Jobs · Information Technology · North Carolina

Senior Security Analyst, Customer Assurance

Plaid · Raleigh-Durham-Chapel Hill Area · 3 wk ago
HybridInformation Technology$134k–$214k/yrFull-time

About the role

The Security Contracts workstream is a core part of Plaid’s Security Assurance program. This role involves leading security contract reviews, building the program infrastructure, and supporting broader Security Assurance activities.

Responsibilities

  • Lead security contract reviews across customer MSAs, DPAs, security addenda, and security exhibits by identifying unacceptable clauses, forming a clear security position, and providing Legal with actionable feedback they can take directly into negotiations.
  • Design and own the end-to-end Security Contracts program infrastructure, including intake processes, tiered SLAs, security positions runbooks, and handoff protocols with Legal and GTM.
  • Track security contract asks across deals, identify recurring patterns, and determine whether they represent gaps in Plaid’s program or non-standard customer requests.
  • Assess feasibility and propose recommendations to leadership when recurring asks point to program gaps, and codify existing capabilities into standard security addenda where appropriate to reduce future negotiation cycles.
  • Join customer and data partner calls as Plaid’s security subject matter expert, building trust through patient, clear, and collaborative communication.
  • Define KPIs, build dashboards, and deliver regular reporting on program health to Security and GTM leadership, including visibility into deal friction, SLA adherence, and improvement opportunities.
  • Build and scale AI-assisted workflows for security assurance, contract review, questionnaire completion, clause library maintenance, pattern analysis, and reporting.
  • Support customer security questionnaires and external audit calls with customers and data partners, ensuring Plaid presents a consistent and credible security posture across customer-facing assurance activities.

Qualifications

  • 6+ years of experience in security assurance, security GRC, security compliance, or a related information security role with meaningful ownership of customer- or partner-facing security workflows.
  • Experience reviewing security provisions in MSAs, DPAs, and security addenda — and translating that expertise into clear positions Legal can take directly into negotiations.
  • Deep familiarity with common security clause types: e.g. incident notification windows, audit rights, encryption requirements, subprocessor obligations, data retention, and penetration testing provisions.
  • Ability to translate a company's security posture and risk appetite into clear, defensible contract positions and hold those positions through multiple negotiation cycles.
  • Experience representing a company's security program directly to customers and financial institution partners on calls — fielding questions about security controls, compliance posture, and contractual obligations.
  • Security Compliance and regulatory knowledge: Working knowledge of SOC 2, ISO 27001, NIST CSF, PCI DSS, GLBA, GDPR/CCPA, NIST 800-53, etc. Deep understanding of what "standard" security contract language looks like in fintech and banking agreements.
  • Program design and operational maturity: Experience building security assurance programs — designing intake processes, tiered SLAs, escalation paths, and runbooks, not just executing within existing ones.
  • Strong analytical skills: ability to identify patterns across a high volume of security contract asks, track pushback rates and cycle counts, and translate findings into process improvements.
  • Experience with metrics ownership: defining KPIs, building tracking infrastructure, and reporting on program health to cross-functional stakeholders.
  • Communication and cross-functional effectiveness: Exceptional written and verbal communication skills — precise enough for Legal to use your positions to draft language, clear enough for a Sales rep to use in a customer call.
  • Experience working directly with Legal and GTM teams as a security subject matter expert.
  • Experience driving customer and data partner calls involving security.
  • Demonstrated ability to build and scale AI-assisted workflows — applies AI tooling to Security Assurance activities like contract review, questionnaire completion, clause library maintenance, pattern analysis, and reporting to materially increase throughput.
  • Shares what works with the broader team; approaches AI as a force multiplier for the function, not just a personal productivity tool.

Nice to have

  • Redlining security contract language directly, beyond providing advisory feedback.

Similar jobs