This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We enable Plaid to quickly build safe and secure products while ensuring that Plaid's users, data, and infrastructure remains protected. The Security GRC team at Plaid is responsible for reducing the likelihood and impact of the highest risks to the business. We unblock the business by proactively identifying, assessing, and reducing security risks without slowing down product delivery. We reduce security incidents through strong governance, effective controls, and informed risk decisions. We maintain an assurance program that demonstrates security maturity to our key stakeholders. We enable the business to prioritize mitigations that matter the most to our customers, consumers, and data partners. We unblock revenue and partnerships opportunities through efficient, high quality security reviews and audits. We design controls that scale with our business, with a strong bias towards automation and continuous assurance. We partner closely across the entire organization to embed security and risk management into critical workflows. We act as trusted advisors that raise the security bar while enabling innovation, experimentation, and velocity. You will help lead and evolve our Security Governance, Risk, and Compliance program to unblock the next phase of Plaid’s growth. You will report directly to the CISO, and manage a team of ICs responsible for security assurance, compliance operations, and technology risk management. You will be a trusted partner to customer-facing cross-functional teams and product teams across different product areas.
Job Responsibility:
Own Plaid's Security GRC strategy and roadmap
Lead and scale the Security GRC team
Run the Compliance and Assurance programs
Build internal and external customer and partner trust
Accelerate GRC workflows through automation
Requirements:
Hands on experience operating security GRC programs that map to industry frameworks: SSAE18 (SOC1 and SOC2), ISO 27001, SOX 404 ITGCs, NIST CSF and 800-53
Hands on experience translating framework requirements into practical and testable control objectives
Hands on experience operating technology risk management programs, and applying quantitative risk analysis techniques (FAIR) and structured qualitative risk modeling
Cloud-Native security controls and architecture literacy
Direct customer facing security and trust assurance experience, and stakeholder management
Direct auditor facing experience through scoping, evidence collection, testing, and remediations
Direct experience building and deploying control automations
Working knowledge of modern web application architecture, build and release techniques, incident response, AuthN/AuthZ strategies, data encryption, vulnerability management, third-party risk management, and security training