Security and Compliance Analyst

Job not on LinkedIn

🔥 0 minutes ago

🇲🇽 Mexico – Remote

💵 MX$80k - MX$90k / month

⏰ Full Time

🟡 Mid-level

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Peek

Peek

51 - 200 employees

Founded 2012

🏨 Hospitality

🍽️ Food & Beverage

📦 Logistics

💰 $80M Series C on 2021-11

Hospitality • Food & Beverage • Logistics

Peek is a company that specializes in offering a wide range of experiences and activities for travelers and adventure seekers. Their platform allows users to discover and book various tours and activities such as snorkeling, ATV rides, kayak rentals, art experiences, food tours, and more across numerous global destinations like the Cayman Islands, Sint Maarten, San Diego, and many others. Peek also provides 'Peek Pro,' a service tailored for businesses to manage bookings. The company emphasizes user-friendly interfaces to filter by top-rated activities and provides detailed booking information to enhance the travel experience for over 25 million customers.

📋 Description

• Own day-to-day operation of compliance programs including SOC 2, PCI DSS, NF525, GDPR, and accessibility • Lead audit and certification cycles end to end as primary auditor contact • Manage scoping, timelines, evidence, requests, findings, and remediation follow-up • Own the Drata compliance platform and maintain control mappings, evidence, and policies • Maintain and improve security policies, procedures, controls, and the risk register • Identify control gaps, recommend fixes, and drive remediation to closure • Run access reviews, policy reviews, risk assessments, business continuity reviews and testing documentation, and vendor security/privacy assessments • Run the data protection program, including records of processing, data processing agreements, impact assessments, data subject requests, and data classification and retention standards • Partner with Legal on breach assessment and notification • Lead customer security and privacy questionnaire and RFP responses with Sales • Coordinate accessibility compliance with Product, Design, and Engineering • Report program status, risks, and audit readiness to leadership • Use AI and automation to reduce repetitive compliance work and build AI-assisted security-answer workflows • Collaborate with Engineering, DevOps, IT, Product, Sales, Legal, HR, external auditors, and technical experts

🎯 Requirements

• 3–5 years in security compliance, GRC, IT audit, risk, or a related field • Hands-on experience running or supporting at least one SOC 2 Type II or PCI DSS audit cycle end to end • Working knowledge of SOC 2 trust services criteria and/or PCI DSS requirements • Experience with a GRC or compliance automation platform (Drata or similar) • Experience conducting vendor or third-party security risk assessments • Experience responding to customer security questionnaires or RFPs • Solid understanding of access controls, authentication, vulnerability management, encryption, logging, incident response, change management, and cloud infrastructure • Strong organization and follow-through, with the ability to manage multiple work streams independently • Clear written and verbal communication with engineers, business teams, auditors, and leadership • Mexican work authorization • Nice to have: Drata, WCAG, NF525, SaaS/cloud infrastructure, AI tools or agents, AI governance, EU AI Act, ISO/IEC 42001, and certifications such as CISA, CRISC, CIPP/E, or Security+

🏖️ Benefits

• Equity • Remote work • Equal-opportunity employment • Disability assistance during the application process

Apply Now

Similar Jobs

🔥 22 hours ago

Truelogic Software

501 - 1000

☁️ SaaS

🤝 B2B

🏢 Enterprise

AI security engineer red-teaming products, APIs, infrastructure, and agentic systems. Strengthening security for a nearshore technology staffing provider serving American companies.

Cloud

🕒 Yesterday

CRH Talento en IT

11 - 50

💼 Consulting

📣 Marketing

🎯 Recruiter

Administrador de seguridad Mainframe ACF2 para CRH Talento en IT, especializada en selección de consultores tecnológicos. Gestionando accesos, auditorías, vulnerabilidades e integraciones IAM.

🗣️🇪🇸 Spanish Required

🕒 Yesterday

CRH Talento en IT

11 - 50

💼 Consulting

📣 Marketing

🎯 Recruiter

Security Engineer especializado en CyberArk PSM y PAM. Administrando accesos privilegiados, sesiones y controles de seguridad para entornos empresariales globales.

🗣️🇪🇸 Spanish Required

Vault

🕒 Yesterday

Sequoia Connect

11 - 50

💼 Consulting

📣 Marketing

📦 Logistics

Security Track Specialist managing Azure, Entra ID, Microsoft 365, and Intune security infrastructure. Supporting identity governance, endpoint management, troubleshooting, and compliance for a global automation-led technology company.

🗣️🇪🇸 Spanish Required

Azure

Cloud

DNS

🕒 2 days ago

VALCE Talent Solutions

11 - 50

🤝 B2B

🎯 Recruiter

💼 Consulting

Security Track Specialist administering Azure, Entra ID, Microsoft 365, and Intune for Hexaware. Managing identity, endpoints, security compliance, troubleshooting, and infrastructure governance remotely.

🗣️🇪🇸 Spanish Required

Azure

Cloud

DNS