CareerPlanSign in

Security Analyst, Third-Party Ecosystem Risk Management

New York City Office💼 Full-time🗓 2026-08-12 → 2026-09-26

Core

Manage end-to-end security risk assessments for Plaid's third-party vendors and customers/partners to ensure ecosystem security and compliance.

Role type

Senior Third-Party Risk Management (TPRM) Analyst

Builds

A scalable, AI-enhanced third-party risk program and risk register

Domain

Financial technology security and third-party risk management

Deliverable

production ML models | product features | dashboards & analysis | client delivery | infrastructure

Required skills

Vendor security risk assessment, third-party risk lifecycle management, SOC 2/ISO 27001/NIST CSF knowledge, program maturation, risk tiering, remediation tracking, AI tooling fluency

Preferred skills

CTPRP/CISA/CISSP certification, hands-on TPRM platform ownership (OneTrust, ProcessUnity, Whistic, SecurityScorecard)

Technologies

OneTrust, ProcessUnity, Whistic, SecurityScorecard, AI tools for assessment and reporting

Responsibilities

Run vendor security risk assessments and triage inbound requests; vet customer and partner security posture; maintain risk tiering and drive remediation; mature the TPRM program with improved questionnaires and workflows; report ecosystem risk metrics to stakeholders; scale assessment workflows using AI.

Seniority

Mid-Senior, hands-on IC

Sourced via ashby · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.