Plaid

Security Engineer, GRC

Plaid
Apply
2 months ago
Seattle, WA, USA +2 moreStaff+
H1B sponsor

Base Salary

$156k - $214k/yr

Responsibilities

  • Architect and build the GRC Engineering foundation with structured, version-controlled controls, policies, framework mappings, and evidence pipelines.
  • Automate continuous controls monitoring, evidence collection, control testing, drift detection, misconfiguration detection, alerting, and remediation workflows.
  • Build dashboards and SQL-driven reporting that convert control and risk data into KPIs and real-time risk signals.
  • Conduct security and technology risk assessments and recommend data-driven mitigations.
  • Automate evidence pulls, access and vendor reviews, questionnaires, risk-register maintenance, and status reporting.
  • Embed compliance checks into CI/CD using policy-as-code, prototype self-healing policies, and scale agentic or AI-assisted workflows.
  • Develop machine-readable, continuously validated evidence and support FedRAMP 20x-style continuous compliance.

Requirements

  • Strong Python and SQL skills with experience building API and webhook integrations across disparate systems.
  • Experience owning an internal tool or service end to end, including design, development, operation, and maintenance.
  • Hands-on experience with AWS, cloud-native security controls, and querying cloud, GitHub, and SaaS logs.
  • Proficiency with dashboarding or data-visualization tools such as Mode.
  • Experience building and operating continuous controls monitoring, including signal collection, detection logic, alerting, and remediation.
  • Experience modeling controls, policies, and framework mappings as structured, version-controlled data.
  • Hands-on experience with Terraform, OPA/Rego, and Sentinel, including embedding compliance checks into CI/CD.
  • Experience automating recurring GRC operations such as evidence collection, access and vendor reviews, questionnaires, risk-register upkeep, and status reporting.
  • Working knowledge of SOC 2, ISO 27001/27701, and NIST CSF/800-53.
  • Experience conducting security or technology risk assessments and translating findings into data-driven mitigation.
  • Familiarity with FedRAMP 20x, machine-readable Key Security Indicators, and continuous compliance.
  • Ability to build and scale agentic or AI-assisted workflows using Claude and OpenAI.
  • Ability to work independently and cross-functionally across security, infrastructure, and engineering.
  • Preferred qualifications include FedRAMP or FedRAMP 20x experience, experience with compliance automation platforms, exposure to security incident response and triage, and experience in fintech or financial services.
  • A degree in Computer Science, Cybersecurity, or a related field is nice to have.

Benefits

  • Plaid provides medical, dental, vision, and 401(k) benefits.
  • Additional compensation may include equity and/or commission, depending on the position offered.
  • Pay and benefits vary based on factors including scope, responsibilities, experience, skill set, and location, and may change over time.

Categories

Plaid

About Plaid

501-1,000 employees

Plaid is a data network that powers the tools millions of people rely on to live a healthier financial life. Plaid works with thousands of companies like Venmo, SoFi, and Betterment, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers more than 12,000 financial institutions across the US, Canada, UK and Europe. Headquartered in San Francisco, the company was founded in 2013 by Zach Perret and William Hockey.

Contact me