Security Analyst, Third-Party Ecosystem Risk Management
$118.68k - $175.8kPlaid
We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam. Team The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security organization, focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission is to reduce the likelihood and impact of security risks while operating a robust assurance program that builds trust with our customers, consumers, and data partners. We partner closely across the company to ensure Plaid’s platform remains secure, resilient, and aligned with industry and regulatory expectations. Third-party ecosystem risk is a core part of how we keep Plaid safe—we vet the security of both the vendors we rely on and the customers and partners who connect to our platform, so trust runs in both directions. Role You will run security risk assessments for Plaid’s third parties end-to-end—from intake and questionnaire through risk rating, findings, and tracked exceptions. You will assess the security posture of customers and partners onboarding to the platform with the same rigor we apply to vendors. You will keep the third-party risk lifecycle moving—risk tiering, reassessment cadence, remediation follow-through, and a clean, current risk register. You will help mature the program—questionnaires, tiering criteria, intake, and runbooks—so reviews get faster and more consistent as volume grows, drawing on how you’ve improved third-party risk programs before. You will report on ecosystem risk to Security and cross-functional stakeholders, and operate as an AI power user to raise your own throughput. Responsibilities Run Vendor Security Risk Assessments: Triage inbound vendor requests, run security reviews scaled to risk tier, rate the risk, and document findings and exceptions. Your assessments keep Plaid from inheriting a vendor’s security gaps and give Procurement, Privacy, and Legal a clear risk signal before contracts are signed. Vet Customer and Partner Security Posture: Review the security practices of customers and partners onboarding to the platform, applying the same standards you use for vendors. Your reviews make sure who connects to Plaid meets the bar before they touch data—protecting consumers and the ecosystem. Keep the Third-Party Risk Lifecycle Current: Maintain risk tiering, drive reassessments on cadence, chase remediation to closure, and keep the risk register accurate. Your follow-through keeps third-party risk a live, trustworthy picture rather than a point-in-time checkbox. Mature the Program: Improve questionnaires, tiering criteria, intake, and tooling as review volume grows—bringing patterns from third-party risk programs you’ve matured before. Your work moves the function from ad hoc toward fast, consistent, and scalable. Report on Ecosystem Risk: Track assessment cycle times, backlog, open exceptions, and reassessment coverage, and report program health to stakeholders. Your reporting gives leadership real visibility into where third-party risk concentrates. Scale Through AI and Tooling: Build and scale AI-assisted workflows for assessment review, questionnaire analysis, and reporting—and share what works. Your approach sets how the team uses AI to handle more reviews without adding headcount. Qualifications Must-haves 4+ years of experience in vendor risk management Third-party and vendor security risk assessment: Experience running security risk assessments of third parties—reviewing questionnaires, SOC 2 and ISO reports, and security documentation, and translating them into a defensible risk rating. Familiarity with the third-party risk lifecycle: intake, tiering, exceptions and risk acceptance, remediation tracking, and periodic reassessment. Security and compliance knowledge: Working knowledge of SOC 2, ISO 27001, NIST CSF, and common control domains (access control, encryption, incident response, BC/DR). Ability to read a control environment and tell a real gap from an acceptable compensating control. Program maturation and operational execution: Experience maturing a third-party or vendor risk program—improving how it works (tiering criteria, questionnaires, workflow, automation), not just executing an existing one. Track record running assessments at volume without dropping rigor. Strong analytical and documentation skills: clear findings, clean tracking, and defensible risk decisions others can follow. Communication and cross-functional effectiveness: Clear written and verbal communication—able to explain a security risk to Procurement, Legal, or a customer without overstating or hand-waving. Comfortable working across Security, Legal, Procurement, and GTM as the third-party risk point of contact. AI fluency and tooling: Demonstrated ability to apply AI tooling to assessment review, questionnaire analysis, and reporting to materially increase throughput—and to share what works with the team. Nice-to-have A third-party-risk or audit credential (CTPRP, CISA, or CISSP), or hands-on ownership of a TPRM platform (e.g. OneTrust, ProcessUnity, Whistic, SecurityScorecard) beyond using it as an end user. Our mission at Plaid is to unlock financial freedom for everyone. To support that mission, we seek to build a diverse team of driven individuals who care deeply about making the financial ecosystem more equitable. We recognize that strong qualifications can come from both prior work experiences and lived experiences. We encourage you to apply to a role even if your experience doesn't fully match the job description. We are always looking for team members that will bring something unique to Plaid! Plaid is proud to be an equal opportunity employer and values diversity at our company. We do not discriminate based on race, color, national origin, ethnicity, religion or religious belief, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, military or veteran status, disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state, and local laws. Plaid is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance with your application or interviews due to a disability, please let us know at View email address on click.appcast.io. Please review our Candidate Privacy Notice here. Additional compensation in the form(s) of equity and/or commission are dependent on the position offered. Plaid provides a comprehensive benefit plan, including medical, dental, vision, and 401(k). Pay is based on factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience and skillset, and location. Pay and benefits are subject to change at any time, consistent with the terms of any applicable compensation or benefit plans. Compensation Range: $118,680 - $175,800 #J-18808-Ljbffr Plaid
- Plaid is seeking a Security Governance, Risk, and Compliance professional to lead end-to-end vendor risk assessments for third parties. You will evaluate customer and partner security posture... ...protect data across a broad partner ecosystem while advancing #J-18808-Ljbffr...Suggested
$110k - $140k
WHAT YOU WILL DO As a Senior Security Analyst Consultant - Attack Surface Management, you will lead and evolve our client’s enterprise Attack Surface Management (ASM) program, helping reduce cyber risk through proactive discovery, analysis, automation, and collaboration...SuggestedLive in- ...the first time ever, you can manage and automate every part of the... ...computer, benefits, and even third-party apps like Slack and Microsoft... ...the RoleJoin Rippling's Security Assurance team and help demonstrate... ...support informed third-party risk and onboarding decisions....SuggestedWork at office3 days per week
$123.6k - $185.4k
...the most important work of your career. About The Team The Third Party Risk Management (TPRM) team is accountable for defining, maintaining, and... ...maintenance Understanding of risk areas such as information security, privacy, business continuity, finance, reputation,...SuggestedWork at officeLocal area$80k - $105k
Information Security Analyst At JH Kelly , we’re seeking a proactive, detail... ...10 years. Vulnerability Management & Remediation Leadership Own... ..., scanning, validation, risk scoring, prioritization, remediation... ...or coordinate internal and third-party security assessments,...SuggestedWork at office$72.6k - $135.7k
...The opportunity The Threat & Risk Analyst leads strategic and tactical... ...in partnership with Global Security and Regional Security teams,... ...security programs and crisis management operations. Your key... ...disciplinary network and diverse ecosystem partners, EY teams can provide...Summer holidayLocal areaFlexible hours$110.57k - $165.86k
...: The mission of the Information Security Team is to manage Information Security risk at Brooks, including availability... ...Security Operations Center (SOC) Analyst, you will primarily be responsible... ...trends relevant to the Brooks ecosystem to understand emerging threats and...Local area$175.1k - $236.9k
We're looking for an experienced Security Engineering Manager to join our Secure Third Party Tools team. Our team builds the standards, controls, and expert review... ...modeling, security architecture reviews, and risk assessments for complex or novel third-party integrations...Flexible hours$113.01k - $208.54k
Duties: Provide thought leadership to the organization in information security frameworks, business continuity management, reporting and metrics, security risk management, firewall protection, information security training, intrusion prevention, data loss prevention, anti...Minimum wageShift work- ...Consulting (FirstDiv) provides program management, acquisition, logistics, field service... ...team! We are seeking a highly motivated Security Analyst II to support the Washington Headquarters... ...briefings. Prepare country-specific risk assessments for personnel traveling internationally...Civilian ContractorContract workFor contractorsWork at officeLocal area
- ...Security Analyst In this role, you will work collaboratively with the Cybersecurity GRC team... ...quarterly SOX control certifications and management attestations. Automates and assists... ...and external SOX audits. Applies a risk-based approach to planning, executing,...
$23 - $25 per hour
...-time monitoring using advanced cargo sensors, our team of security and logistics professionals keeps an eye on shipments in transit... ...to actively monitor customer shipments, analyze cargo risk events, and manage response protocols. Agents communicate directly with customers...Hourly payWork at officeLocal areaWorldwideShift workAfternoon shift- ...development company based in Bellevue is looking for a skilled Mobile Security Analyst to participate in security assessments and perform thorough... ...investigations and preparing reports to mitigate identified risks. This role offers an opportunity to impact security protocols...
- First Division Consulting (FirstDiv) seeks a Security Analyst II to support the Washington Headquarters Services Security Enterprise Services... ...include policy analysis, administrative security management, inspections, and compliance oversight for DoW agencies and...
- Sound Transit in Seattle is seeking a Security Assurance Analyst to support its Information Security program. You will conduct system audits, assist in vulnerability management, and ensure major systems comply with internal controls and industry requirements. The role...
$140.8k - $176k
...We are looking for a highly experienced and motivated Senior Security Analyst who is passionate about advanced security monitoring,... ...strategies. Experience in proactive threat hunting, vulnerability management, and coordinating with red teams or penetration testers....- ...controller architecture and content management system. Our services also extend to the... .... Job Description Participate in security planning and analyst activities. Performs security assessments... ...Threat Models like ASF, STRIDE and Risk Assessment model like DREAD. Prepare...
- BDA, LLC is seeking a Senior Security Analyst to strengthen our security program and move from a reactive approach to a proactive, planned security... ...potential exploits, and work with IT and business partners to reduce risk across the organization. #J-18808-Ljbffr BDA, LLC
$134.16k - $213.6k
About The Team The Security Governance, Risk, and Compliance team is part of Plaid’s security organization, focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission is to reduce the likelihood and...Contract workLocal area- I8IS - Infiniti Software Solutions seeks a Ping security analyst in Seattle/Plano/St. Louis/onsite. Must have 10-15 years of IAM experience and hands-on work with PingFederate, PingAccess, and PingOne SSO. Proficiency in SAML, OAuth, and OIDC is required, along with access...
- ...integrations, policies, authentication flows, and access controls. Manage application onboarding and SSO integrations across enterprise... ...PagerDuty. Collaborate with application, infrastructure, and security teams to ensure secure and reliable IAM operations. Required...Contract work
$120k - $150k
...skills/ability Setting up Idp and SP connections, Policies, Selectors, Adapters and contract mapping in PingFederate Access Token Management, Access Token Mapping, OIDC polices in PingFederate Onboarding Applications into PingAccess and PingFederate Working on...Contract work$140.8k - $176k
DigitalOcean is seeking a Senior Security Analyst to lead critical aspects of our security monitoring program. You will be responsible for real-time monitoring of security events and developing detection capabilities while collaborating with other teams to enhance security...- Motorola Solutions seeks a Cybersecurity Analyst to assess and analyze cybersecurity documentation for client information systems, developing automations to streamline assessment processes. You will align with FISMA, NIST RMF, and FedRAMP standards, with a primary focus...Remote job
$26.7 - $33.82 per hour
...USD $33.82/Hr. Job Summary The Physical Security Analyst is responsible for assisting in the... ...information, makes recommendations to senior management when appropriate and submits reports as... ...degree in business administration, risk management or equivilent combination of...Work at office$100k
...to join our team as a Threat Hunter / SOC Analyst. In this role, you will play a critical role in enhancing our operational security by conducting manual threat detection operations... ...* Experience conducting threat hunting or managing incident response for organizations,...Permanent employmentWork at officeRelocation- WaFd Bank is seeking a Physical Security Analyst to help develop, oversee, and implement the bank's physical security program. The role collaborates with the Corporate Physical Security Officer and various departments to protect people, assets, and information while upholding...
- ...DescriptionProSidian is a Management and Operations... ...the broad spectrum of Risk Management, Compliance... ...Planning Investment Controls Analyst II to support an... ...manage coastal and marine ecosystems and resources. The... ...the USG’s designated Security Office.Additional InformationCORE...Full timeTemporary workFor contractorsWork experience placementWork at officeFlexible hours
$148k - $203.5k
Secure Every Identity, from AI to Human Identity is the key to unlocking the... ...solution by identifying and resolving risks to the employees, product, and most... ...customers so they can effectively manage their risk. As a Senior level analyst of Customer Assurance, you will...Work experience placementLocal areaWorldwideFlexible hours- Nscale, a GPU cloud provider for AI, seeks a Security Analyst to join their operations team in Seattle. You will triage alerts across endpoints... ...network, investigate suspicious activity, and escalate high‑risk events to the appropriate owners, ensuring timely actions and...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Analyst, Third-Party Ecosystem Risk Management. Be the first to apply!
- rate analyst Seattle, WA
- work from home security analyst Seattle, WA
- entry level information security analyst Seattle, WA
- national security analyst Seattle, WA
- application security analyst Seattle, WA
- information security analyst Seattle, WA
- entry level security analyst Seattle, WA
- security analyst Seattle, WA
- security operations analyst Seattle, WA
- information security compliance analyst Seattle, WA



