Senior Security Analyst, Customer Assurance
Plaid · Raleigh-Durham-Chapel Hill Area · 3 wk ago
HybridInformation Technology$134k–$214k/yrFull-time
About the role
The Security Contracts workstream is a core part of Plaid’s Security Assurance program. This role involves leading security contract reviews, building the program infrastructure, and supporting broader Security Assurance activities.
Responsibilities
- Lead security contract reviews across customer MSAs, DPAs, security addenda, and security exhibits by identifying unacceptable clauses, forming a clear security position, and providing Legal with actionable feedback they can take directly into negotiations.
- Design and own the end-to-end Security Contracts program infrastructure, including intake processes, tiered SLAs, security positions runbooks, and handoff protocols with Legal and GTM.
- Track security contract asks across deals, identify recurring patterns, and determine whether they represent gaps in Plaid’s program or non-standard customer requests.
- Assess feasibility and propose recommendations to leadership when recurring asks point to program gaps, and codify existing capabilities into standard security addenda where appropriate to reduce future negotiation cycles.
- Join customer and data partner calls as Plaid’s security subject matter expert, building trust through patient, clear, and collaborative communication.
- Define KPIs, build dashboards, and deliver regular reporting on program health to Security and GTM leadership, including visibility into deal friction, SLA adherence, and improvement opportunities.
- Build and scale AI-assisted workflows for security assurance, contract review, questionnaire completion, clause library maintenance, pattern analysis, and reporting.
- Support customer security questionnaires and external audit calls with customers and data partners, ensuring Plaid presents a consistent and credible security posture across customer-facing assurance activities.
Qualifications
- 6+ years of experience in security assurance, security GRC, security compliance, or a related information security role with meaningful ownership of customer- or partner-facing security workflows.
- Experience reviewing security provisions in MSAs, DPAs, and security addenda — and translating that expertise into clear positions Legal can take directly into negotiations.
- Deep familiarity with common security clause types: e.g. incident notification windows, audit rights, encryption requirements, subprocessor obligations, data retention, and penetration testing provisions.
- Ability to translate a company's security posture and risk appetite into clear, defensible contract positions and hold those positions through multiple negotiation cycles.
- Experience representing a company's security program directly to customers and financial institution partners on calls — fielding questions about security controls, compliance posture, and contractual obligations.
- Security Compliance and regulatory knowledge: Working knowledge of SOC 2, ISO 27001, NIST CSF, PCI DSS, GLBA, GDPR/CCPA, NIST 800-53, etc. Deep understanding of what "standard" security contract language looks like in fintech and banking agreements.
- Program design and operational maturity: Experience building security assurance programs — designing intake processes, tiered SLAs, escalation paths, and runbooks, not just executing within existing ones.
- Strong analytical skills: ability to identify patterns across a high volume of security contract asks, track pushback rates and cycle counts, and translate findings into process improvements.
- Experience with metrics ownership: defining KPIs, building tracking infrastructure, and reporting on program health to cross-functional stakeholders.
- Communication and cross-functional effectiveness: Exceptional written and verbal communication skills — precise enough for Legal to use your positions to draft language, clear enough for a Sales rep to use in a customer call.
- Experience working directly with Legal and GTM teams as a security subject matter expert.
- Experience driving customer and data partner calls involving security.
- Demonstrated ability to build and scale AI-assisted workflows — applies AI tooling to Security Assurance activities like contract review, questionnaire completion, clause library maintenance, pattern analysis, and reporting to materially increase throughput.
- Shares what works with the broader team; approaches AI as a force multiplier for the function, not just a personal productivity tool.
Nice to have
- Redlining security contract language directly, beyond providing advisory feedback.