Skip to content
← Back to job listings

Security Engineer (GRC)

Plaid · United States

External listingfull-time11 days ago

About The Role

Join Plaid's Security Governance, Risk, and Compliance (GRC) team as a Security Engineer (GRC). In this foundational role, you will define and build the GRC Engineering discipline, turning compliance into code and audits into a continuous, automated capability. You will architect GRC's engineering foundation, build continuous controls monitoring, and drive data-informed risk assessments. This is a high-ownership position that offers the opportunity to make a significant impact on Plaid's security posture and compliance efforts.

  • Own GRC Engineering at Plaid, defining the discipline and architecture, and building the foundation for compliance work.
  • Build Continuous Controls Monitoring, automating evidence collection, control testing, and monitoring across systems.
  • Drive Data-Informed Risk Assessments, conducting security and technology risk assessments and recommending mitigations using data.
  • You treat every roadblock as just an obstacle to route around — you don't back down, because there's always a path
  • You're relentlessly curious — you poke, you investigate, and you dig into how controls can silently fail, drift, or get bypassed so you can catch it automatically
  • You like range — juggling several problems across security, risk, compliance, and engineering beats grinding on a single one
  • You love building and shipping internal tools and solutions that people actually use
  • You think in systems: you'd rather design the thing that eliminates a whole class of manual work than automate one task at a time
  • You're energized by turning compliance from a documentation exercise into demonstrable, continuous, machine-readable evidence
  • Proficiency with dashboarding / data-visualization tools (e.g., Mode) to turn control and risk data into KPIs and signal
  • Experience owning an internal tool or service end to end — design, build, operate, and maintain — with real users depending on it
  • Hands-on experience with AWS and cloud-native security controls, including the ability to query cloud, GitHub, and SaaS logs
  • Strong Python and SQL, with a proven track record of building API/webhook integrations that connect disparate systems
  • Hands-on experience with IaC (Terraform) and policy-as-code (OPA/Rego, Sentinel), including embedding compliance checks into CI/CD
  • Proven ability to eliminate recurring operational toil — evidence pulls, access and vendor reviews, questionnaires, risk-register upkeep, status reports — with durable automation rather than one-off scripts
  • Experience conducting security or technology risk assessments and translating findings into data-driven mitigation
  • Experience with audit ›/ compliance automation platforms (Anecdotes, Drata, Vanta, Paramify, or similar)
  • Ability to work independently and cross-functionally across security, infrastructure, and engineering, with strong prioritization and the ability to influence without authority
  • Demonstrated ability to build and scale agentic / AI-assisted workflows (Claude, OpenAI) as leverage for the whole team
  • Degree in Computer Science, Cybersecurity, or a related field
  • Exposure to security incident response and triage
  • Experience in a high-growth fintech or financial-services environment
  • Experience building and operating continuous controls monitoring end to end — collecting signal from live systems, writing and tuning the detection logic that compares state to a baseline, alerting, and driving remediation
  • Familiarity with the shift to continuous compliance (FedRAMP 20x, machine-readable Key Security Indicators) and how it changes evidence and control design
  • Demonstrated ability to model controls, policies, and framework mappings as structured, version-controlled data rather than docs and spreadsheets
  • Direct experience with FedRAMP or FedRAMP 20x, or other public-sector / continuous-compliance authorizations
  • Working knowledge of SOC 2, ISO 27001/27701, and NIST CSF/800-53, with the ability to map controls to evidence and crosswalk a single control across frameworks
  • We encourage you to apply to a role even if your experience doesn't fully match the job description

This is an external listing. JobSpring does not represent or verify the employer. Report this listing