Security Engineer GRC
Summary
Own and architect GRC engineering at Plaid: build automated evidence pipelines, continuous controls monitoring, and AI-assisted compliance workflows using Python, SQL, and cloud-native tools.
You own GRC Engineering, define its architecture, build codified sources of truth and live evidence pipelines, automate continuous controls monitoring, create risk dashboards and reporting, conduct risk assessments, automate operational work, embed compliance checks into CI/CD, and develop AI-assisted compliance workflows.
Responsibilities
- Define the GRC Engineering discipline and architecture
- Build pipelines and codified sources of truth for controls and policies
- Automate evidence collection, control testing, and monitoring
- Write and tune detection logic for drift and misconfiguration
- Build dashboards and SQL-driven risk reporting
- Conduct security and technology risk assessments
- Automate evidence pulls, access reviews, vendor reviews, questionnaires, and risk-register upkeep
- Embed compliance checks into CI/CD
- Prototype self-healing policies
- Build continuously validated machine-readable evidence
Requirements
- Strong Python and SQL
- Experience building API and webhook integrations
- Experience owning an internal tool or service end to end
- Hands-on experience with AWS and cloud-native security controls
- Experience querying cloud, GitHub, and SaaS logs
- Proficiency with dashboarding and data visualization tools
- Experience building continuous controls monitoring
- Experience modeling controls, policies, and framework mappings as structured data
- Experience with Terraform and policy-as-code using OPA/Rego or Sentinel
- Knowledge of SOC 2, ISO 27001/27701, and NIST CSF/800-53
- Experience conducting security or technology risk assessments
- Experience building AI-assisted workflows
Benefits
- Equity
- Medical insurance
- Dental insurance
- Vision insurance
- 401(k)