Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Analyst, Third-Party Ecosystem Risk Management

$118.68k - $175.8k

Plaid Financial

We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam.Team:The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security organization, focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission is to reduce the likelihood and impact of security risks while operating a robust assurance program that builds trust with our customers, consumers, and data partners.We partner closely across the company to ensure Plaid’s platform remains secure, resilient, and aligned with industry and regulatory expectations. Third-party ecosystem risk is a core part of how we keep Plaid safe—we vet the security of both the vendors we rely on and the customers and partners who connect to our platform, so trust runs in both directions.Role:You will run security risk assessments for Plaid’s third parties end-to-end—from intake and questionnaire through risk rating, findings, and tracked exceptions.You will assess the security posture of customers and partners onboarding to the platform with the same rigor we apply to vendors.You will keep the third-party risk lifecycle moving—risk tiering, reassessment cadence, remediation follow-through, and a clean, current risk register.You will help mature the program—questionnaires, tiering criteria, intake, and runbooks—so reviews get faster and more consistent as volume grows, drawing on how you’ve improved third-party risk programs before.You will report on ecosystem risk to Security and cross-functional stakeholders, and operate as an AI power user to raise your own throughput.Responsibilities:Run Vendor Security Risk Assessments: Triage inbound vendor requests, run security reviews scaled to risk tier, rate the risk, and document findings and exceptions. Your assessments keep Plaid from inheriting a vendor’s security gaps and give Procurement, Privacy, and Legal a clear risk signal before contracts are signed.Vet Customer and Partner Security Posture: Review the security practices of customers and partners onboarding to the platform, applying the same standards you use for vendors. Your reviews make sure who connects to Plaid meets the bar before they touch data—protecting consumers and the ecosystem.Keep the Third-Party Risk Lifecycle Current: Maintain risk tiering, drive reassessments on cadence, chase remediation to closure, and keep the risk register accurate. Your follow-through keeps third-party risk a live, trustworthy picture rather than a point-in-time checkbox.Mature the Program: Improve questionnaires, tiering criteria, intake, runbooks, and tooling as review volume grows—bringing patterns from third-party risk programs you’ve matured before. Your work moves the function from ad hoc toward fast, consistent, and scalable.Report on Ecosystem Risk: Track assessment cycle times, backlog, open exceptions, and reassessment coverage, and report program health to stakeholders. Your reporting gives leadership real visibility into where third-party risk concentrates.Scale Through AI and Tooling: Build and scale AI-assisted workflows for assessment review, questionnaire analysis, and reporting—and share what works. Your approach sets how the team uses AI to handle more reviews without adding headcount.Qualifications:Must-haves4+ years of experience in vendor risk managementThird-party and vendor security risk assessment:Experience running security risk assessments of third parties—reviewing questionnaires, SOC 2 and ISO reports, and security documentation, and translating them into a defensible risk rating.Familiarity with the third-party risk lifecycle: intake, tiering, exceptions and risk acceptance, remediation tracking, and periodic reassessment.Security and compliance knowledge:Working knowledge of SOC 2, ISO 27001, NIST CSF, and common control domains (access control, encryption, incident response, BC/DR).Ability to read a control environment and tell a real gap from an acceptable compensating control.Program maturation and operational execution:Experience maturing a third-party or vendor risk program—improving how it works (tiering criteria, questionnaires, workflow, automation), not just executing an existing one.Track record running assessments at volume without dropping rigor.Strong analytical and documentation skills: clear findings, clean tracking, and defensible risk decisions others can follow.Communication and cross-functional effectiveness:Clear written and verbal communication—able to explain a security risk to Procurement, Legal, or a customer without overstating or hand-waving.Comfortable working across Security, Legal, Procurement, and GTM as the third-party risk point of contact.AI fluency and tooling:Demonstrated ability to apply AI tooling to assessment review, questionnaire analysis, and reporting to materially increase throughput—and to share what works with the team.Nice-to-haveA third-party-risk or audit credential (CTPRP, CISA, or CISSP), or hands-on ownership of a TPRM platform (e.g. OneTrust, ProcessUnity, Whistic, SecurityScorecard) beyond using it as an end user.Our mission at Plaid is to unlock financial freedom for everyone. To support that mission, we seek to build a diverse team of driven individuals who care deeply about making the financial ecosystem more equitable. We recognize that strong qualifications can come from both prior work experiences and lived experiences. We encourage you to apply to a role even if your experience doesn't fully match the job description. We are always looking for team members that will bring something unique to Plaid!Plaid is proud to be an equal opportunity employer and values diversity at our company. We do not discriminate based on race, color, national origin, ethnicity, religion or religious belief, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, military or veteran status, disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state, and local laws. Plaid is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance with your application or interviews due to a disability, please let us know at View email address on click.appcast.io review our Candidate Privacy Notice here.Additional compensation in the form(s) of equity and/or commission are dependent on the position offered. Plaid provides a comprehensive benefit plan, including medical, dental, vision, and 401(k). Pay is based on factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience and skillset, and location. Pay and benefits are subject to change at any time, consistent with the terms of any applicable compensation or benefit plans.Compensation Range: $118,680 - $175,800LocationNew York City Office; Raleigh Office; San Francisco HQ; Seattle OfficeAddress85 Spring Street, 10th Floor, New York, New York, 10012Employment TypeFull timeLocation TypeHybridDepartmentAll DepartmentsSecurityCompensationZone 1 - NYC, SF, SeattleBase Salary $138,000 – $175,800 • Offers EquityZone 3 - RaleighBase Salary $118,680 – $151,188 • Offers EquityAdditional compensation in the form(s) of equity and/or commission are dependent on the position offered. Plaid provides a comprehensive benefit plan, including medical, dental, vision, and 401(k). Pay is based on factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience and skillset, and location. Pay and benefits are subject to change at any time, consistent with the terms of any applicable compensation or benefit plans.

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Security Analyst, Third-Party Ecosystem Risk Management in San Francisco, CA vacancy
  • $75k - $100k

    Senior Security Analyst - Heartflow Join to apply for the Senior...  ...advancing the diagnosis and management of coronary artery...  ...data and medical device ecosystem. We are looking for an investigator...  ...security reviews of third‑party vendors to identify risks and ensure they meet... 
    Suggested
    Full time
    Local area
    Worldwide
    Relocation

    (ISC)2 East Bay Chapter

    San Francisco, CA
    2 days ago
  • California Academy of Sciences in San Francisco is seeking a Senior Security Analyst to configure, maintain, and monitor internal security...  ...architecture, and protect departments through proactive risk management. The role requires strong hands-on experience with firewalls... 
    Suggested

    (ISC)2 East Bay Chapter

    San Francisco, CA
    1 day ago
  • DoorDash is seeking a security-focused Third-Party Risk Management (TPRM) Sr. Analyst to mature our program and lead risk assessments across the vendor ecosystem. You will drive continuous security improvements, partner with security engineering, procurement, privacy, and... 
    Suggested

    DoorDash

    San Francisco, CA
    4 days ago
  • $134.16k - $213.6k

     ...London and Amsterdam.About the Team:The Security Governance, Risk, and Compliance (GRC) team is part of...  ...enabling the business by proactively managing information security risks and...  ...care deeply about making the financial ecosystem more equitable. We recognize that strong... 
    Suggested
    Contract work
    Work experience placement
    Work at office
    Local area

    Plaid Financial

    San Francisco, CA
    5 hours ago
  •  ...the first time ever, you can manage and automate every part of the...  ...computer, benefits, and even third-party apps like Slack and Microsoft...  ...the RoleJoin Rippling's Security Assurance team and help demonstrate...  ...support informed third-party risk and onboarding decisions.... 
    Suggested
    Work at office
    3 days per week

    Rippling

    San Francisco, CA
    5 hours ago
  • $121.76k

     ...Information Technology, the Senior Security Analyst is responsible for...  ...engagement to regenerate fragile ecosystems around the world. Learn more...  .... Key Responsibilities Manage, coordinate, and implement the...  ...identify potential security risks and tabletop scenarios.... 
    Full time
    Contract work

    Isc2 Eastbay Chapter

    San Francisco, CA
    3 days ago
  • Requirements 4+ years of experience in risk or compliance roles, preferably third party risk in a regulated environment Proven experience managing distinct projects and programs, with...  ...Understanding of risk areas such as information security, privacy, business continuity, finance... 

    Stripe

    San Francisco, CA
    4 days ago
  • Information Security Operations Analyst (0661U), Berkeley IT - 87198 Departmental Overview The Information Security Office (ISO) coordinates the risk management process for UC Berkeley's information systems and directs campus-wide efforts to adequately secure institutional... 
    Full time
    Work at office

    University of California, Berkeley

    Berkeley, CA
    3 days ago
  • $117.2k - $176.7k

     ...Salesforce.The ExperienceLocation: San Francisco, CAThe Senior Security GRC Analyst role is part of our Assurance team, sitting at the...  ...across frameworks and presenting program status and risk areas to leadership.Manage internal evidence collection by assigning tasks to... 
    Full time
    Work at office

    Salesforce

    San Francisco, CA
    3 days ago
  • $121.76k

    A leading scientific institution in San Francisco is seeking a Senior Security Analyst to manage information security controls, focusing on cybersecurity and operational integration. The ideal candidate will have over 5 years of IT experience with extensive knowledge in... 
    Full time

    Isc2 Eastbay Chapter

    San Francisco, CA
    4 days ago
  • VRC (Valuation Research Corporation) is seeking an analyst for its complex securities valuation practice in San Francisco. You will value derivatives and other illiquid securities for financial reporting, tax, and regulatory needs, using rigorous modeling and client data... 

    VRC (Valuation Research Corporation)

    San Francisco, CA
    5 days ago
  • $91.5k - $120k

    IT Security Analyst (5353C), Information Security Office #87490 At the University of California...  ...Office (ISO) coordinates the risk management process for UC Berkeley's information...  ...Python, Go. Experience with the Elastic ecosystem, particularly Logstash, Kibana, and Elastic... 
    Full time
    H1b
    Work at office
    Immediate start
    Afternoon shift

    University of California

    Berkeley, CA
    5 days ago
  • $75k - $100k

    A leading medical technology firm in San Francisco is seeking a Senior Security Analyst to join their Information Security team. This role will focus on analyzing security events and implementing enhancements to detection capabilities, ensuring the safety of patient data... 

    (ISC)2 East Bay Chapter

    San Francisco, CA
    2 days ago
  • Upwind is a next-generation Cloud Security Platform that leverages...  ...identify and prioritize critical risks, providing precise insights and efficient cloud security management. Unlike traditional tools,...  ...We are looking for a Security Analyst to join our MDR team. In this... 

    Upwind Security, Inc.

    San Francisco, CA
    4 days ago
  • $1,750 - $2,150 per month

     ...experienced cybersecurity professionals — security analysts, penetration testers, incident...  ...cybersecurity at an enterprise organization, managed security service provider (MSSP), consultancy...  ...GCP), or zero‑trust design Governance, risk, and compliance (GRC) — NIST, ISO 27001... 
    Remote job
    Hourly pay

    Obsidian

    San Francisco, CA
    4 days ago
  • $144k - $162k

     ...What you'll be doing Run the customer security questionnaire program end-to-end, from intake...  ..., near-self-service answers. Operate risk and control workflows: triage incoming risks...  ...be available. For this role, the Hiring Manager would like folks to be in the office 2... 
    Full time
    Work at office
    Relocation
    Relocation package
    2 days per week

    VAMP Inc

    San Francisco, CA
    5 days ago
  • $90k - $100k

     ...are looking for:  We’re looking for a Security Analyst to help keep Forage’s security and...  ...Key Responsibilities:  Triage and manage incoming security requests from entire...  ...Please note: We are not engaging with third-party recruiters or agencies for this role. We... 
    Work at office

    Forage

    San Francisco, CA
    more than 2 months ago
  •  ...within the broader Finance Risk Management (FRM) organization and plays...  ...investments, M&A, financial close, third-party dependencies, systems, and...  ...across the finance ecosystem. Together, we help build the...  ...job duties require access to secure and protected information technology... 
    Work at office
    Relocation package

    Neura Market

    San Francisco, CA
    2 days ago
  •  ...Francisco, CA (Hybrid) Archer Faris is pioneering the world’s first 100% multi-agent approach to enterprise security, starting with Third-Party Risk Management, a domain that is mission critical, deeply human, and notoriously broken. Founded by security and AI leaders... 
    Immediate start

    Archer Faris

    San Francisco, CA
    2 days ago
  • Information Security Analyst Location: San Francisco, CA; Los Angeles, CA; Salt Lake City, Utah Duration: 12+ Months, 5 days onsite Must Have: SPL that Splunk uses Actual incident tickets - resolve actual security incident tickets Qualifications: Bachelor's degree... 
    Contract work
    Work at office

    Compunnel Inc.

    San Francisco, CA
    2 days ago
  • Job43 - EITS Security Risk Analyst B (Engagement) Location: 100% Remote Max Submissions: 5 Proposed Start Date: ASAP Proposed End Date:...  ...reporting. Coordinate enterprise-level security and risk management efforts. Act as a subject matter expert (SME) on information... 
    Remote job
    Immediate start
    Flexible hours

    DELTASOFT SOLUTIONS

    San Francisco, CA
    2 days ago
  • $175k - $220k

     ...LinkedIn, Monday.com, Nvidia, and Bridgewater. About the Team The Security team at LangChain treats compliance as a business enabler, not a...  ...confidence in our security posture. Support vendor privacy risk assessments during onboarding and renewals. What you’ll bring... 
    Contract work
    Work at office
    Flexible hours

    LangChain

    San Francisco, CA
    5 days ago
  • $28 - $35 per hour

    2025 Corporate & Investment Risk Management Analyst Program Jobs for Humanity is collaborating with The RRS Group Inc to build an inclusive and just employment ecosystem. We support individuals coming from all walks of life. Company Name: The RRS Group Inc The RRS... 
    Hourly pay
    Full time
    Summer work
    Internship
    Work at office
    Immediate start

    Jobs for Humanity

    San Francisco, CA
    2 days ago
  • $190k - $220k

     ...What You’ll Do:Provide credit risk leadership, policy design,...  ...that requires the ability to manage multiple priorities and meet...  ...responsible for maintaining a secure and productive workspace with...  ...agencies, search firms, or any third parties. Any resume submitted to any... 
    Work at office
    Local area
    Remote work
    Worldwide

    Upgrade

    San Francisco, CA
    2 days ago
  •  ...movement, cards, payables, receivables. Risk is not a side quest. Every dollar we move...  ...decisioning flows, scoring, policy creation, case management and the machinery that decides who gets...  .../referral abuse, friendly fraud, first-party abuse. Instrument the signals, write the... 
    For contractors
    Work at office

    Truss

    San Francisco, CA
    3 days ago
  • Mercury is seeking an Information Security GRC Analyst to mature security, risk, and compliance programs and build guardrails for business continuity and resilience. You will lead risk assessments, partner with cross‑functional teams, and drive audit readiness across SOC... 

    Embedded Shishya

    San Francisco, CA
    1 day ago
  • $130k - $155k

    Cox Worldwide Funds plc is looking for a Trade Operations & Data Analyst to join the Investment Operations department in San Francisco. This role is pivotal for maintaining the integrity of security reference data and overall asset data quality. Successful candidates will... 
    Work at office
    Worldwide

    Cox Worldwide Funds plc

    San Francisco, CA
    2 days ago
  • Discord Inc. is growing its Security GRC function and seeks a Security Analyst to own the day-to-day program, including questionnaires, risk tracking, analyses, tooling, and documentation. You will work with Security, Engineering, IT, and Legal to make compliance friction... 

    Discord

    San Francisco, CA
    4 days ago
  • DELTASOFT SOLUTIONS LLC seeks a remote EITS Security Risk Analyst B to bridge CISO initiatives and IT teams. The role involves developing risk...  ...7 years of IT experience, including 5 in Security Risk Management, and have a strong understanding of EMR systems and GRC tools... 
    Remote job
    Immediate start

    DELTASOFT SOLUTIONS LLC

    San Francisco, CA
    1 day ago
  • $96.3k - $145.2k

     ...Salesforce's core values at the heart of it all. Experience The Security GRC Analyst role is part of our Security and Compliance team, sitting at...  ..., coordinating schedules and minimizing duplication. Manage internal evidence collection by assigning tasks to control owners... 
    Work at office

    salesforce.com, inc.

    San Francisco, CA
    5 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Analyst, Third-Party Ecosystem Risk Management. Be the first to apply!