Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Analyst, Third-Party Ecosystem Risk Management

$118.68k - $175.8k

Plaid Financial

We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Seattle, Washington D.C., Raleigh, London, and Amsterdam.Team:The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security organization, focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission is to reduce the likelihood and impact of security risks while operating a robust assurance program that builds trust with our customers, consumers, and data partners.We partner closely across the company to ensure Plaid’s platform remains secure, resilient, and aligned with industry and regulatory expectations. Third-party ecosystem risk is a core part of how we keep Plaid safe—we vet the security of both the vendors we rely on and the customers and partners who connect to our platform, so trust runs in both directions.Role:You will run security risk assessments for Plaid’s third parties end-to-end—from intake and questionnaire through risk rating, findings, and tracked exceptions.You will assess the security posture of customers and partners onboarding to the platform with the same rigor we apply to vendors.You will keep the third-party risk lifecycle moving—risk tiering, reassessment cadence, remediation follow-through, and a clean, current risk register.You will help mature the program—questionnaires, tiering criteria, intake, and runbooks—so reviews get faster and more consistent as volume grows, drawing on how you’ve improved third-party risk programs before.You will report on ecosystem risk to Security and cross-functional stakeholders, and operate as an AI power user to raise your own throughput.Responsibilities:Run Vendor Security Risk Assessments: Triage inbound vendor requests, run security reviews scaled to risk tier, rate the risk, and document findings and exceptions. Your assessments keep Plaid from inheriting a vendor’s security gaps and give Procurement, Privacy, and Legal a clear risk signal before contracts are signed.Vet Customer and Partner Security Posture: Review the security practices of customers and partners onboarding to the platform, applying the same standards you use for vendors. Your reviews make sure who connects to Plaid meets the bar before they touch data—protecting consumers and the ecosystem.Keep the Third-Party Risk Lifecycle Current: Maintain risk tiering, drive reassessments on cadence, chase remediation to closure, and keep the risk register accurate. Your follow-through keeps third-party risk a live, trustworthy picture rather than a point-in-time checkbox.Mature the Program: Improve questionnaires, tiering criteria, intake, runbooks, and tooling as review volume grows—bringing patterns from third-party risk programs you’ve matured before. Your work moves the function from ad hoc toward fast, consistent, and scalable.Report on Ecosystem Risk: Track assessment cycle times, backlog, open exceptions, and reassessment coverage, and report program health to stakeholders. Your reporting gives leadership real visibility into where third-party risk concentrates.Scale Through AI and Tooling: Build and scale AI-assisted workflows for assessment review, questionnaire analysis, and reporting—and share what works. Your approach sets how the team uses AI to handle more reviews without adding headcount.Qualifications:Must-haves4+ years of experience in vendor risk managementThird-party and vendor security risk assessment:Experience running security risk assessments of third parties—reviewing questionnaires, SOC 2 and ISO reports, and security documentation, and translating them into a defensible risk rating.Familiarity with the third-party risk lifecycle: intake, tiering, exceptions and risk acceptance, remediation tracking, and periodic reassessment.Security and compliance knowledge:Working knowledge of SOC 2, ISO 27001, NIST CSF, and common control domains (access control, encryption, incident response, BC/DR).Ability to read a control environment and tell a real gap from an acceptable compensating control.Program maturation and operational execution:Experience maturing a third-party or vendor risk program—improving how it works (tiering criteria, questionnaires, workflow, automation), not just executing an existing one.Track record running assessments at volume without dropping rigor.Strong analytical and documentation skills: clear findings, clean tracking, and defensible risk decisions others can follow.Communication and cross-functional effectiveness:Clear written and verbal communication—able to explain a security risk to Procurement, Legal, or a customer without overstating or hand-waving.Comfortable working across Security, Legal, Procurement, and GTM as the third-party risk point of contact.AI fluency and tooling:Demonstrated ability to apply AI tooling to assessment review, questionnaire analysis, and reporting to materially increase throughput—and to share what works with the team.Nice-to-haveA third-party-risk or audit credential (CTPRP, CISA, or CISSP), or hands-on ownership of a TPRM platform (e.g. OneTrust, ProcessUnity, Whistic, SecurityScorecard) beyond using it as an end user.Our mission at Plaid is to unlock financial freedom for everyone. To support that mission, we seek to build a diverse team of driven individuals who care deeply about making the financial ecosystem more equitable. We recognize that strong qualifications can come from both prior work experiences and lived experiences. We encourage you to apply to a role even if your experience doesn't fully match the job description. We are always looking for team members that will bring something unique to Plaid!Plaid is proud to be an equal opportunity employer and values diversity at our company. We do not discriminate based on race, color, national origin, ethnicity, religion or religious belief, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, military or veteran status, disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state, and local laws. Plaid is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance with your application or interviews due to a disability, please let us know at View email address on click.appcast.io review our Candidate Privacy Notice here.Additional compensation in the form(s) of equity and/or commission are dependent on the position offered. Plaid provides a comprehensive benefit plan, including medical, dental, vision, and 401(k). Pay is based on factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience and skillset, and location. Pay and benefits are subject to change at any time, consistent with the terms of any applicable compensation or benefit plans.Compensation Range: $118,680 - $175,800LocationNew York City Office; Raleigh Office; San Francisco HQ; Seattle OfficeAddress85 Spring Street, 10th Floor, New York, New York, 10012Employment TypeFull timeLocation TypeHybridDepartmentAll DepartmentsSecurityCompensationZone 1 - NYC, SF, SeattleBase Salary $138,000 – $175,800 • Offers EquityZone 3 - RaleighBase Salary $118,680 – $151,188 • Offers EquityAdditional compensation in the form(s) of equity and/or commission are dependent on the position offered. Plaid provides a comprehensive benefit plan, including medical, dental, vision, and 401(k). Pay is based on factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience and skillset, and location. Pay and benefits are subject to change at any time, consistent with the terms of any applicable compensation or benefit plans.

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Security Analyst, Third-Party Ecosystem Risk Management in San Francisco, CA vacancy
  • $172.5k - $215.63k

     ...class user experience design.As our Lead Security Analyst - GRC, you’ll lead initiatives that...  ...remediation.Coordinate and monitor third-party risk assessments and compliance reviews.Own...  ...security risk registry Audit & Risk Management: Perform audit readiness assessments,... 
    Suggested
    Hourly pay
    Work at office
    Flexible hours
    2 days per week

    Collective Health

    San Francisco, CA
    2 days ago
  •  ...Doist is seeking a Safeguards Enforcement Analyst on the account abuse team to build and execute enforcement workflows that keep our products safe, focusing on detecting and mitigating potential harm. You will drive enforcement areas including access controls and identity... 
    Suggested

    Doist

    San Francisco, CA
    13 hours ago
  • $144k - $162k

     ...Discord's Legal team is growing its Security GRC function, and we're looking for a Security Analyst to help run and scale it. You'll...  ...program: the questionnaires, risk tracking, analyses, tooling, and...  .... For this role, the Hiring Manager would like folks to be in the office... 
    Suggested
    Full time
    Work at office
    Immediate start
    Relocation
    Relocation package
    2 days per week

    Discord

    San Francisco, CA
    2 days ago
  • $1,750 - $2,150 per month

     ...experienced cybersecurity professionals — security analysts, penetration testers, incident...  ...cybersecurity at an enterprise organization, managed security service provider (MSSP), consultancy...  ...GCP), or zero‑trust design Governance, risk, and compliance (GRC) — NIST, ISO 27001... 
    Suggested
    Remote job
    Hourly pay

    Obsidian

    San Francisco, CA
    2 days ago
  •  ...union. The Cybersecurity Awareness Analyst leads the design and execution of the organization’s security awareness and training programs...  ...order to reduce institutional risk. The Analyst works closely with the Cybersecurity Risk Management Manager and CISO to support... 
    Suggested
    Work experience placement
    Worldwide

    University of California, San Francisco

    San Francisco, CA
    6 days ago
  • $91.5k - $120k

     ...Departmental Overview The Information Security Office (ISO) coordinates the risk management process for UC Berkeley's...  ...Summary As a seasoned IT Security Analyst working collaboratively within the...  ...Go. Experience with the Elastic ecosystem, particularly Logstash, Kibana, and... 
    Full time
    H1b
    Work at office
    Immediate start
    Afternoon shift

    University of California, Berkeley

    Berkeley, CA
    2 days ago
  • $90k - $100k

     ...are looking for:  We’re looking for a Security Analyst to help keep Forage’s security and...  ...Key Responsibilities:  Triage and manage incoming security requests from entire...  ...Please note: We are not engaging with third-party recruiters or agencies for this role. We... 
    Work at office

    Forage

    San Francisco, CA
    more than 2 months ago
  • $151.05k - $166.95k

     ...is expanding its Information Security function, and this is the team...  ...Senior Security Operations Analyst (Detection & Response), you will...  ...your work to directly reduce risk to real people's financial...  ...spots. Own vulnerability management: run day-to-day vulnerability... 
    Temporary work
    Work experience placement
    Immediate start
    Remote work
    Home office
    Flexible hours
    2 days per week
    3 days per week
    1 day per week

    Point Digital Finance, Inc.

    San Francisco, CA
    9 days ago
  • Information Security Analyst Location: San Francisco, CA; Los Angeles, CA; Salt Lake City, Utah Duration: 12+ Months, 5 days onsite Must Have: SPL that Splunk uses Actual incident tickets - resolve actual security incident tickets Qualifications: Bachelor's degree... 
    Contract work
    Work at office

    Compunnel Inc.

    San Francisco, CA
    5 days ago
  •  ...keep the electric grid secure and reliable, even...  ...Information Security Analyst, AI Governance will own...  ...data-exposure and misuse risk, deploying and configuring...  ...for business use, and managing their ongoing...  ...and jailbreak exposure, third-party plugin risk, and integration... 
    Ongoing contract
    Full time
    Work at office
    Relocation package

    Form Energy, Inc.

    Berkeley, CA
    1 day ago
  • $153k - $215k

     ...LinkedIn, Monday.com, Nvidia, and Bridgewater. About The Team The Security team at LangChain treats compliance as a business enabler, not a...  ...confidence in our security posture. Support vendor privacy risk assessments during onboarding and renewals. What you’ll bring... 
    Contract work
    Work at office
    Flexible hours

    LangChain

    San Francisco, CA
    4 days ago
  •  .... Job Description Working in the Border Security operations space, the Associate Border Security Analyst performs the day-to-day operations on Firewalls,...  ...policy changes in accordance with established change-management, security, and operational procedures. Create... 
    Temporary work
    Local area
    Weekend work

    AbbVie

    San Francisco, CA
    16 days ago
  •  ...recruiting process here . Pinterest’s Security team (Pinfosec) is seeking an IC14...  ...Security Engineer -  Security Governance, Risk & Compliance (GRC Senior Analyst) to support and strengthen our...  ...security processes that help the business manage risk effectively. Reporting to the... 
    Full time
    Interim role

    Pinterest

    San Francisco, CA
    8 days ago
  •  ...Job Description Job Description Job43 – EITS Security Risk Analyst B (Engagement) Location: 100% Remote Max Submissions: 5 Proposed...  .... Coordinate enterprise-level security and risk management efforts. Act as a subject matter expert (SME) on information... 
    Remote job
    Immediate start
    Flexible hours

    DELTASOFT SOLUTIONS LLC

    San Francisco, CA
    1 day ago
  • $80k - $135k

     ...LLM, and TTS – rather than relying on third-party API providers. This is a deliberate architectural...  ...enables the uptime guarantees, data security standards, and customization depth that...  ...self-directed — does not need heavy management or a fully built playbook to be... 
    Full time

    Bland AI

    San Francisco, CA
    3 days ago
  • $200k - $225k

    Description The best advisors are more than portfolio managers — they are the confidantes families turn to across generations...  ...strategies in-house with our innovative approach to risk management and select third-party managers. Our alternative investments are unique and... 
    Work at office

    Lido Advisors

    San Francisco, CA
    2 days ago
  • University of California, Berkeley is seeking a seasoned IT Security Analyst to join the Security Engineering team within the Information Security Office. You will administer security systems, implement controls, and support broad-scale security initiatives across campus... 
    Work at office

    University of California, Berkeley

    Berkeley, CA
    2 days ago
  • $117.2k - $176.7k

     ...are the future of Salesforce.The ExperienceEnterprise Security is looking for a Senior Analyst to support our Business Information Security Officers (...  ...to keep those engagements running smoothly — tracking risks and commitments, coordinating deliverables, and preparing... 
    Full time

    Salesforce

    San Francisco, CA
    1 day ago
  • $102.5k - $187.9k

     ...rapid growth across SAP and Governance, Risk, and Compliance (GRC), EY is seeking SAP Security and GRC professionals who understand risk management challenges and can support improved...  ...multi-disciplinary network and diverse ecosystem partners, EY teams can provide services... 
    Summer holiday
    Flexible hours
    Shift work

    EY

    San Francisco, CA
    1 day ago
  • $152.7k - $294k

     ...The Global Information Security Strategist is a senior role responsible...  ...business demands and cyber risks. Key Responsibilities:...  ...program leadership and stakeholder management skills. Proven ability to...  ...network and diverse ecosystem partners, EY teams can provide... 
    Summer holiday
    Local area
    Flexible hours
    Shift work

    EY

    San Francisco, CA
    2 days ago
  • $117.2k - $176.7k

     ...has the information needed to make strategic, risk-based decisions. The GCC team is a division within the Product Security Organization, and you'll play a pivotal role in...  ...experience in IT audit or internal controls, managing global compliance assessments in complex environments... 
    Full time

    Salesforce

    San Francisco, CA
    1 day ago
  • $200k - $285k

     ...and build lasting financial security in whatever way is most relevant...  ...Career for You? The Chief Risk Officer (CRO) is a key member...  ...responsible for the overall management of risk across the credit union...  ...Vendor Management Manage the third-party risk management program,... 
    Work at office
    Local area

    SF Fire Credit Union

    San Francisco, CA
    2 days ago
  • $150k - $250k

     ...leading robotics companies and national-security-critical hardware. Basically, we're...  ...&M ownership, evidence collection, and managing the C3PAO assessment (we're already evaluating...  ...and lead real incidents. Vendor/third-party risk management, including ITAR/CMMC-aware external... 
    Full time
    Contract work
    Work at office

    Garuda Ventures

    San Francisco, CA
    3 days ago
  •  ...to meet you. About The Role Security is now a strategic differentiator...  ...testing, and vulnerability management Define security standards...  ...response capabilities Governance, Risk & Compliance Lead our...  ...Own vendor risk management and third-party security reviews Partner with... 
    Full time
    Work at office
    Remote work
    Flexible hours
    2 days per week

    Plenful

    San Francisco, CA
    4 days ago
  • $244k - $390.58k

     ...Docusign’s Intelligent Agreement Management platform, companies can...  ...The Senior Director, Product Security leads all aspects of the Docusign...  ...vulnerabilities and broader risks. The role will oversee...  .../capabilities of the product ecosystem Maintain deep technical expertise... 
    Contract work
    Work at office
    Local area
    Remote work
    2 days per week

    Docusign

    San Francisco, CA
    3 days ago
  •  ...Snorkel is hiring a Head of Security to build and lead our security...  ...application security, and governance, risk & compliance (GRC). You'll...  ...modeling, and vulnerability management programs Set standards for...  ...practices: risk register, third-party/vendor risk, policy framework... 
    For contractors
    Flexible hours

    Snorkel AI

    San Francisco, CA
    2 days ago
  •  ...of Google's earliest product managers and co-creator of Google Maps...  ...do ~ Drive high-impact security and infrastructure...  ...managing dependencies, tracking risk, and ensuring delivery of Sierra...  ...~ Legal: On security terms, third-party risk, and contractual obligations... 
    Full time
    Flexible hours

    Sierra

    San Francisco, CA
    1 day ago
  • $128.55k - $222.82k

     ...responsible for the origination and management of profitable commercial...  ...the Company’s established risk and return parameters. This...  ...with financial, market and security analysis, to update the credit...  ...you provide to us or third parties in the application process.... 
    Temporary work
    Local area
    Home office
    Flexible hours

    Manulife and John Hancock

    San Francisco, CA
    1 hour ago
  • $95k - $115k

    Join to apply for the Financial Analyst, FP&A role at OFX Join to apply for the Financial...  ...doing business across borders, reducing risk and eliminating routine operational tasks...  ...countries in 30+ currencies and currency risk management solutions to simplify global payments.... 
    Full time
    Work at office
    Flexible hours

    OFX

    San Francisco, CA
    5 days ago
  • $140k - $190k

     ...seeking a data-driven and hands-on Manager / Sr Manager on our Card Credit Risk team to drive a variety of...  ...are responsible for maintaining a secure and productive workspace with reliable...  ...staffing agencies, search firms, or any third parties. Any resume submitted to any... 
    Work at office
    Local area
    Remote work
    Worldwide

    Upgrade

    San Francisco, CA
    13 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Analyst, Third-Party Ecosystem Risk Management. Be the first to apply!