About this role
About the Role Plaid is hiring a Security Engineer, GRC to help build pipelines, automate evidence collection, and model controls across the GRC framework in a hybrid environment. This role supports continuous monitoring and risk-based decision making alongside security and engineering teams. What You'll Do
- Build and maintain data pipelines that automate evidence collection and evidence packaging for audits and controls testing.
- Model, implement, and operationalize controls across the GRC framework; enable continuous controls monitoring.
- Integrate policy-as-code and automation into CI/CD pipelines using tools like OPA/Rego, Sentinel, Terraform.
- Collaborate with security, product, and platform teams to ensure security and compliance requirements are met in cloud environments (AWS).
- Apply AI tooling to improve efficiency, risk detection, and evidence quality. What We're Looking For
- Strong Python and SQL programming experience.
- AWS and cloud security experience.
- Terraform and policy-as-code experience (OPA/Rego, Sentinel).
- CI/CD integration and automation experience.
- Continuous controls monitoring and GRC framework knowledge.
- Familiarity with AI tooling in security/compliance contexts. Nice to Have
- Experience with tools such as Mode, Claude, OpenAI, Anecdotes, Drata, Vanta, Paramify. Compensation & Benefits
- Salary: $156k-$214k per year.
- Employment type: Full-time; Hybrid work arrangement in San Francisco, Seattle, or New York City.
- Location: San Francisco, Seattle, or NYC; United States.