This...  ...like wallets and custodians to mitigate real-world risks. The ideal candidate will have over 10 years in security,... 
    Flexible hours

    Stellar Development Foundation

    New York, NY
    5 days ago
  • $166.9k - $278.1k

     ...,900 - $278,100Job Function: Risk ConsultingEmployer: EY Global...  ...platforms, Microservices, Cloud, API Management, and open-source technologies...  ...Change Management), Third-party Risk Management (TPRM), Business...  ...network and diverse ecosystem partners, EY teams can provide... 
    Immediate start

    EY (Ernst & Young)

    New York, NY
    15 hours ago
  • $150k - $175k

     ...Investments is a leading global asset manager with over 65 years of experience helping...  ...you.Role SummaryThe Asset-Backed Securities Trader/Analyst is responsible for identifying and sourcing...  ...to generate trade ideas, manage risk, and drive performance.This role reports... 
    Full time
    Work at office
    Local area

    American Century Investments

    New York, NY
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Analyst, Third-Party Ecosystem Risk Management [Remote]. Be the first to apply!