Назад
Company hidden
5 дней назад

Security & Compliance Analyst

80 000 - 90 000MXN
Формат работы
remote (только Mexico)
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
Mexico
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security & Compliance Analyst (GRC/AI): Running and strengthening security, compliance, and governance programs across Peek with an accent on SOC 2, PCI DSS, data protection, audits, and customer security reviews. Focus on leading audit cycles, maintaining control evidence and risk registers, coordinating remediation across teams, and building AI-assisted workflows for repetitive compliance work.

Location: Remote within Mexico; Guadalajara, Hermosillo, Mexico City, or Monterrey

Salary: MX$80,000–MX$90,000 per month plus equity

Company

hirify.global provides an AI-powered operating system for museums, attractions, tours, and activities, supporting booking operations and guest experiences.

What you will do

  • Operate and strengthen compliance programs covering SOC 2, PCI DSS, NF525, GDPR, accessibility, and other data protection requirements.
  • Lead audit and certification cycles from scoping and evidence collection through findings and remediation follow-up.
  • Maintain the Drata compliance platform, control mappings, evidence, policies, risk register, and governance documentation.
  • Run access reviews, risk assessments, business continuity reviews, vendor security assessments, and data protection activities.
  • Partner with Sales on customer security questionnaires and RFPs, and coordinate accessibility compliance with Product, Design, and Engineering.
  • Report program status and audit readiness to leadership while developing AI-assisted workflows for evidence collection, control mapping, questionnaires, and reporting.

Requirements

  • 3–5 years of experience in security compliance, GRC, IT audit, risk, or a related field.
  • Hands-on experience running or supporting at least one SOC 2 Type II or PCI DSS audit cycle end to end.
  • Working knowledge of SOC 2 trust services criteria and/or PCI DSS requirements.
  • Experience with Drata or a similar GRC or compliance automation platform, vendor risk assessments, and customer security questionnaires or RFPs.
  • Understanding of access controls, authentication, vulnerability management, encryption, logging, incident response, change management, and cloud infrastructure.
  • Strong organization, independent ownership, follow-through, and communication with engineers, business teams, auditors, and leadership.

Nice to have

  • Experience with accessibility standards such as WCAG and familiarity with NF525.
  • Experience working with SaaS products, cloud infrastructure, or engineering teams.
  • Experience using AI tools or building AI agents and automations for security, compliance, or governance.
  • Familiarity with AI governance, the EU AI Act, or ISO/IEC 42001.
  • Certifications such as CISA, CRISC, CIPP/E, or Security+.

Culture & Benefits

  • Remote-first work within Mexico.
  • Equity included in the compensation package.
  • Emphasis on ownership, curiosity, pragmatism, clear communication, and continuous improvement.
  • Opportunity to work cross-functionally with Engineering, DevOps, IT, Product, Sales, Legal, HR, and external auditors.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →