Senior Software Engineer - Product Security
Listed on 2026-06-15
-
IT/Tech
Cybersecurity
We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use.
Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam.
The Product Security team is responsible for managing the security processes, policies and controls to secure Plaid’s developer and consumer facing products. The product security team is focused on areas like Application Security, Vulnerability Management, Secure Development Lifecycle, Penetration Testing and Cloud Security. We build the services and components that protect Plaid’s products. We move security "left" by engineering common libraries, modules, and workflows that make the secure path the easiest path for all Plaid engineers.
Plaid is looking for a Product Security Engineer who is a builder to join our Product Security team.
Unlike traditional Product security roles, this position is for a Senior software engineer who wants to solve security challenges at scale by designing and building production-grade services, libraries, and frameworks. Our goal is to make the "secure path" the only path for Plaid developers.
The Role- Lead, design and develop security capabilities to manage vulnerabilities lifecycle and automate workflows to reduce KTLO toil.
- Own, maintain, and build Plaid’s VM Orchestration service and build solutions to eliminate the entire vulnerability classes.
- Partner with product and engineering teams to architect and build security controls to make our products even more secure.
- Consult with product engineers to ensure Plaid services meet security standards.
- Help educate and support other engineering teams to improve security in their own products and services.
- Assist with Plaid’s incident response and security awareness programs.
- Collaborate with other security platform members and build necessary engineering solutions to meet their needs.
- Build the secure engineering foundations that secure the future of digital finance.
- Develop maintainable and secure software to enhance Plaid's security posture and create paved roads for developers for easy and default integration of security controls.
- Design, develop, and maintain security-critical services and components.
- Develop internal tooling to automate vulnerability detection, dependency management, and remediation workflows within the CI/CD pipeline.
- Replace manual security gates with engineered solutions that allow product teams to ship faster and more securely.
- Communicate effectively with managers and team members regarding project deliverables and progress.
- Design and implement technical solutions that align with the evolving needs of the business.
- Proactively identify and address security vulnerabilities in products and services.
- Actively participate in incident response and security awareness initiatives.
- 5+ years of professional experience building and scaling production services.
- Ability to architect and build software systems to meet security, privacy, usability, scalability and cost requirements.
While these experience and characteristics are not prerequisites, candidates whose experience includes:
- Building systems or services related to vulnerability management, data encryption, key management, secret management, user authentication, service authentication, authorization systems, and security policy enforcement.
- Designing distributed systems and microservices with a focus on performance and reliability.
- Familiarity with modern cloud infrastructure (AWS, Kubernetes, Terraform) and how to integrate security controls into them.
- A passion for…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).