Security Engineer, GRC
Own GRC Engineering at Plaid by building a codified, continuous, data-driven compliance system. Architect pipelines for controls/evidence, implement continuous monitoring and policy-as-code in CI/CD, turn risk data into real-time signals, and scale AI/agentic workflows to eliminate manual toil.
About the job
Responsibilities
- Architect GRC's Engineering Foundation: Build pipelines and codified source of truth for controls, policies, and framework mappings as structured, version-controlled data fed by live pipelines.
- Build Continuous Controls Monitoring: Automate evidence collection, control testing, and monitoring across cloud and internal systems; write and tune detection logic for drift and misconfigurations.
- Turn Data into Risk Signal: Build dashboards and SQL-driven reporting to create KPIs and real-time visibility into risk posture.
- Drive Data-Informed Risk Assessments: Conduct security and technology risk assessments, recommend mitigations, and reduce manual overhead in risk management.
- Automate Operational Toil: Eliminate recurring manual work (evidence pulls, access/vendor reviews, questionnaires, risk-register upkeep, status reporting) with durable automation.
- Shift Compliance Left with Code and AI: Embed compliance checks into CI/CD as policy-as-code, prototype self-healing policies, and scale agentic/AI-assisted workflows.
- Future-proof for Continuous Compliance: Build toward machine-readable, continuously validated evidence (e.g. FedRAMP 20x-style Key Security Indicators).
Qualifications
- Strong Python and SQL; proven track record building API/webhook integrations.
- Experience owning an internal tool or service end-to-end (design, build, operate, maintain) with real users.
- Hands-on with AWS, cloud-native security controls, querying cloud/GitHub/SaaS logs.
- Proficiency with dashboarding/data-visualization tools (e.g. Mode).
- Experience building and operating continuous controls monitoring end-to-end (signal collection, detection logic, alerting, remediation).
- Ability to model controls, policies, and framework mappings as structured, version-controlled data.
- Hands-on with IaC (Terraform) and policy-as-code (OPA/Rego, Sentinel); embedding compliance into CI/CD.
- Proven ability to eliminate recurring operational toil with durable automation.
- Working knowledge of SOC 2, ISO 27001/27701, NIST CSF/800-53; mapping controls across frameworks.
- Experience conducting security/technology risk assessments and translating to data-driven mitigations.
- Familiarity with continuous compliance (FedRAMP 20x, machine-readable Key Security Indicators).
- Demonstrated ability to build and scale agentic/AI-assisted workflows (Claude, OpenAI).
- Ability to work independently and cross-functionally across security, infrastructure, and engineering; strong prioritization and influence without authority.
Nice-to-Haves
- Direct experience with FedRAMP or FedRAMP 20x, or other public-sector/continuous-compliance authorizations.
- Experience with audit/compliance automation platforms (Anecdotes, Drata, Vanta, Paramify, or similar).
- Exposure to security incident response and triage.
- Experience in a high-growth fintech or financial-services environment.
- Degree in Computer Science, Cybersecurity, or related field.
Skills
Python, SQL, AWS, Terraform, Opa, Rego, Sentinel, Mode, CI/CD, SOC 2, ISO 27001, Nist, FedRAMP
Similar jobs
Security Engineering jobsManages FedRAMP compliance for a cloud service provider by implementing security controls, supporting audits and remediation, maintaining SSP documentation, and coordinating authorization activities. Requires 5+ years of IT audit or compliance experience and hands-on FedRAMP ATO leadership.
The Application Security Engineer will embed security practices throughout the SaaS software development lifecycle, including threat modeling, automated testing, vulnerability remediation, and incident response. The role requires 5+ years of application or product security experience and expertise with DevSecOps workflows, web applications, and CI/CD automation.
The Cyber Threat Intel Analyst tracks, investigates, attributes, and reports on advanced threats targeting cloud, AI, and developer environments. The role requires at least three years of security or threat research experience and strong technical analysis and writing skills.
The GRC Analyst will operate and mature security and compliance programs across major privacy and security frameworks, supporting risk assessments, access reviews, third-party risk, control monitoring, and audits. The role requires 3–5 years of GRC or information security experience and strong cross-functional communication.
Build automated detection, investigation, and incident-response systems for a cloud-native platform. The role requires strong software engineering, security incident investigation, cloud infrastructure, Kubernetes, Linux, networking, and SQL experience, with opportunities to apply LLMs to security operations.