Skip to content
PlaidPlaid

Security Engineer, GRC

Own GRC Engineering at Plaid by building a codified, continuous, data-driven compliance system. Architect pipelines for controls/evidence, implement continuous monitoring and policy-as-code in CI/CD, turn risk data into real-time signals, and scale AI/agentic workflows to eliminate manual toil.

About the job

Responsibilities

  • Architect GRC's Engineering Foundation: Build pipelines and codified source of truth for controls, policies, and framework mappings as structured, version-controlled data fed by live pipelines.
  • Build Continuous Controls Monitoring: Automate evidence collection, control testing, and monitoring across cloud and internal systems; write and tune detection logic for drift and misconfigurations.
  • Turn Data into Risk Signal: Build dashboards and SQL-driven reporting to create KPIs and real-time visibility into risk posture.
  • Drive Data-Informed Risk Assessments: Conduct security and technology risk assessments, recommend mitigations, and reduce manual overhead in risk management.
  • Automate Operational Toil: Eliminate recurring manual work (evidence pulls, access/vendor reviews, questionnaires, risk-register upkeep, status reporting) with durable automation.
  • Shift Compliance Left with Code and AI: Embed compliance checks into CI/CD as policy-as-code, prototype self-healing policies, and scale agentic/AI-assisted workflows.
  • Future-proof for Continuous Compliance: Build toward machine-readable, continuously validated evidence (e.g. FedRAMP 20x-style Key Security Indicators).

Qualifications

  • Strong Python and SQL; proven track record building API/webhook integrations.
  • Experience owning an internal tool or service end-to-end (design, build, operate, maintain) with real users.
  • Hands-on with AWS, cloud-native security controls, querying cloud/GitHub/SaaS logs.
  • Proficiency with dashboarding/data-visualization tools (e.g. Mode).
  • Experience building and operating continuous controls monitoring end-to-end (signal collection, detection logic, alerting, remediation).
  • Ability to model controls, policies, and framework mappings as structured, version-controlled data.
  • Hands-on with IaC (Terraform) and policy-as-code (OPA/Rego, Sentinel); embedding compliance into CI/CD.
  • Proven ability to eliminate recurring operational toil with durable automation.
  • Working knowledge of SOC 2, ISO 27001/27701, NIST CSF/800-53; mapping controls across frameworks.
  • Experience conducting security/technology risk assessments and translating to data-driven mitigations.
  • Familiarity with continuous compliance (FedRAMP 20x, machine-readable Key Security Indicators).
  • Demonstrated ability to build and scale agentic/AI-assisted workflows (Claude, OpenAI).
  • Ability to work independently and cross-functionally across security, infrastructure, and engineering; strong prioritization and influence without authority.

Nice-to-Haves

  • Direct experience with FedRAMP or FedRAMP 20x, or other public-sector/continuous-compliance authorizations.
  • Experience with audit/compliance automation platforms (Anecdotes, Drata, Vanta, Paramify, or similar).
  • Exposure to security incident response and triage.
  • Experience in a high-growth fintech or financial-services environment.
  • Degree in Computer Science, Cybersecurity, or related field.

Skills

Python, SQL, AWS, Terraform, Opa, Rego, Sentinel, Mode, CI/CD, SOC 2, ISO 27001, Nist, FedRAMP

Figma

Figma

United States

Federal Compliance Manager
$153k+/yrRemote5+ YOESecurity Engineering

Manages FedRAMP compliance for a cloud service provider by implementing security controls, supporting audits and remediation, maintaining SSP documentation, and coordinating authorization activities. Requires 5+ years of IT audit or compliance experience and hands-on FedRAMP ATO leadership.

Vannevar

Vannevar

United States

Application Security Engineer
$160k+/yrRemote5+ YOESecurity Engineering

The Application Security Engineer will embed security practices throughout the SaaS software development lifecycle, including threat modeling, automated testing, vulnerability remediation, and incident response. The role requires 5+ years of application or product security experience and expertise with DevSecOps workflows, web applications, and CI/CD automation.

Wiz

Wiz

Washington, DC

Cyber Threat Intel Analyst
$160k+/yrOn-site3+ YOESecurity Engineering

The Cyber Threat Intel Analyst tracks, investigates, attributes, and reports on advanced threats targeting cloud, AI, and developer environments. The role requires at least three years of security or threat research experience and strong technical analysis and writing skills.

Fireworks AI

Fireworks AI

San Mateo, CA

GRC Analyst
$160k+/yrOn-site3+ YOESecurity Engineering

The GRC Analyst will operate and mature security and compliance programs across major privacy and security frameworks, supporting risk assessments, access reviews, third-party risk, control monitoring, and audits. The role requires 3–5 years of GRC or information security experience and strong cross-functional communication.

Modal

Modal

New York, NY

Detection And Response Engineer
$150k+/yrOn-siteSecurity Engineering

Build automated detection, investigation, and incident-response systems for a cloud-native platform. The role requires strong software engineering, security incident investigation, cloud infrastructure, Kubernetes, Linux, networking, and SQL experience, with opportunities to apply LLMs to security operations.