\nWe believe that the way people interact with their finances will drastically improve in the next few years. Weโre dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaidโs network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam. #LI-Remote\n\n\nThe mission of Plaid's Product Security Team is โImprove our customerโs trust by assuring secure development and delivery of products and services, minimizing risk to the ecosystem, and preventing security incidents.โ\n\n\nThe Product Security team is responsible for managing the security processes, policies and controls to secure Plaidโs developer and consumer facing products. The product security team is focused on areas like Application Security, Vulnerability Management, Secure Architecture and Coding, Penetration Testing and Cloud Security.\n\n\nAs a Product Security Engineer, you will work with the Engineering team to build secure products, ensuring security controls are available by default and educating stakeholders on best practices and standards. You will build and implement runtime protection on Plaidโs live products by implementing security solutions like automated security scanners, and runtime application protections. You will also participate in security reviews, threat modeling and building secure architecture standards for products deployed on AWS. You will detect vulnerabilities and triage them with appropriate owners, use vulnerability remediation tools and practices, and follow compliance standards and frameworks but at the same time ensuring you compliment developer velocity and developer satisfaction is a top priority. \n\n\nMajor projects may include building/installing application security testing tools, refining a vulnerability management program, deploying and testing interceptors/wrappers for runtime protection, partnering with strategic teams to help minimize the risk earlier and also coordinating with other security and engineering teams to standardize security policies and standards.\n\n\n\nResponsibilities \n* Lead product security processes and controls focused on secure development and vulnerability remediation of Plaid products.\n* Lead secure design and threat modeling exercises with product and development teams and provide feedback during all phases of the development lifecycle.\n* Partner with engineering teams to identify and solve complex security problems.\n* Conduct thorough technical security assessments and provide expert security opinion to minimize risk in Plaid products.\n* Conduct security testing during product development and in the production environment.\n* Maintain and create secure development practices and programs for our engineering teams and external developers.\n* Understand global events and trends to influence key technical decisions and ensure the security of Plaid products\n* Scaling the impact of security teams by mentoring security engineers.\n* Build training programs to educate the engineering team in secure development concepts. \n\n\n\nQualifications \n* 7+ years of experience in implementing and leading product security controls and processes like secure SDLC, security champions, VM, bug bounty, threat and risk assessment, etc. \n* Excel in secure architecture and development concepts.\n* Hands on skill in building developer centric security solutions.\n* Expertise in areas like shift-left, secure development, vulnerability management and risk management.\n* Knowledge of securing applications deployed using docker, kubernetes, and public cloud like AWS. \n* Strong in both upward and downward communication of security updates and reports.\n* Experience in using security testing tools like Burp.\n* Have deployed common application security testing tools for early vulnerability management at scale. \n* Familiar with OWASP top 10 and CWE top 25 standards.\n\n\n\n\n$215,300 - $322,900 a yearTarget base Salary for this role is $215,300- $322,900 per year. Additional compensation in the form(s) of equity and/or commission are dependent on the position offered. Plaid provides a comprehensive benefit plan, including medical, dental, vision, and 401(k). Pay is based on factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience and skillset, and location. Pay and benefits are subject to change at any time, consistent with the terms of any applicable compensation or benefit plans.\n\nOur mission at Plaid is to unlock financial freedom for everyone. To support that mission, we seek to build a diverse team of driven individuals who care deeply about making the financial ecosystem more equitable. We recognize that strong qualifications can come from both prior work experiences and lived experiences. We encourage you to apply to a role even if your experience doesn't fully match the job description. We are always looking for team members that will bring something unique to Plaid!\n\n\nPlaid is proud to be an equal opportunity employer and values diversity at our company. We do not discriminate based on race, color, national origin, ethnicity, religion or religious belief, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, military or veteran status, disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state, and local laws. Plaid is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance with your application or interviews due to a disability, please let us know at
[email protected].\n\n\nPlease review our Candidate Privacy Notice here. \n\n#Salary and compensation\n
No salary data published by company so we estimated salary based on similar jobs related to Design, Testing, Cloud and Engineer jobs that are similar:\n\n
$50,000 — $95,000/year\n
\n\n#Benefits\n
๐ฐ 401(k)\n\n๐ Distributed team\n\nโฐ Async\n\n๐ค Vision insurance\n\n๐ฆท Dental insurance\n\n๐ Medical insurance\n\n๐ Unlimited vacation\n\n๐ Paid time off\n\n๐ 4 day workweek\n\n๐ฐ 401k matching\n\n๐ Company retreats\n\n๐ฌ Coworking budget\n\n๐ Learning budget\n\n๐ช Free gym membership\n\n๐ง Mental wellness budget\n\n๐ฅ Home office budget\n\n๐ฅง Pay in crypto\n\n๐ฅธ Pseudonymous\n\n๐ฐ Profit sharing\n\n๐ฐ Equity compensation\n\nโฌ๏ธ No whiteboard interview\n\n๐ No monitoring system\n\n๐ซ No politics at work\n\n๐
We hire old (and young)\n\n
\n\n#Location\nUnited States