Jobs › Security Analyst, Third-Party Ecosystem Risk Management
Security Analyst, Third-Party Ecosystem Risk Management
Job at a glance
- Category
- Risk
- Work arrangement
- On-site
- Location
- New York City
- Posted
- Aug 31, 2026
Free. One click to unsubscribe. We never share your address.
Plaid is hiring a Security Analyst, Third-Party Ecosystem Risk Management in New York City. This is a Risk job in the governance, risk, and compliance field. Review the full details below and apply directly with Plaid.
We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Seattle, Washington D.C., Raleigh, London, and Amsterdam. Team: The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security organization, focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission is to reduce the likelihood and impact of security risks while operating a robust assurance program that builds trust with our customers, consumers, and data partners.We partner closely across the company to ensure Plaid’s platform remains secure, resilient, and aligned with industry and regulatory expectations. Third-party ecosystem risk is a core part of how we keep Plaid safe, we vet the security of both the vendors we rely on and the customers and partners who connect to our platform, so trust runs in both directions. Role: You will run security risk assessments for Plaid’s third parties end-to-end, from intake and questionnaire through risk rating, findings, and tracked exceptions. You will assess the security posture of customers and partners onboarding to the platform with the same rigor we apply to vendors. You will keep the third-party risk lifecycle moving, risk tiering, reassessment cadence, remediation follow-through, and a clean, current risk register. You will help mature the program, questionnaires, tiering criteria, intake, and runbooks, so reviews get faster and more consistent as volume grows, drawing on how you’ve improved third-party risk programs before. You will report on ecosystem risk to Security and cross-functional stakeholders, and operate as an AI power user to raise your own throughput. Responsibilities: Run Vendor Security Risk Assessments : Triage inbound vendor requests, run security reviews scaled to risk
Full responsibilities and requirements are on Plaid's application page.
Apply for this job →Location and market context
This job is based in New York City on-site. Local candidates benefit from being close to Plaid's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.
About risk management jobs
Risk jobs own the methodology for identifying, assessing, and escalating enterprise, operational, and technology risk. Second-line teams set risk appetite and challenge the first line. Jobs like this one are typically evaluated against frameworks such as enterprise and operational risk frameworks, NIST AI RMF, and risk-appetite and escalation practices.
How to position yourself for this risk management job
Strong candidates emphasize risk assessment methodology, appetite and escalation, cross-functional partnership, and clear reporting to senior leadership and the board. In your resume and outreach, tie your experience to how Plaid would apply enterprise and operational risk frameworks, NIST AI RMF, and risk-appetite and escalation practices, and lead with concrete outcomes rather than duties.
Similar GRC jobs
More GRC jobs: All GRC jobs · Search by category & location