Security Analyst, Third-Party Ecosystem Risk Management
$118.68k - $175.8kPlaid
We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam.
Team:
The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security organization, focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission is to reduce the likelihood and impact of security risks while operating a robust assurance program that builds trust with our customers, consumers, and data partners.We partner closely across the company to ensure Plaid’s platform remains secure, resilient, and aligned with industry and regulatory expectations.
Third-party ecosystem risk is a core part of how we keep Plaid safe—we vet the security of both the vendors we rely on and the customers and partners who connect to our platform, so trust runs in both directions.
Role:
You will run security risk assessments for Plaid’s third parties end-to-end—from intake and questionnaire through risk rating, findings, and tracked exceptions.
You will assess the security posture of customers and partners onboarding to the platform with the same rigor we apply to vendors.
You will keep the third-party risk lifecycle moving—risk tiering, reassessment cadence, remediation follow-through, and a clean, current risk register.
You will help mature the program—questionnaires, tiering criteria, intake, and runbooks—so reviews get faster and more consistent as volume grows, drawing on how you’ve improved third-party risk programs before.
You will report on ecosystem risk to Security and cross-functional stakeholders, and operate as an AI power user to raise your own throughput.
Responsibilities:
Run Vendor Security Risk Assessments : Triage inbound vendor requests, run security reviews scaled to risk tier, rate the risk, and document findings and exceptions. Your assessments keep Plaid from inheriting a vendor’s security gaps and give Procurement, Privacy, and Legal a clear risk signal before contracts are signed.
Vet Customer and Partner Security Posture : Review the security practices of customers and partners onboarding to the platform, applying the same standards you use for vendors. Your reviews make sure who connects to Plaid meets the bar before they touch data—protecting consumers and the ecosystem.
Keep the Third-Party Risk Lifecycle Current : Maintain risk tiering, drive reassessments on cadence, chase remediation to closure, and keep the risk register accurate. Your follow-through keeps third-party risk a live, trustworthy picture rather than a point-in-time checkbox.
Mature the Program : Improve questionnaires, tiering criteria, intake, runbooks, and tooling as review volume grows—bringing patterns from third-party risk programs you’ve matured before. Your work moves the function from ad hoc toward fast, consistent, and scalable.
Report on Ecosystem Risk : Track assessment cycle times, backlog, open exceptions, and reassessment coverage, and report program health to stakeholders. Your reporting gives leadership real visibility into where third-party risk concentrates.
Scale Through AI and Tooling : Build and scale AI-assisted workflows for assessment review, questionnaire analysis, and reporting—and share what works. Your approach sets how the team uses AI to handle more reviews without adding headcount.
Qualifications:
Must-haves
4+ years of experience in vendor risk management
Third-party and vendor security risk assessment:
Experience running security risk assessments of third parties—reviewing questionnaires, SOC 2 and ISO reports, and security documentation, and translating them into a defensible risk rating.
Familiarity with the third-party risk lifecycle: intake, tiering, exceptions and risk acceptance, remediation tracking, and periodic reassessment.
Security and compliance knowledge:
Working knowledge of SOC 2, ISO 27001, NIST CSF, and common control domains (access control, encryption, incident response, BC/DR).
Ability to read a control environment and tell a real gap from an acceptable compensating control.
Program maturation and operational execution:
Experience maturing a third-party or vendor risk program—improving how it works (tiering criteria, questionnaires, workflow, automation), not just executing an existing one.
Track record running assessments at volume without dropping rigor.
Strong analytical and documentation skills: clear findings, clean tracking, and defensible risk decisions others can follow.
Communication and cross-functional effectiveness:
Clear written and verbal communication—able to explain a security risk to Procurement, Legal, or a customer without overstating or hand-waving.
Comfortable working across Security, Legal, Procurement, and GTM as the third-party risk point of contact.
AI fluency and tooling:
Demonstrated ability to apply AI tooling to assessment review, questionnaire analysis, and reporting to materially increase throughput—and to share what works with the team.
Nice-to-have
A third-party-risk or audit credential (CTPRP, CISA, or CISSP), or hands-on ownership of a TPRM platform (e.g. OneTrust, ProcessUnity, Whistic, SecurityScorecard) beyond using it as an end user.
Our mission at Plaid is to unlock financial freedom for everyone. To support that mission, we seek to build a diverse team of driven individuals who care deeply about making the financial ecosystem more equitable. We recognize that strong qualifications can come from both prior work experiences and lived experiences. We encourage you to apply to a role even if your experience doesn't fully match the job description. We are always looking for team members that will bring something unique to Plaid!
Plaid is proud to be an equal opportunity employer and values diversity at our company. We do not discriminate based on race, color, national origin, ethnicity, religion or religious belief, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, military or veteran status, disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state, and local laws. Plaid is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance with your application or interviews due to a disability, please let us know at View email address on aiapply.co.
Please review our Candidate Privacy Notice here .
Additional compensation in the form(s) of equity and/or commission are dependent on the position offered. Plaid provides a comprehensive benefit plan, including medical, dental, vision, and 401(k). Pay is based on factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience and skillset, and location. Pay and benefits are subject to change at any time, consistent with the terms of any applicable compensation or benefit plans.
- Job Description The Security Risk & Compliance Analyst supports the organization’s global information security... ...identification, assessment, and management of information security risks and... ...stakeholders, external auditors, and third‑party vendors to support a culture of...SuggestedWork at office
$190.9k - $254.6k
Procurement Senior Manager - Third Party Risk Strategy Job ID: 110961 Atlanta Connecticut - Darien Denver London Miramar... ...framework that supports a diverse and global third-party ecosystem. You will own the design and evolution of the firm's third...SuggestedHourly payApprenticeshipWork at office$72k - $90k
...Center, a collaborative ecosystem of the world's most... ...by our world-class management consulting, delivery... ...Position Overview: The Security Analyst supports customer... ...project plans, milestones, risk registers, and status... ...Manage vendor and third-party relationships related...SuggestedFull timeRemote workShift work$110k - $230k
...Senior ActuaryA-CAP is a leading provider of capital and third-party asset management solutions. Through our synergistic platform of insurance carriers... ...commitment is demonstrated through the industry-leading risk-adjusted returns we achieve, and the innovative capital...SuggestedFull timeTemporary workImmediate startWork visaMonday to Friday$160k - $228.5k
...week Corporate Vice President, Head of Third Party Risk ManagementRole Overview:New York Life... ...to serve as Head of Third-Party Risk Management (TPRM). Sitting in the Second Line of... ...closely with Procurement, Information Security, Legal, Compliance, Business Continuity...SuggestedLocal area3 days per week$176.6k - $294.3k
...Our Global Governance, Risk, and Compliance (GRC)... ...embedding governance, risk management, and compliance into... ...is used and that security, privacy, and regulatory... ...experienced Director, Third Party Risk Management (TPRM)... ...risk across a complex ecosystem of vendors, partners,...Permanent employmentFull timeContract workH1bWork at officeLocal areaVisa sponsorshipWork visaRelocation package2 days per week3 days per week$42k - $150k
...Overview The incumbent is responsible for all aspects of and will provide oversight, guidance and challenge to the Bank’s Third Party Risk Management (TPRM). S/he will establish and enhance the Third Party Risk Framework, draft and maintain TPRM policies and standards,...Work experience placement$142.5k
...Director, Application Security Engineering to strengthen... ...prevent and remediate risk, and communicate... ...modeling, vulnerability management, automation, security... ...pipelines, containers, APIs, third‑party components, and... ...of the global sports ecosystem. For more information,...Hourly payTemporary workWork at officeLocal areaWorldwideShift work3 days per week- ...on the appointment of an IT Security Analyst to help identify, remediate, and reduce security risk across networks, endpoints, servers... ...role covers vulnerability management, patching, security... ...policy enforcement Work with third party vendors to meet security and...Relocation
- ## Security AnalystApplyremote type: Hybridlocations:... ...as our newest Security Analyst.**SUMMARY**We are... ...our clients' technology ecosystems, fostering continuous... ...Detective, Compliance Manager GRC, VulScan.* Strong... ...Compliance Portals.* Risk Assessment.* Policy and...Work at officeLocal areaFlexible hours
- ...Security Analyst The Security Analyst is responsible for managing third-party vulnerability data, executing scans using Sompo’s proprietary tools, and partnering with IT... ...processes to maintain a complete and accurate risk picture. Evaluate existing vulnerabilities...
$89.25k - $150.25k
...AuditSchedule: Full timeCareer Area: Operational Risk Management and Control ManagementCompany:... ...Audit Group’s assurance coverage for Third-Party Risk Management. The colleague will... ...including operational resilience, information security, technology, data management,...Ongoing contractWorldwide- Consolidated Edison Company of New York is seeking a Sr. Risk Manager for Third Party Risk Management (TPRM) to support program design, development, execution, and enhancements across the TPRM lifecycle, including planning, due diligence, contracts, monitoring, and off...
- ...We are looking for an IT Security Analyst to help protect enterprise systems... ...role focuses on identifying risk, detecting abnormal behavior... ...and patching. Tune, manage, and audit security tools such... ...Support regulatory, audit, and third-party risk assessment activities....
$86.46k - $126k
Join to apply for the Senior Security Analyst role at Jack Henry Join to apply for the Senior... ...opportunity to use your project management and business analysis skills to help... ...effectiveness of data security, data awareness, third party risk, and incident response. * May perform...Full timeLocal areaRemote work- ...emergency medical and security solutions for corporations... ...culture. We have managed crises in the worst environments... ...Center (GSOC) Analyst will be responsible... ...hotel locations, high-risk destinations, and transportation... ...relationships with third-party security providers,...WorldwideShift work
- Responsibilities Security Planning Develop a security plan for the... ...systems and networks to assess risks and determine how policies... ...fixing any flaws in IT systems Manage the negative effects of an... ...attacks Verify the security of third-party vendors and collaborate to...
$148k - $185k
...team ensures that appropriate security controls and data protections... .... We conduct security risk assessments, consult with organizational... ...Security program, facilitate third-party security audits, work with... ...global markets. You'll manage relationships with external auditors...Hourly payWork at officeLocal areaFlexible hours3 days per week$102.6k - $179.25k
About the Role:As a Senior IT Security Analyst, you will engage in advanced... ...and recovery efforts.• Manage access controls and monitor... ...technologies.• Conduct security risk assessments and mitigation planning... ...AI-generated responses or third-party support during interviews...Full timeWork at office$145k - $160k
...Times Company is looking for a Senior Manager, Travel and Event Security to lead the strategic development... ...requires a proactive leader who can manage risk in a fast-paced, mission-driven... ...train, and support high-performing third-party security vendors, ensuring defined service...Local areaWorldwideFlexible hours$118.3k - $207.4k
Third‑Party IT Risk Manager is responsible for leading and modernizing Wolters Kluwer’s global third‑party cyber risk management capability across... ...engagements align with the organization’s risk appetite, security standards, and regulatory expectations and lead the...Full timeContract workWork at officeShift work$59.8k - $114.5k
...insights, and client outcomes. In management at Crowe, you play a pivotal role in leading... ...challenges with confidence. The Third Party Risk Manager position will be primarily... ...leading the assessment of the information security posture of key clients' third parties...Local areaRemote workWorldwide$352k
...leader to support our Enterprise Security team as we continue to... ...oversees the broad regional risk posture, influences global standards... ....Job Responsibilities:Lead, manage, and develop a high impact... ...enforcement, federal agencies, third party vendors and community...Hourly payFull timeLocal areaImmediate startWorldwideFlexible hours$120k - $150k
...New York, the Information Security Threat Analyst is responsible for detecting... ...technologies, end users, and Managed Security Service Providers... ...the relationship with the third-party providers who deliver these... ...the firm’s procurement and risk functions. Qualifications:...Work at officeFlexible hours$45k - $100k
...the Role We are seeking an AI Security Analyst responsible for securing... ...and can translate AI‑related risks into practical, enforceable... ...enterprise systems (APIs, plugins, third‑party apps) Monitor AI usage and... ...securing SaaS platforms and managing identity/access risks (SSO,...Full timeWork at officeWeekend work- ...Academy is growing rapidly and security is at the forefront of... ...are seeking a Senior Security Analyst to join our Information Security... ...department. The Technology team manages a modern technology... ...CrowdStrike, proactively identifying risks, leading investigations, driving...Work at officeImmediate startVisa sponsorship3 days per week
- ...025706Reference26-01357Senior Security AnalystJob Number: 26-01357Want... ...looking for a Senior Security Analyst for our client in New York, NY... ...teams to identify security risks, improve cloud security controls... ...multiple cloud providers.Help manage and operate Cloud Security Posture...Work experience placement
$97.59k - $142.99k
...opportunity to join our team as a Sr. II Security Analyst - Vulnerabilities. In this role, the... ...Penetration Testing and Vulnerabilities Management team. The group is an agile team that effectively... ...threat intelligence reports, write risk analysis report for zero-day critical...Full time$104.5k - $213.8k
...Description The position will be primarily responsible for managing and leading Third Party Risk Management (TPRM) engagements, including oversight of... ...third-party risk across areas such as information security, compliance, operational risk, privacy, and broader TPRM...Local areaRemote work- Crowe Advisory LLC is seeking a Senior Third Party Risk Manager to lead assessments of information security posture for key clients’ third parties. You will oversee teams, drive remediation strategies, and collaborate with client leadership across industries including...Remote job
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Analyst, Third-Party Ecosystem Risk Management. Be the first to apply!
- application security analyst New York, NY
- entry level information security analyst New York, NY
- entry level security analyst New York, NY
- information security analyst New York, NY
- senior security analyst New York, NY
- rate analyst New York, NY
- IT security analyst New York, NY
- national security analyst New York, NY
- work from home security analyst New York, NY
- physical security analyst New York, NY



