Jobs / United States / Plaid INC
Security Engineer, GRC
Plaid INC · 🇺🇸 San Francisco HQ; Seattle Office; New York City Office
Sponsorship verdict
Sponsorship possible
One solid signal, not two — worth applying, and worth asking about sponsorship early.
- Employer is on a government sponsor recordThe US Department of Labor certified 27 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 9 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).
- The posting doesn’t mention sponsorshipSilence isn’t a refusal — ask the recruiter before investing much time.
- No salary bar for this routeH-1B has no fixed salary bar: the employer must pay at least the prevailing wage for the role and area. Cap-subject employers enter a lottery weighted by wage level. Source: https://www.federalregister.gov/documents/2025/12/29/2025-23853/weighted-selection-process-for-registrants-and-petitioners-seeking-to-file-cap-subject-h-1b, rules effective 2026-02-27.
- What Plaid INC paid sponsored hires in similar roles1 certified filing for “Senior Software Engineer” (Information Security Analysts) in NY: $180k–$180k, median $180k. Most were filed at wage level IV (100%) — 4 lottery entries, ≈61% projected selection odds for cap-subject employers. Source: US Department of Labor LCA disclosure data (Oct 2025 – Jun 2026).
- Confirmed live todayWhen a source last listed this job as open.
US H-1B: cap-subject employers enter a lottery weighted by wage level — Level I gets 1 entry, Level IV gets 4 (DHS projected selection odds ≈15% at Level I to ≈61% at Level IV). Universities and non-profit research employers are cap-exempt. The $100,000 fee for new petitions from abroad is currently blocked by a court order (appeal pending).
A verdict summarises public evidence; it is not legal advice and never a guarantee — the employer and the immigration authority decide. Sign in to factor in where you can already work.
Or apply yourself on the official page →
Sponsor Radar — Plaid INC
The US Department of Labor certified 27 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 9 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).
Past sponsorship or register membership never guarantees sponsorship for this vacancy or for you. Full Sponsor Radar for Plaid INC →
About the role
We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Seattle, Washington D.C., Raleigh, London, and Amsterdam. The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security organization, focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission is to reduce the likelihood and impact of security risks while operating a robust assurance program that builds trust with our customers, consumers, and data partners. We own Plaid’s security compliance frameworks, run our audits and risk programs, and partner across the company to keep Plaid’s platform secure, resilient, and aligned with industry and regulatory expectations. GRC Engineering is how we make all of that scale — turning compliance into code, evidence into telemetry, and audits into a continuous, automated capability. The Role: - You will own GRC Engineering at Plaid — a foundational, high-ownership role defining an emerging discipline from the ground up. Today most of our compliance work is manual and point-in-time; you will turn it into an engineered system that is continuous, data-driven, and scalable, and set the technical direction for the field. - You will: - Define the discipline and the architecture — how GRC Engineering works at Plaid, not just execute within it. - Build the foundation the function runs on — a codified source of truth for controls, policies, and evidence, fed by live pipelines and continuous controls monitoring. - Be the engineering backbone for Security Assurance & Trust Enablement, Third-Party Ecosystem Risk, and Risk Management - Make risk visible and data-driven — turning control and risk data into real-time signals for the team and leadership. - Pioneer where compliance is heading — compliance-agents-as-code in the SDLC, AI- and agent-driven workflows, and machine-readable continuous compliance (FedRAMP 20x). - This role is perfect for you if: - You think in systems: you'd rather design the thing that eliminates a whole class of manual work than automate one task at a time. - You love building and shipping internal tools and solutions that people actually use. - You're relentlessly curious — you poke, you investigate, and you dig into how controls can silently fail, drift, or get bypassed so you can catch it automatically. - You treat every roadblock as just an obstacle to route around — you don't back down, because there's always a path. - You like range — juggling several problems across security, risk, compliance, and engineering beats grinding on a single one. - You're energized by turning compliance from a documentation exercise into demonstrable, continuous, machine-readable evidence. Responsibilities: - Architect GRC's Engineering Foundation: Build the pipelines and codified source of truth the function runs on — controls, policies, and framework mappings captured as structured, version-controlled data and fed by live control and system state — so one control maps evidence across SO