Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Analyst, Third-Party Ecosystem Risk Management

$118.68k - $175.8k

Plaid

We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam. Team The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security organization, focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission is to reduce the likelihood and impact of security risks while operating a robust assurance program that builds trust with our customers, consumers, and data partners. We partner closely across the company to ensure Plaid’s platform remains secure, resilient, and aligned with industry and regulatory expectations. Third-party ecosystem risk is a core part of how we keep Plaid safe—we vet the security of both the vendors we rely on and the customers and partners who connect to our platform, so trust runs in both directions. Role You will run security risk assessments for Plaid’s third parties end-to-end—from intake and questionnaire through risk rating, findings, and tracked exceptions. You will assess the security posture of customers and partners onboarding to the platform with the same rigor we apply to vendors. You will keep the third-party risk lifecycle moving—risk tiering, reassessment cadence, remediation follow-through, and a clean, current risk register. You will help mature the program—questionnaires, tiering criteria, intake, and runbooks—so reviews get faster and more consistent as volume grows, drawing on how you’ve improved third-party risk programs before. You will report on ecosystem risk to Security and cross-functional stakeholders, and operate as an AI power user to raise your own throughput. Responsibilities Run Vendor Security Risk Assessments: Triage inbound vendor requests, run security reviews scaled to risk tier, rate the risk, and document findings and exceptions. Your assessments keep Plaid from inheriting a vendor’s security gaps and give Procurement, Privacy, and Legal a clear risk signal before contracts are signed. Vet Customer and Partner Security Posture: Review the security practices of customers and partners onboarding to the platform, applying the same standards you use for vendors. Your reviews make sure who connects to Plaid meets the bar before they touch data—protecting consumers and the ecosystem. Keep the Third-Party Risk Lifecycle Current: Maintain risk tiering, drive reassessments on cadence, chase remediation to closure, and keep the risk register accurate. Your follow-through keeps third-party risk a live, trustworthy picture rather than a point-in-time checkbox. Mature the Program: Improve questionnaires, tiering criteria, intake, and tooling as review volume grows—bringing patterns from third-party risk programs you’ve matured before. Your work moves the function from ad hoc toward fast, consistent, and scalable. Report on Ecosystem Risk: Track assessment cycle times, backlog, open exceptions, and reassessment coverage, and report program health to stakeholders. Your reporting gives leadership real visibility into where third-party risk concentrates. Scale Through AI and Tooling: Build and scale AI-assisted workflows for assessment review, questionnaire analysis, and reporting—and share what works. Your approach sets how the team uses AI to handle more reviews without adding headcount. Qualifications Must-haves 4+ years of experience in vendor risk management Third-party and vendor security risk assessment: Experience running security risk assessments of third parties—reviewing questionnaires, SOC 2 and ISO reports, and security documentation, and translating them into a defensible risk rating. Familiarity with the third-party risk lifecycle: intake, tiering, exceptions and risk acceptance, remediation tracking, and periodic reassessment. Security and compliance knowledge: Working knowledge of SOC 2, ISO 27001, NIST CSF, and common control domains (access control, encryption, incident response, BC/DR). Ability to read a control environment and tell a real gap from an acceptable compensating control. Program maturation and operational execution: Experience maturing a third-party or vendor risk program—improving how it works (tiering criteria, questionnaires, workflow, automation), not just executing an existing one. Track record running assessments at volume without dropping rigor. Strong analytical and documentation skills: clear findings, clean tracking, and defensible risk decisions others can follow. Communication and cross-functional effectiveness: Clear written and verbal communication—able to explain a security risk to Procurement, Legal, or a customer without overstating or hand-waving. Comfortable working across Security, Legal, Procurement, and GTM as the third-party risk point of contact. AI fluency and tooling: Demonstrated ability to apply AI tooling to assessment review, questionnaire analysis, and reporting to materially increase throughput—and to share what works with the team. Nice-to-have A third-party-risk or audit credential (CTPRP, CISA, or CISSP), or hands-on ownership of a TPRM platform (e.g. OneTrust, ProcessUnity, Whistic, SecurityScorecard) beyond using it as an end user. Our mission at Plaid is to unlock financial freedom for everyone. To support that mission, we seek to build a diverse team of driven individuals who care deeply about making the financial ecosystem more equitable. We recognize that strong qualifications can come from both prior work experiences and lived experiences. We encourage you to apply to a role even if your experience doesn't fully match the job description. We are always looking for team members that will bring something unique to Plaid! Plaid is proud to be an equal opportunity employer and values diversity at our company. We do not discriminate based on race, color, national origin, ethnicity, religion or religious belief, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, military or veteran status, disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state, and local laws. Plaid is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance with your application or interviews due to a disability, please let us know at View email address on click.appcast.io. Please review our Candidate Privacy Notice here. Additional compensation in the form(s) of equity and/or commission are dependent on the position offered. Plaid provides a comprehensive benefit plan, including medical, dental, vision, and 401(k). Pay is based on factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience and skillset, and location. Pay and benefits are subject to change at any time, consistent with the terms of any applicable compensation or benefit plans. Compensation Range: $118,680 - $175,800 #J-18808-Ljbffr Plaid

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Security Analyst, Third-Party Ecosystem Risk Management in Seattle, WA vacancy
  •  ...Overview: Cybersecurity GRC Security Analyst - Risk and Issue Management Who we are We are a yoga-inspired technical apparel company up to big things. The practice and philosophy of yoga informs our overall purpose to elevate the world through the power of... 
    Suggested

    Voluble Systems LLC

    Seattle, WA
    3 days ago
  • SCT seeks a Program Analyst to support a national security mission, providing technical expertise and analytical leadership on nuclear R&D and engineering...  ...advisor and contribute to strategic planning, risk management, and program oversight. The role demands at least 3... 
    Suggested

    SCT

    Seattle, WA
    2 days ago
  • $129k - $171k

     ...Detection and Response team is looking for a Security Operations Analyst to be the watchtower for Anduril's critical defense...  ..., you consent to Anduril Industries using a third-party service provider to conduct pre-employment risk, integrity, and due diligence screening and... 
    Suggested
    Full time
    Work experience placement
    Immediate start

    Anduril Industries

    Seattle, WA
    3 days ago
  • $80k - $105k

     ...Information Security Analyst At JH Kelly , we’re seeking a proactive, detail...  ...10 years. Vulnerability Management & Remediation Leadership Own...  ...discovery, scanning, validation, risk scoring, prioritization,...  ...or coordinate internal and third-party security assessments, including... 
    Suggested
    Work at office

    JH Kelly

    Seattle, WA
    4 days ago
  • $128.1k - $239.6k

     ..., all of whom rely on secure technology to be able...  ...responds and mitigates cyber-risk, protecting EY and...  ..., and our information management systems.   The...  ...seeking an Active Defense Analyst with a strong...  ...disciplinary network and diverse ecosystem partners, EY teams can... 
    Suggested
    Summer holiday
    Local area
    Remote work
    Flexible hours
    Night shift
    Weekend work

    EY

    Seattle, WA
    2 days ago
  • $102.83k - $190.97k

     ...office.* THE JOB The Senior Information Security Risk Analyst will support the assessment of...  ...of Warner Bros. Discovery's (WBD's) third party suppliers/vendors. This role requires...  ...third party information security risk management to foster business-enabling insights.... 
    Contract work
    Temporary work
    Work at office
    Local area

    Warner Bros. Discovery

    Seattle, WA
    15 hours ago
  • $175.1k - $236.9k

    We're looking for an experienced Security Engineering Manager to join our Secure Third Party Tools team. Our team builds the standards, controls, and expert review...  ...modeling, security architecture reviews, and risk assessments for complex or novel third-party integrations... 
    Flexible hours

    Amazon

    Seattle, WA
    2 days ago
  • $75.7k

     ...(UW-IT) has an outstanding opportunity for Security Analyst to join their team.About this OpportunityReporting to Technology Manager, the Security Analyst serves as a technical...  ...researchers and technical staff to assess security risks, implement security best practices, support... 
    Full time
    Temporary work
    Work at office
    Shift work

    University of Washington

    Seattle, WA
    1 day ago
  • $117.2k - $176.7k

     ...are the future of Salesforce.The ExperienceEnterprise Security is looking for a Senior Analyst to support our Business Information Security Officers (...  ...to keep those engagements running smoothly — tracking risks and commitments, coordinating deliverables, and preparing... 
    Full time

    Salesforce

    Bellevue, WA
    3 days ago
  •  ...Security AnalystIn this role, you will work collaboratively with the Cybersecurity GRC team...  ...SOX control certifications and management attestations.Automates and assists in gathering...  ...internal and external SOX audits.Applies a risk-based approach to planning, executing,... 

    Georgia IT Inc

    Seattle, WA
    3 days ago
  •  ...controller architecture and content management system. Our services also extend to the...  .... Job Description Participate in security planning and analyst activities. Performs security assessments...  ...Threat Models like ASF, STRIDE and Risk Assessment model like DREAD. Prepare... 

    360 IT Professionals

    Bellevue, WA
    4 days ago
  • $113.01k - $208.54k

    Duties: Provide thought leadership to the organization in information security frameworks, business continuity management, reporting and metrics, security risk management, firewall protection, information security training, intrusion prevention, data loss prevention, anti... 
    Minimum wage
    Shift work

    Providence Health & Services

    Renton, WA
    4 days ago
  •  ...Application Security Analyst (AI Training) About the Role We're partnering with the world's leading AI research labs to build smarter...  ...learn how to assess, prioritize, and remediate application risk. Your expertise in identifying exploitable vulnerabilities - not... 
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work

    Alignerr

    Seattle, WA
    3 days ago
  •  ...Senior Analyst, DSO Policy Assurance Team As a member of the DSO...  ...enabling adherence to corporate security policies via procedural and...  ...They will identify, track and manage remediation and mitigation activities...  ..., IT Audit, GRC (Governance, Risk, Compliance) or related field... 
    Contract work

    Software Technology Inc

    Bellevue, WA
    2 days ago
  •  ...Federal Systems is seeking an Information Security Analyst to join our work supporting our DHS...  ...include but are not limited to: Track and manage POAMs throughout the remediation cycle from...  ...and update System Security Plan (SSP), Risk Assessment (RA), Privacy Threshold... 
    Work at office

    NextGen Federal Systems

    Seattle, WA
    3 days ago
  •  ...and Certification (GCC) team. You will partner with engineering to translate regulatory mandates into actionable controls and drive risk mitigation across Salesforce environments. In this role, you will work with external auditors, translate frameworks into deliverables... 

    Salesforce

    Seattle, WA
    4 hours ago
  •  ...Job Title: Information Security Analyst Location: Bellevue, WA Type: Contract Contractor...  ...respond to security alerts from the Managed Detection & Response (MDR) service, as...  ...requests to identify potential security risks and provide actionable recommendations... 
    Permanent employment
    Full time
    Contract work
    For contractors
    Work experience placement
    Local area

    System One

    Bellevue, WA
    2 days ago
  • $1,600 per month

     ...Profession Information Security City Washington DC USA The role of the Information Security Analyst is to protect and secure our organizations...  ...responsible for conducting risk assessments implementing...  ...detectionprevention systems vulnerability management tools etc Ability to conduct... 
    Full time

    EliteService Staffing

    Seattle, WA
    4 hours ago
  • $46 - $63 per hour

     ...innovations, is looking for an Information Security Analyst. This role will support cybersecurity...  ...security operations, vulnerability management, and security awareness functions while...  ...software and technology requests for security risks and provide mitigation recommendations.... 
    Hourly pay
    Local area

    Hansell Tierney

    Bellevue, WA
    4 days ago
  • The University of Washington's Information Technology unit seeks a Security Analyst to implement and manage security controls across research computing and cloud environments. You will assess risks, drive best practices, and support compliance initiatives in a hybrid work... 

    FHLB Des Moines

    Seattle, WA
    4 days ago
  • KBR, Inc. is seeking an All Source Analyst in the Washington, DC area to support national security missions with high-quality intelligence products. The role...  ...delivering briefings that inform program decisions and risk management. The position offers competitive compensation... 

    KBR, Inc.

    Seattle, WA
    3 days ago
  • $100k - $180k

     ...effectiveness, data analytics, talent management, human capital management, and...  ...SCT is seeking a Program Analyst to provide direct support to our team within a national security mission organization. The...  ...implementation, and supply chain risks and recommend mitigation... 
    Contract work
    Work at office

    SCT

    Seattle, WA
    2 days ago
  • $55.2k - $126k

    Security Cooperation Analyst The Opportunity: Are you searching for a position where you can use your program...  ...the Defense Security Assistance Management System (DSAMS), Management...  ...develop program strategy and eliminate risks across projects. Help make sure our... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Seattle, WA
    3 days ago
  • $140.8k - $176k

    DigitalOcean is seeking a Senior Security Analyst to lead critical aspects of our security monitoring program. You will be responsible for real-time monitoring of security events and developing detection capabilities while collaborating with other teams to enhance security... 

    DigitalOcean

    Seattle, WA
    3 days ago
  •  ...locate missing children, and more. The Role As a Defensive Security Analyst, you are responsible for the security of Palantir’s people and...  ...on new challenges. In this role, you'll independently manage SOC systems that are essential to our security posture, ensuring... 

    Palantir

    Seattle, WA
    15 hours ago
  • $120k - $130k

     ...Job Summary BDA is looking for a Senior Security Analyst who can help us strengthen our security...  ...IT and business partners to reduce risk across the organization. You will alsohave...  ..., or ISO 27001. Understanding ofrisk management practices and the ability toidentify,... 
    Summer work
    Local area
    Remote work

    BDA

    Seattle, WA
    4 days ago
  • General Dynamics Information Technology is seeking an Information Security Analyst to design, implement, and manage secure Azure Government Secret cloud architectures. You will enforce zero-trust, RBAC, and identity federation, while configuring Defender for Cloud, Key... 

    General Dynamics Information Technology

    Seattle, WA
    3 days ago
  •  ...development company based in Bellevue is looking for a skilled Mobile Security Analyst to participate in security assessments and perform thorough...  ...investigations and preparing reports to mitigate identified risks. This role offers an opportunity to impact security protocols... 

    360 IT Professionals

    Bellevue, WA
    1 day ago
  • $100k

     ...to join our team as a Threat Hunter / SOC Analyst. In this role, you will play a critical role in enhancing our operational security by conducting manual threat detection operations...  ...* Experience conducting threat hunting or managing incident response for organizations,... 
    Permanent employment
    Work at office
    Relocation

    Galvanick

    Seattle, WA
    16 days ago
  • $83.93k - $113.55k

     ...None Job Family: Cyber and IT Risk Management Job Qualifications: Skills:...  ...and Milestones (POA&M), Security Vulnerability Assessments Certifications...  ...: Information Security Analyst Duties and Responsibilities:...  ...security assessments with third‑party assessors Manage Plans of... 
    Temporary work
    Immediate start
    Remote work
    Worldwide
    Flexible hours
    3 days per week

    General Dynamics Information Technology

    Seattle, WA
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Analyst, Third-Party Ecosystem Risk Management. Be the first to apply!