Security Engineer, GRC

Plaid - New York City Metropolitan Area

Hiring: Security Engineer, GRC Company: Plaid Location: New York City Metropolitan Area Job Posted Time: 2026-09-03 11:14:35 Target Skills & Keywords : AWS, CI/CD, FedRAMP, GitHub, IaC, Python, Risk Management, SOC 2, SQL, SaaS, Terraform About the job Required Skills: •Own GRC Engineering at Plaid — a foundational, high-ownership role defining an emerging discipline from the ground up. Today most of our compliance work is manual and point-in-time; you will turn it into an engineered system that is continuous, data-driven, and scalable, and set the technical direction for the field. •Define the discipline and the architecture — how GRC Engineering works at Plaid, not just execute within it. •Build the foundation the function runs on — a codified source of truth for controls, policies, and evidence, fed by live pipelines and continuous controls monitoring. •Be the engineering backbone for Security Assurance & Trust Enablement, Third-Party Ecosystem Risk, and Risk Management •Make risk visible and data-driven — turning control and risk data into real-time signals for the team and leadership. •Pioneer where compliance is heading — compliance-agents-as-code in the SDLC, AI- and agent-driven workflows, and machine-readable continuous compliance (FedRAMP 20x). •You think in systems: you'd rather design the thing that eliminates a whole class of manual work than automate one task at a time. •You love building and shipping internal tools and solutions that people actually use. Qualifications: •Strong Python and SQL, with a proven track record of building API/webhook integrations that connect disparate systems. •Applied hands-on capability in AWS and cloud-native security controls, including the ability to query cloud, GitHub, and SaaS logs. •Proficiency with dashboarding / data-visualization tools (e.g., Mode) to turn control and risk data into KPIs and signal. •Demonstrated ability to model controls, policies, and framework mappings as structured, version-controlled data rather than docs and spreadsheets. •Applied hands-on capability in IaC (Terraform) and policy-as-code (OPA/Rego, Sentinel), including embedding compliance checks into CI/CD. •Proven ability to eliminate recurring operational toil — evidence pulls, access and vendor reviews, questionnaires, risk-register upkeep, status reports — with durable automation rather than one-off scripts. •Solid functional working knowledge of SOC 2, ISO 27001/27701, and NIST CSF/800-53, with the ability to map controls to evidence and crosswalk a single control across frameworks. •Operational familiarity with the shift to continuous compliance (FedRAMP 20x, machine-readable Key Security Indicators) and how it changes evidence and control design. Compensation: •$156,000 - $213,600 / year Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!