Skip to content
PlaidPlaidNew York, NY

Security Analyst, Third-Party Ecosystem Risk Management

Conducts end-to-end security risk assessments for vendors, customers, and partners while maintaining risk tiering, remediation, reassessments, and reporting. The role also matures third-party risk processes and uses AI-assisted workflows to scale assessment operations.

119k – 176k/yr
Hybrid4+ YOESecurity Engineering

About the role

Responsibilities

  • Run end-to-end vendor security risk assessments, including intake, questionnaire review, risk rating, findings, exceptions, and documentation.
  • Assess the security posture of customers and partners onboarding to the platform.
  • Maintain third-party risk tiering, reassessment cadence, remediation tracking, and the risk register.
  • Improve questionnaires, tiering criteria, intake processes, runbooks, workflows, automation, and tooling.
  • Track assessment cycle times, backlog, open exceptions, and reassessment coverage; report ecosystem risk to Security and cross-functional stakeholders.
  • Build and scale AI-assisted workflows for assessment review, questionnaire analysis, and reporting.

Requirements

  • 4+ years of experience in vendor risk management.
  • Experience conducting third-party security risk assessments, including reviewing questionnaires, SOC 2 and ISO reports, and security documentation.
  • Familiarity with the third-party risk lifecycle: intake, tiering, exceptions, risk acceptance, remediation tracking, and periodic reassessment.
  • Working knowledge of SOC 2, ISO 27001, NIST CSF, and common control domains such as access control, encryption, incident response, and business continuity/disaster recovery.
  • Ability to evaluate control environments, identify genuine gaps, and assess compensating controls.
  • Experience maturing third-party or vendor risk programs through improved tiering criteria, questionnaires, workflows, and automation.
  • Track record of running assessments at volume while maintaining rigor.
  • Strong analytical, documentation, written communication, and verbal communication skills.
  • Ability to explain security risks clearly to Procurement, Legal, customers, and other stakeholders.
  • Comfortable working across Security, Legal, Procurement, and go-to-market teams.
  • Demonstrated ability to apply AI tooling to assessment review, questionnaire analysis, and reporting to increase throughput.

Nice-to-haves

  • Third-party risk or audit credential such as CTPRP, CISA, or CISSP.
  • Hands-on ownership of a TPRM platform such as OneTrust, ProcessUnity, Whistic, or SecurityScorecard.

Compensation and Benefits

  • Annual base salary range: $118,680–$175,800.
  • Additional compensation may include equity and/or commission, depending on the position offered.
  • Comprehensive benefits include medical, dental, vision, and 401(k).

Skills

vendor risk managementthird-party risk managementSOC 2ISO 27001nist csfAccess ControlencryptionIncident Responsebusiness continuityRisk AssessmentonetrustprocessunitywhisticsecurityscorecardAI Tools
Writer

Security engineer, application security

WriterNew York, NY +1

Builds security into AI platform through threat modeling, SAST/DAST in CI/CD, code reviews, and secure architecture design. Requires 4+ years app sec experience, programming in Python/Java/Go/JS, and DevSecOps tools expertise.

119k – 210k/yrHybrid4+ YOESecurity Engineering
Applied Intuition

System Safety Engineer, Autonomy Trucking

Applied IntuitionSunnyvale, CA

Defines and manages safety architecture, requirements, and analysis (FMEA, FTA, STPA) for L4 autonomous trucking software/hardware. Requires 3+ years system safety experience, automotive standards expertise (ISO 26262), and engineering background in ADAS/autonomy.

118k – 250k/yrOn-site3+ YOESecurity Engineering
Northwood Space

Identity & Endpoint Security Engineer

Northwood SpaceLos Angeles, CA

Design and own Northwood's identity and endpoint security architecture with deep focus on Okta administration, SSO, RBAC, MDM, and privileged access controls. Ensure compliance with CMMC Level 2, NIST, ITAR and other government standards in a hybrid environment.

120k – 190k/yrOn-site3+ YOESecurity Engineering
Mintlify

Security & Compliance Operations Manager

MintlifySan Francisco, CA

Own and run Mintlify's end-to-end security and compliance programs (SOC 2, ISO 27001/42001, GDPR, Microsoft SSPA) as the first dedicated GRC Program Manager. Administer Drata, manage audits/vendors/evidence, handle customer-facing compliance, and coordinate with engineering.

120k – 180k/yrOn-site3+ YOESecurity Engineering
Northwood Space

Product Security Manager

Northwood SpaceLos Angeles, CA

Own the full product security lifecycle for space communications systems, from threat modeling and secure architecture to penetration testing, vulnerability management, cryptography, and compliance with FedRAMP, CMMC, and NIST standards. Requires 5+ years of product/application security leadership, deep expertise in SAST/DAST, secrets management, CI/CD hardening, and applied cryptography; TS/SCI clearance eligibility required.

120k – 190k/yrOn-site5+ YOESecurity Engineering