Software & Data Engineering Foundations
Strong Python and SQL, with a proven track record of building API/webhook integrations that connect disparate systems
Experience owning an internal tool or service end to end — design, build, operate, and maintain — with real users depending on it
Hands-on experience with AWS and cloud-native security controls, including the ability to query cloud, GitHub, and SaaS logs
Proficiency with dashboarding / data-visualization tools (e.g., Mode) to turn control and risk data into KPIs and signal
Applied GRC Engineering
Experience building and operating continuous controls monitoring end to end — collecting signal from live systems, writing and tuning the detection logic that compares state to a baseline, alerting, and driving remediation
Demonstrated ability to model controls, policies, and framework mappings as structured, version-controlled data rather than docs and spreadsheets
Hands-on experience with IaC (Terraform) and policy-as-code (OPA/Rego, Sentinel), including embedding compliance checks into CI/CD
Proven ability to eliminate recurring operational toil — evidence pulls, access and vendor reviews, questionnaires, risk-register upkeep, status reports — with durable automation rather than one-off scripts
Compliance & risk knowledge
Working knowledge of SOC 2, ISO 27001/27701, and NIST CSF/800-53, with the ability to map controls to evidence and crosswalk a single control across frameworks
Experience conducting security or technology risk assessments and translating findings into data-driven mitigation
Familiarity with the shift to continuous compliance (FedRAMP 20x, machine-readable Key Security Indicators) and how it changes evidence and control design
AI fluency & tooling
Demonstrated ability to build and scale agentic / AI-assisted workflows (Claude, OpenAI) as leverage for the whole team
Cross-functional effectiveness
Ability to work independently and cross-functionally across security, infrastructure, and engineering, with strong prioritization and the ability to influence without authority
Direct experience with FedRAMP or FedRAMP 20x, or other public-sector / continuous-compliance authorizations
Experience with audit ›/ compliance automation platforms (Anecdotes, Drata, Vanta, Paramify, or similar)
Exposure to security incident response and triage
Experience in a high-growth fintech or financial-services environment
Degree in Computer Science, Cybersecurity, or a related field
Our mission at Plaid is to unlock financial freedom for everyone. To support that mission, we seek to build a diverse team of driven individuals who care deeply about making the financial ecosystem more equitable. We recognize that strong qualifications can come from both prior work experiences and lived experiences. We encourage you to apply to a role even if your experience doesn't fully match the job description. We are always looking for team members that will bring something unique to Plaid!
Additional compensation in the form(s) of equity and/or commission are dependent on the position offered. Plaid provides a comprehensive benefit plan, including medical, dental, vision, and 401(k). Pay is based on factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience and skillset, and location. Pay and benefits are subject to change at any time, consistent with the terms of any applicable compensation or benefit plans