Skip to content
PlaidPlaidSan Francisco, CA

Security Engineer, GRC

Own GRC Engineering at Plaid by building a codified, continuous, data-driven compliance system. Architect pipelines for controls/evidence, implement continuous monitoring and policy-as-code in CI/CD, turn risk data into real-time signals, and scale AI/agentic workflows to eliminate manual toil.

156k – 214k/yr
Hybrid5+ YOESecurity Engineering

About the role

Responsibilities

  • Architect GRC's Engineering Foundation: Build pipelines and codified source of truth for controls, policies, and framework mappings as structured, version-controlled data fed by live pipelines.
  • Build Continuous Controls Monitoring: Automate evidence collection, control testing, and monitoring across cloud and internal systems; write and tune detection logic for drift and misconfigurations.
  • Turn Data into Risk Signal: Build dashboards and SQL-driven reporting to create KPIs and real-time visibility into risk posture.
  • Drive Data-Informed Risk Assessments: Conduct security and technology risk assessments, recommend mitigations, and reduce manual overhead in risk management.
  • Automate Operational Toil: Eliminate recurring manual work (evidence pulls, access/vendor reviews, questionnaires, risk-register upkeep, status reporting) with durable automation.
  • Shift Compliance Left with Code and AI: Embed compliance checks into CI/CD as policy-as-code, prototype self-healing policies, and scale agentic/AI-assisted workflows.
  • Future-proof for Continuous Compliance: Build toward machine-readable, continuously validated evidence (e.g. FedRAMP 20x-style Key Security Indicators).

Qualifications

  • Strong Python and SQL; proven track record building API/webhook integrations.
  • Experience owning an internal tool or service end-to-end (design, build, operate, maintain) with real users.
  • Hands-on with AWS, cloud-native security controls, querying cloud/GitHub/SaaS logs.
  • Proficiency with dashboarding/data-visualization tools (e.g. Mode).
  • Experience building and operating continuous controls monitoring end-to-end (signal collection, detection logic, alerting, remediation).
  • Ability to model controls, policies, and framework mappings as structured, version-controlled data.
  • Hands-on with IaC (Terraform) and policy-as-code (OPA/Rego, Sentinel); embedding compliance into CI/CD.
  • Proven ability to eliminate recurring operational toil with durable automation.
  • Working knowledge of SOC 2, ISO 27001/27701, NIST CSF/800-53; mapping controls across frameworks.
  • Experience conducting security/technology risk assessments and translating to data-driven mitigations.
  • Familiarity with continuous compliance (FedRAMP 20x, machine-readable Key Security Indicators).
  • Demonstrated ability to build and scale agentic/AI-assisted workflows (Claude, OpenAI).
  • Ability to work independently and cross-functionally across security, infrastructure, and engineering; strong prioritization and influence without authority.

Nice-to-Haves

  • Direct experience with FedRAMP or FedRAMP 20x, or other public-sector/continuous-compliance authorizations.
  • Experience with audit/compliance automation platforms (Anecdotes, Drata, Vanta, Paramify, or similar).
  • Exposure to security incident response and triage.
  • Experience in a high-growth fintech or financial-services environment.
  • Degree in Computer Science, Cybersecurity, or related field.

Skills

PythonSQLAWSTerraformoparegosentinelmodeCI/CDSOC 2ISO 27001nistFedRAMP
Stripe

Backend Engineer, AI Security

StripeNew York, NY +2

Builds security frameworks and defenses against AI threats like prompt injection and jailbreaks, integrated with core AI infrastructure. Collaborates across teams; requires 5+ years software experience, ideally in security and AI systems.

157k – 286k/yr
Hybrid5+ YOESecurity Engineering
Sentry

Security Engineer, IAM

SentrySan Francisco, CA

As a Security Engineer, IAM, you will own and mature identity and access management infrastructure and tooling, continuously improving access control practices with automation and self-service support. You will champion and implement secure-by-design access principles and secure human and non-human identities.

155k – 240k/yr
Hybrid3+ YOESecurity Engineering
Runpod

Cloud Infrastructure Security Engineer

RunpodUnited States

Systems-focused Cloud Infrastructure Security Engineer responsible for securing Runpod's multitenant GPU bare-metal and virtualized environments. Requires 5+ years in infrastructure security, deep Linux kernel and virtualization expertise (KVM/QEMU), and low-level programming (C/Go/Rust) to prevent breakouts and harden against threats.

152k – 175k/yr
Remote5+ YOESecurity Engineering
Runpod

Full Stack Security Engineer

RunpodUnited States

Full Stack Security Engineer embedding with engineering teams to secure Runpod's AI cloud platform. Lead threat modeling, fix vulnerabilities by writing code in Python/Go/TS, implement DevSecOps pipelines, and champion security across web apps, APIs, and microservices.

152k – 175k/yr
Remote5+ YOESecurity Engineering
Skydio

Security Engineer

SkydioSan Mateo, CA

Build automation and internal tooling to enforce security controls, integrate identity/cloud systems, automate compliance evidence collection, and enable self-remediation across Skydio's multi-tenant cloud and corporate environments. Requires 3+ years software/security engineering experience and strong coding skills in Python or Go.

160k – 210k/yr
Hybrid3+ YOESecurity Engineering