Jobs · Information Technology · Washington

Senior Security Analyst, Customer Assurance

Plaid · Greater Seattle Area · 3 wk ago
HybridInformation Technology$134k–$214k/yrFull-time

Responsibilities

  • Lead Security Contract Reviews: Review security provisions in customer MSAs, DPAs, and security addenda—identifying unacceptable clauses, forming a clear security position, and providing Legal with actionable feedback.
  • Shape the Security Contract Review Strategy: Design and own the end-to-end program infrastructure—intake process, tiered SLAs, security positions runbooks, and handoff protocols with Legal and GTM.
  • Drive Strategic Intelligence: Track security contract asks across deals, identify recurring patterns, and determine whether they reflect a gap in Plaid's program or a non-standard customer request.
  • Accelerate Deals: Join customer and data partner calls as Plaid's security subject matter expert—comfortable navigating the formality and pace of traditional financial institutions, building trust through patience and clear, collaborative communication.
  • Own Program Health: Define KPIs, build dashboards, and deliver regular reporting on program health to Security and GTM leadership.
  • Scale Through AI and Tooling: Build and scale AI-assisted workflows for security assurance, pattern analysis, and reporting—sharing what works across the team.
  • Support Security Trust Activities: Respond to customer security questionnaires and support external audit calls with customers and data partners—serving as Plaid's security subject matter expert across all customer-facing assurance activities.

Qualifications

  • 6+ years of experience in security assurance, security GRC, security compliance, or a related information security role with meaningful ownership of customer- or partner-facing security workflows.
  • Experience reviewing security provisions in MSAs, DPAs, and security addenda—translating that expertise into clear positions Legal can take directly into negotiations.
  • Deep familiarity with common security clause types: e.g. incident notification windows, audit rights, encryption requirements, subprocessor obligations, data retention, and penetration testing provisions.
  • Ability to translate a company's security posture and risk appetite into clear, defensible contract positions and hold those positions through multiple negotiation cycles.
  • Experience representing a company's security program directly to customers and financial institution partners on calls—fielding questions about security controls, compliance posture, and contractual obligations.
  • Security Compliance and regulatory knowledge: Working knowledge of SOC 2, ISO 27001, NIST CSF, PCI DSS, GLBA, GDPR/CCPA, NIST 800-53, etc.
  • Deep understanding of what "standard" security contract language looks like in fintech and banking agreements.
  • Experience building security assurance programs—designing intake processes, tiered SLAs, escalation paths, and runbooks, not just executing within existing ones.
  • Strong analytical skills: ability to identify patterns across a high volume of security contract asks, track pushback rates and cycle counts, and translate findings into process improvements.
  • Experience with metrics ownership: defining KPIs, building tracking infrastructure, and reporting on program health to cross-functional stakeholders.
  • Communication and cross-functional effectiveness: Exceptional written and verbal communication skills—precise enough for Legal to use your positions to draft language, clear enough for a Sales rep to use in a customer call.
  • Experience working directly with Legal and GTM teams as a security subject matter expert.
  • Experience driving customer and data partner calls involving security.
  • Demonstrated ability to build and scale AI-assisted workflows—applies AI tooling to Security Assurance activities like contract review, questionnaire completion, clause library maintenance, pattern analysis, and reporting to materially increase throughput.
  • Shares what works with the broader team; approaches AI as a force multiplier for the function, not just a personal productivity tool.

Similar jobs