Plaid logo
PlaidPosted 1 month ago

Security Engineer, GRC

$156,000–$213,600 year

RemoteUnited States

Full TimeLarge

Job Summary

Architect GRC Engineering at Plaid by defining the discipline and building a codified source of truth for controls, policies, and evidence fed by live pipelines. Automate evidence collection, control testing, and monitoring across cloud systems to ensure audit readiness is continuous, while turning raw risk data into real-time KPIs for leadership. Shift compliance left by embedding policy-as-code checks into CI/CD flows and scaling AI-assisted workflows to eliminate recurring manual toil. Drive data-informed risk assessments and future-proof the function for machine-readable continuous compliance standards like FedRAMP 20x.

Required Qualifications

  • Strong Python and SQL
  • Proven track record of building API/webhook integrations that connect disparate systems
  • Experience owning an internal tool or service end to end — design, build, operate, and maintain — with real users depending on it
  • Hands-on experience with AWS and cloud-native security controls, including the ability to query cloud, GitHub, and SaaS logs
  • Proficiency with dashboarding / data-visualization tools (e.g., Mode) to turn control and risk data into KPIs and signal
  • Experience building and operating continuous controls monitoring end to end — collecting signal from live systems, writing and tuning the detection logic that compares state to a baseline, alerting, and driving remediation
  • Demonstrated ability to model controls, policies, and framework mappings as structured, version-controlled data rather than docs and spreadsheets
  • Hands-on experience with IaC (Terraform) and policy-as-code (OPA/Rego, Sentinel), including embedding compliance checks into CI/CD
  • Proven ability to eliminate recurring operational toil — evidence pulls, access and vendor reviews, questionnaires, risk-register upkeep, status reports — with durable automation rather than one-off scripts
  • Working knowledge of SOC 2, ISO 27001/27701, and NIST CSF/800-53, with the ability to map controls to evidence and crosswalk a single control across frameworks
  • Experience conducting security or technology risk assessments and translating findings into data-driven mitigation
  • Familiarity with the shift to continuous compliance (FedRAMP 20x, machine-readable Key Security Indicators) and how it changes evidence and control design
  • Demonstrated ability to build and scale agentic / AI-assisted workflows (Claude, OpenAI) as leverage for the whole team
  • Ability to work independently and cross-functionally across security, infrastructure, and engineering, with strong prioritization and the ability to influence without authority

Desired Qualifications

  • Direct experience with FedRAMP or FedRAMP 20x, or other public-sector / continuous-compliance authorizations
  • Experience with audit ›/ compliance automation platforms (Anecdotes, Drata, Vanta, Paramify, or similar)
  • Exposure to security incident response and triage
  • Experience in a high-growth fintech or financial-services environment
  • Degree in Computer Science, Cybersecurity, or a related field

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce