Security Engineer, GRC
Plaid · San Francisco Bay Area · 1 wk ago
HybridInformation Technology$156k–$214k/yrFull-time
Responsibilities
- Architect GRC's Engineering Foundation: Build the pipelines and codified source of truth the function runs on — controls, policies, and framework mappings captured as structured, version-controlled data and fed by live control and system state — so one control maps evidence across SOC 2, ISO, NIST, and beyond instead of being re-collected for every audit.
- Build Continuous Controls Monitoring: Automate evidence collection, control testing, and monitoring across cloud and internal systems, and write and tune the detection that flags drift and misconfiguration against baseline — so audit readiness is continuous and gaps surface the moment they appear, not at audit time.
- Turn Data into Risk Signal: Build dashboards and SQL-driven reporting that turn raw control and risk data into KPIs, giving the team and leadership real-time visibility into risk posture.
- Drive Data-Informed Risk Assessments: Conduct security and technology risk assessments and recommend mitigations using data — keeping the risk management program running while cutting its manual overhead.
- Automate Operational Toil: Eliminate the recurring manual work the team carries — evidence pulls, access and vendor reviews, questionnaires, risk-register upkeep, status reporting — with durable automation that gives time back across every workstream.
- Shift Compliance Left with Code and AI: Embed compliance checks into the CI/CD flow as policy-as-code so controls are validated as code ships, prototype self-healing policies reconciled against live infrastructure, and scale agentic / AI-assisted workflows across the function.
- Future-proof for Continuous Compliance: Build toward machine-readable, continuously validated evidence (FedRAMP 20x-style Key Security Indicators), positioning Plaid to meet continuous-compliance expectations as we enter new markets and pursue new authorizations.
Qualifications
- Software & Data Engineering Foundations: Strong Python and SQL, with a proven track record of building API/webhook integrations that connect disparate systems.
- Experience owning an internal tool or service end to end — design, build, operate, and maintain — with real users depending on it.
- Hands-on experience with AWS and cloud-native security controls, including the ability to query cloud, GitHub, and SaaS logs.
- Proficiency with dashboarding / data-visualization tools (e.g., Mode) to turn control and risk data into KPIs and signal.
- Applied GRC Engineering: Experience building and operating continuous controls monitoring end to end — collecting signal from live systems, writing and tuning the detection logic that compares state to a baseline, alerting, and driving remediation.
- Demonstrated ability to model controls, policies, and framework mappings as structured, version-controlled data rather than docs and spreadsheets.
- Hands-on experience with IaC (Terraform) and policy-as-code (OPA/Rego, Sentinel), including embedding compliance checks into CI/CD.
- Prominent ability to eliminate recurring operational toil — evidence pulls, access and vendor reviews, questionnaires, risk-register upkeep, status reports — with durable automation rather than one-off scripts.
- Compliance & risk knowledge: Working knowledge of SOC 2, ISO 27001/27701, and NIST CSF/800-53, with the ability to map controls to evidence and crosswalk a single control across frameworks.
- Experience conducting security or technology risk assessments and translating findings into data-driven mitigation.
- Familiarity with the shift to continuous compliance (FedRAMP 20x, machine-readable Key Security Indicators) and how it changes evidence and control design.
- AI fluency & tooling: Demonstrated ability to build and scale agentic / AI-assisted workflows (Claude, OpenAI) as leverage for the whole team.
- Cross-functional effectiveness: Ability to work independently and cross-functionally across security, infrastructure, and engineering, with strong prioritization and the ability to influence without authority.