Impress employers and recruiters.
Choose from hundreds of resume examples.

Impress employers and recruiters.
Choose from hundreds of resume examples.
Tailor your resume to this Security Analyst, Third-Party Ecosystem Risk Management role.
Rezi rewrites your resume against Plaid's job description. Free.

Tailor your resume to this Security Analyst, Third-Party Ecosystem Risk Management role.
Rezi rewrites your resume against Plaid's job description. Free.
Don't guess if your resume is good enough.
See how it scores against the Security Analyst, Third-Party Ecosystem Risk Management posting at Plaid — free, in seconds.

Don't guess if your resume is good enough.
See how it scores against the Security Analyst, Third-Party Ecosystem Risk Management posting at Plaid — free, in seconds.
About the Role
The Security Governance, Risk, and Compliance (GRC) team is focused on enabling the business by proactively managing information security risks and maintaining effective controls. This role will manage security risk assessments for Plaid’s third parties end-to-end, assess the security posture of customers and partners, and mature the third-party risk program.
Responsibilities
- Run Vendor Security Risk Assessments: Triage inbound vendor requests, run security reviews scaled to risk tier, rate the risk, and document findings and exceptions.
- Vet Customer and Partner Security Posture: Review the security practices of customers and partners onboarding to the platform, applying the same standards used for vendors.
- Keep the Third-Party Risk Lifecycle Current: Maintain risk tiering, drive reassessments on cadence, chase remediation to closure, and keep the risk register accurate.
- Mature the Program: Improve questionnaires, tiering criteria, intake, runbooks, and tooling as review volume grows.
- Report on Ecosystem Risk: Track assessment cycle times, backlog, open exceptions, and reassessment coverage, and report program health to stakeholders.
- Scale Through AI and Tooling: Build and scale AI-assisted workflows for assessment review, questionnaire analysis, and reporting.
Requirements
- 4+ years of experience in vendor risk management
- Experience running security risk assessments of third parties—reviewing questionnaires, SOC 2 and ISO reports, and security documentation, and translating them into a defensible risk rating.
- Familiarity with the third-party risk lifecycle: intake, tiering, exceptions and risk acceptance, remediation tracking, and periodic reassessment.
- Working knowledge of SOC 2, ISO 27001, NIST CSF, and common control domains (access control, encryption, incident response, BC/DR).
- Ability to read a control environment and tell a real gap from an acceptable compensating control.
- Experience maturing a third-party or vendor risk program—improving how it works (tiering criteria, questionnaires, workflow, automation), not just executing an existing one.
- Track record running assessments at volume without dropping rigor.
- Strong analytical and documentation skills: clear findings, clean tracking, and defensible risk decisions others can follow.
- Clear written and verbal communication—able to explain a security risk to Procurement, Legal, or a customer without overstating or hand-waving.
- Comfortable working across Security, Legal, Procurement, and GTM as the third-party risk point of contact.
- Demonstrated ability to apply AI tooling to assessment review, questionnaire analysis, and reporting to materially increase throughput—and to share what works with the team.
Skills
- Vendor risk management
- Third-party risk assessment
- Security risk assessment
- SOC 2
- ISO 27001
- NIST CSF
- Access control
- Encryption
- Incident response
- BC/DR
- Program maturation
- Analytical skills
- Documentation skills
- Written communication
- Verbal communication
- AI tooling
- Assessment review
- Questionnaire analysis
- Reporting
Location
- San Francisco
- New York
- Washington D.C.
- London
- Amsterdam
Work Type
- Full-time
Experience Level
- 4+ years of experience
Education Level
- CTPRP
- CISA
- CISSP
Benefits
- Medical
- Dental
- Vision
- 401(k)
About the Company
- Plaid powers the tools millions of people rely on to live a healthier financial life.
- We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use.
- Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe.
- Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam.
- Our mission at Plaid is to unlock financial freedom for everyone.
- To support that mission, we seek to build a diverse team of driven individuals who care deeply about making the financial ecosystem more equitable.
Equal Opportunity
- Plaid is proud to be an equal opportunity employer and values diversity at our company.
- We do not discriminate based on race, color, national origin, ethnicity, religion or religious belief, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, military or veteran status, disability, or other applicable legally protected characteristics.
- We also consider qualified applicants with criminal histories, consistent with applicable federal, state, and local laws.
- Plaid is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process.
- If you need any assistance with your application or interviews due to a disability, please let us know at accommodations@plaid.com.