Jobs · Information Technology · California

Security Engineer, GRC

Plaid · San Francisco Bay Area · 1 wk ago
HybridInformation Technology$156k–$214k/yrFull-time

Responsibilities

  • Architect GRC's Engineering Foundation: Build the pipelines and codified source of truth the function runs on — controls, policies, and framework mappings captured as structured, version-controlled data and fed by live control and system state — so one control maps evidence across SOC 2, ISO, NIST, and beyond instead of being re-collected for every audit.
  • Build Continuous Controls Monitoring: Automate evidence collection, control testing, and monitoring across cloud and internal systems, and write and tune the detection that flags drift and misconfiguration against baseline — so audit readiness is continuous and gaps surface the moment they appear, not at audit time.
  • Turn Data into Risk Signal: Build dashboards and SQL-driven reporting that turn raw control and risk data into KPIs, giving the team and leadership real-time visibility into risk posture.
  • Drive Data-Informed Risk Assessments: Conduct security and technology risk assessments and recommend mitigations using data — keeping the risk management program running while cutting its manual overhead.
  • Automate Operational Toil: Eliminate the recurring manual work the team carries — evidence pulls, access and vendor reviews, questionnaires, risk-register upkeep, status reporting — with durable automation that gives time back across every workstream.
  • Shift Compliance Left with Code and AI: Embed compliance checks into the CI/CD flow as policy-as-code so controls are validated as code ships, prototype self-healing policies reconciled against live infrastructure, and scale agentic / AI-assisted workflows across the function.
  • Future-proof for Continuous Compliance: Build toward machine-readable, continuously validated evidence (FedRAMP 20x-style Key Security Indicators), positioning Plaid to meet continuous-compliance expectations as we enter new markets and pursue new authorizations.

Qualifications

  • Software & Data Engineering Foundations: Strong Python and SQL, with a proven track record of building API/webhook integrations that connect disparate systems.
  • Experience owning an internal tool or service end to end — design, build, operate, and maintain — with real users depending on it.
  • Hands-on experience with AWS and cloud-native security controls, including the ability to query cloud, GitHub, and SaaS logs.
  • Proficiency with dashboarding / data-visualization tools (e.g., Mode) to turn control and risk data into KPIs and signal.
  • Applied GRC Engineering: Experience building and operating continuous controls monitoring end to end — collecting signal from live systems, writing and tuning the detection logic that compares state to a baseline, alerting, and driving remediation.
  • Demonstrated ability to model controls, policies, and framework mappings as structured, version-controlled data rather than docs and spreadsheets.
  • Hands-on experience with IaC (Terraform) and policy-as-code (OPA/Rego, Sentinel), including embedding compliance checks into CI/CD.
  • Prominent ability to eliminate recurring operational toil — evidence pulls, access and vendor reviews, questionnaires, risk-register upkeep, status reports — with durable automation rather than one-off scripts.
  • Compliance & risk knowledge: Working knowledge of SOC 2, ISO 27001/27701, and NIST CSF/800-53, with the ability to map controls to evidence and crosswalk a single control across frameworks.
  • Experience conducting security or technology risk assessments and translating findings into data-driven mitigation.
  • Familiarity with the shift to continuous compliance (FedRAMP 20x, machine-readable Key Security Indicators) and how it changes evidence and control design.
  • AI fluency & tooling: Demonstrated ability to build and scale agentic / AI-assisted workflows (Claude, OpenAI) as leverage for the whole team.
  • Cross-functional effectiveness: Ability to work independently and cross-functionally across security, infrastructure, and engineering, with strong prioritization and the ability to influence without authority.

Similar jobs

Security Analyst (GRC)

MachinifyUnited States· 1 mo ago
RemoteInformation Technology$70k–$95k/yrapply on job-boards.greenhouse.io