Skip to content
PlaidPlaidNew York, NY

Security Analyst, Third-Party Ecosystem Risk Management

Conducts end-to-end security risk assessments for vendors, customers, and partners while maintaining risk tiering, remediation, reassessments, and reporting. The role also matures third-party risk processes and uses AI-assisted workflows to scale assessment operations.

$119k – $176k/yr
Hybrid4+ YOESecurity Engineering

About the job

Responsibilities

  • Run end-to-end vendor security risk assessments, including intake, questionnaire review, risk rating, findings, exceptions, and documentation.
  • Assess the security posture of customers and partners onboarding to the platform.
  • Maintain third-party risk tiering, reassessment cadence, remediation tracking, and the risk register.
  • Improve questionnaires, tiering criteria, intake processes, runbooks, workflows, automation, and tooling.
  • Track assessment cycle times, backlog, open exceptions, and reassessment coverage; report ecosystem risk to Security and cross-functional stakeholders.
  • Build and scale AI-assisted workflows for assessment review, questionnaire analysis, and reporting.

Requirements

  • 4+ years of experience in vendor risk management.
  • Experience conducting third-party security risk assessments, including reviewing questionnaires, SOC 2 and ISO reports, and security documentation.
  • Familiarity with the third-party risk lifecycle: intake, tiering, exceptions, risk acceptance, remediation tracking, and periodic reassessment.
  • Working knowledge of SOC 2, ISO 27001, NIST CSF, and common control domains such as access control, encryption, incident response, and business continuity/disaster recovery.
  • Ability to evaluate control environments, identify genuine gaps, and assess compensating controls.
  • Experience maturing third-party or vendor risk programs through improved tiering criteria, questionnaires, workflows, and automation.
  • Track record of running assessments at volume while maintaining rigor.
  • Strong analytical, documentation, written communication, and verbal communication skills.
  • Ability to explain security risks clearly to Procurement, Legal, customers, and other stakeholders.
  • Comfortable working across Security, Legal, Procurement, and go-to-market teams.
  • Demonstrated ability to apply AI tooling to assessment review, questionnaire analysis, and reporting to increase throughput.

Nice-to-haves

  • Third-party risk or audit credential such as CTPRP, CISA, or CISSP.
  • Hands-on ownership of a TPRM platform such as OneTrust, ProcessUnity, Whistic, or SecurityScorecard.

Compensation and Benefits

  • Annual base salary range: $118,680–$175,800.
  • Additional compensation may include equity and/or commission, depending on the position offered.
  • Comprehensive benefits include medical, dental, vision, and 401(k).

Skills

Vendor Risk ManagementThird-Party Risk ManagementSOC 2ISO 27001Nist CsfAccess ControlEncryptionIncident ResponseBusiness ContinuityRisk AssessmentOnetrustProcessunityWhisticSecurityscorecardAI Tools