Security Analyst, Third-Party Ecosystem Risk Management
Core
Manage end-to-end security risk assessments for Plaid's third-party vendors and customers/partners to ensure ecosystem security and compliance.
Role type
Senior Third-Party Risk Management (TPRM) Analyst
Builds
A scalable, AI-enhanced third-party risk program and risk register
Domain
Financial technology security and third-party risk management
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
Vendor security risk assessment, third-party risk lifecycle management, SOC 2/ISO 27001/NIST CSF knowledge, program maturation, risk tiering, remediation tracking, AI tooling fluency
Preferred skills
CTPRP/CISA/CISSP certification, hands-on TPRM platform ownership (OneTrust, ProcessUnity, Whistic, SecurityScorecard)
Technologies
OneTrust, ProcessUnity, Whistic, SecurityScorecard, AI tools for assessment and reporting
Responsibilities
Run vendor security risk assessments and triage inbound requests; vet customer and partner security posture; maintain risk tiering and drive remediation; mature the TPRM program with improved questionnaires and workflows; report ecosystem risk metrics to stakeholders; scale assessment workflows using AI.
Seniority
Mid-Senior, hands-on IC