North AmericaFull TimeOther
Remotely
iso 27001soc 2all othernist csfonetrustwhisticprocessunity
Job Description
📋 Description
- Run security risk assessments for Plaid’s third parties end-to-end
- Assess security posture of customers and partners onboarding to the platform
- Maintain third-party risk lifecycle: tiering, reassessment cadence, remediation tracking
- Mature the program: questionnaires, runbooks, intake, and tooling
- Report ecosystem risk to Security and cross-functional stakeholders; leverage AI tooling to improve
🎯 Requirements
- 4+ years in vendor risk management
- Experience running security risk assessments of third parties (SOC 2, ISO 27001, security docs)
- Familiarity with third-party risk lifecycle: intake, tiering, exceptions, remediation, reassessment
- Security/compliance knowledge: SOC 2, ISO 27001, NIST CSF; control domains (access, encryption
- Program maturation and operational execution; ability to scale assessments
- Strong communication across Security, Legal, Procurement, GTM; AI tooling proficiency
🎁 Benefits
- Equity (as part of compensation)
- Comprehensive benefits: medical, dental, vision, 401(k)