Senior Security Analyst, Customer Assurance
Plaid · Greater Seattle Area · 3 wk ago
HybridInformation Technology$134k–$214k/yrFull-time
Responsibilities
- Lead Security Contract Reviews: Review security provisions in customer MSAs, DPAs, and security addenda—identifying unacceptable clauses, forming a clear security position, and providing Legal with actionable feedback.
- Shape the Security Contract Review Strategy: Design and own the end-to-end program infrastructure—intake process, tiered SLAs, security positions runbooks, and handoff protocols with Legal and GTM.
- Drive Strategic Intelligence: Track security contract asks across deals, identify recurring patterns, and determine whether they reflect a gap in Plaid's program or a non-standard customer request.
- Accelerate Deals: Join customer and data partner calls as Plaid's security subject matter expert—comfortable navigating the formality and pace of traditional financial institutions, building trust through patience and clear, collaborative communication.
- Own Program Health: Define KPIs, build dashboards, and deliver regular reporting on program health to Security and GTM leadership.
- Scale Through AI and Tooling: Build and scale AI-assisted workflows for security assurance, pattern analysis, and reporting—sharing what works across the team.
- Support Security Trust Activities: Respond to customer security questionnaires and support external audit calls with customers and data partners—serving as Plaid's security subject matter expert across all customer-facing assurance activities.
Qualifications
- 6+ years of experience in security assurance, security GRC, security compliance, or a related information security role with meaningful ownership of customer- or partner-facing security workflows.
- Experience reviewing security provisions in MSAs, DPAs, and security addenda—translating that expertise into clear positions Legal can take directly into negotiations.
- Deep familiarity with common security clause types: e.g. incident notification windows, audit rights, encryption requirements, subprocessor obligations, data retention, and penetration testing provisions.
- Ability to translate a company's security posture and risk appetite into clear, defensible contract positions and hold those positions through multiple negotiation cycles.
- Experience representing a company's security program directly to customers and financial institution partners on calls—fielding questions about security controls, compliance posture, and contractual obligations.
- Security Compliance and regulatory knowledge: Working knowledge of SOC 2, ISO 27001, NIST CSF, PCI DSS, GLBA, GDPR/CCPA, NIST 800-53, etc.
- Deep understanding of what "standard" security contract language looks like in fintech and banking agreements.
- Experience building security assurance programs—designing intake processes, tiered SLAs, escalation paths, and runbooks, not just executing within existing ones.
- Strong analytical skills: ability to identify patterns across a high volume of security contract asks, track pushback rates and cycle counts, and translate findings into process improvements.
- Experience with metrics ownership: defining KPIs, building tracking infrastructure, and reporting on program health to cross-functional stakeholders.
- Communication and cross-functional effectiveness: Exceptional written and verbal communication skills—precise enough for Legal to use your positions to draft language, clear enough for a Sales rep to use in a customer call.
- Experience working directly with Legal and GTM teams as a security subject matter expert.
- Experience driving customer and data partner calls involving security.
- Demonstrated ability to build and scale AI-assisted workflows—applies AI tooling to Security Assurance activities like contract review, questionnaire completion, clause library maintenance, pattern analysis, and reporting to materially increase throughput.
- Shares what works with the broader team; approaches AI as a force multiplier for the function, not just a personal productivity tool.