Plaid
Software Engineer - Security Engineering
Full details on LinkedIn
The complete job description, requirements, and application details are available on the original posting.
About Plaid
Plaid is a prominent fintech company founded in 2013, specializing in creating secure connections between financial applications, banks, and users' accounts. It supports over 12,000 applications and connects to approximately 10,000 banks globally. Plaid's mission is to democratize financial services through technology, acting as a secure intermediary for data transfer. The platform serves half of U.S. adults and has a valuation of around $13.4 billion. Plaid's flagship product, Plaid Link, offers a developer-friendly API for seamless onboarding, enabling apps to access banking data without direct bank integrations. The company provides various services, including secure bank payments, fraud prevention, personal finance insights, and compliance solutions. Its offerings are designed to enhance user experience and improve financial services through a growing network of connections. Notable applications powered by Plaid include Venmo, Robinhood, and Coinbase, among others, supporting a diverse ecosystem for consumers and businesses alike.
Security at Plaid
Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.
Security Philosophy
- Plaid's AppSec philosophy centers on improving customer trust through the secure development and delivery of products.
- They emphasize a 'shift left' approach, aiming to make the secure path the easiest path for engineers by automating vulnerability detection and remediation workflows within the CI/CD pipeline to reduce operational toil.
Security Team
- The Product Security team at Plaid is responsible for managing security processes, policies, and controls for both developer and consumer-facing products.
- The team is led globally by Nitin Chauhan.
- Current recruitment efforts indicate a focus on Senior Product Security Engineers and Software Engineers specialized in Product Security.
Key Initiatives
- Active initiatives include the development of 'paved roads' for developers to integrate security controls by default and the maintenance of a vulnerability management orchestration service.
- Operational workflows include threat modeling and risk assessments at early development stages, rigorous security testing for new features, and a public bug bounty program with defined SLAs (48-hour response, 5-day triage).
Preparing for an AppSec interview?
Get the weekly briefing 2,000+ security pros trust.