Security Analyst, Third-Party Ecosystem Risk Management

Added
6 days ago
Type
Full time
Salary
Upgrade to Premium to se...

Related skills

iso 27001 soc 2 nist csf onetrust whistic

📋 Description

  • Run security risk assessments for Plaid’s third parties end-to-end
  • Assess security posture of customers and partners onboarding to the platform
  • Maintain third-party risk lifecycle: tiering, reassessment cadence, remediation tracking
  • Mature the program: questionnaires, runbooks, intake, and tooling
  • Report ecosystem risk to Security and cross-functional stakeholders; leverage AI tooling to improve

🎯 Requirements

  • 4+ years in vendor risk management
  • Experience running security risk assessments of third parties (SOC 2, ISO 27001, security docs)
  • Familiarity with third-party risk lifecycle: intake, tiering, exceptions, remediation, reassessment
  • Security/compliance knowledge: SOC 2, ISO 27001, NIST CSF; control domains (access, encryption
  • Program maturation and operational execution; ability to scale assessments
  • Strong communication across Security, Legal, Procurement, GTM; AI tooling proficiency

🎁 Benefits

  • Equity (as part of compensation)
  • Comprehensive benefits: medical, dental, vision, 401(k)
Share job

Meet JobCopilot: Your Personal AI Job Hunter

Automatically Apply to All Other Jobs. Just set your preferences and Job Copilot will do the rest — finding, filtering, and applying while you focus on what matters.

Related All Other Jobs

See more All Other jobs →