← Back to job listings
PL
Security Engineer (GRC)
Plaid · United States
About The Role
Join Plaid's Security Governance, Risk, and Compliance (GRC) team as a Security Engineer (GRC). In this foundational role, you will define and build the GRC Engineering discipline, turning compliance into code and audits into a continuous, automated capability. You will architect GRC's engineering foundation, build continuous controls monitoring, and drive data-informed risk assessments. This is a high-ownership position that offers the opportunity to make a significant impact on Plaid's security posture and compliance efforts.
- Own GRC Engineering at Plaid, defining the discipline and architecture, and building the foundation for compliance work.
- Build Continuous Controls Monitoring, automating evidence collection, control testing, and monitoring across systems.
- Drive Data-Informed Risk Assessments, conducting security and technology risk assessments and recommending mitigations using data.
- You treat every roadblock as just an obstacle to route around — you don't back down, because there's always a path
- You're relentlessly curious — you poke, you investigate, and you dig into how controls can silently fail, drift, or get bypassed so you can catch it automatically
- You like range — juggling several problems across security, risk, compliance, and engineering beats grinding on a single one
- You love building and shipping internal tools and solutions that people actually use
- You think in systems: you'd rather design the thing that eliminates a whole class of manual work than automate one task at a time
- You're energized by turning compliance from a documentation exercise into demonstrable, continuous, machine-readable evidence
- Proficiency with dashboarding / data-visualization tools (e.g., Mode) to turn control and risk data into KPIs and signal
- Experience owning an internal tool or service end to end — design, build, operate, and maintain — with real users depending on it
- Hands-on experience with AWS and cloud-native security controls, including the ability to query cloud, GitHub, and SaaS logs
- Strong Python and SQL, with a proven track record of building API/webhook integrations that connect disparate systems
- Hands-on experience with IaC (Terraform) and policy-as-code (OPA/Rego, Sentinel), including embedding compliance checks into CI/CD
- Proven ability to eliminate recurring operational toil — evidence pulls, access and vendor reviews, questionnaires, risk-register upkeep, status reports — with durable automation rather than one-off scripts
- Experience conducting security or technology risk assessments and translating findings into data-driven mitigation
- Experience with audit ›/ compliance automation platforms (Anecdotes, Drata, Vanta, Paramify, or similar)
- Ability to work independently and cross-functionally across security, infrastructure, and engineering, with strong prioritization and the ability to influence without authority
- Demonstrated ability to build and scale agentic / AI-assisted workflows (Claude, OpenAI) as leverage for the whole team
- Degree in Computer Science, Cybersecurity, or a related field
- Exposure to security incident response and triage
- Experience in a high-growth fintech or financial-services environment
- Experience building and operating continuous controls monitoring end to end — collecting signal from live systems, writing and tuning the detection logic that compares state to a baseline, alerting, and driving remediation
- Familiarity with the shift to continuous compliance (FedRAMP 20x, machine-readable Key Security Indicators) and how it changes evidence and control design
- Demonstrated ability to model controls, policies, and framework mappings as structured, version-controlled data rather than docs and spreadsheets
- Direct experience with FedRAMP or FedRAMP 20x, or other public-sector / continuous-compliance authorizations
- Working knowledge of SOC 2, ISO 27001/27701, and NIST CSF/800-53, with the ability to map controls to evidence and crosswalk a single control across frameworks
- We encourage you to apply to a role even if your experience doesn't fully match the job description
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring