Security and Compliance Analyst
Peek · Mexico; Monterrey; Mexico City; Hermosillo; Guadalajara · Remoto
Es un puesto remoto: contratan desde México.
El aviso publica el sueldo: MXN 80.000 a 90.000 por mes.
Piden al menos 5 años de experiencia.
Lo publica Peek y está vigente desde el 23 de septiembre de 2026.
Toca Postularme y entra con tu cuenta de Google: te llevamos al aviso en Ashby y te ayudamos a armar el CV para este puesto.
PostularmeDescripción del puesto
Peek is the operating system powering the experiences industry - from museums and attractions to tours and activities. With over $7B in bookings, Peek’s AI-powered platform has helped thousands of merchants to increase revenues, save time, and deliver seamless guest experiences. Customers include MoMA, Whitney Museum, Seattle Aquarium, Bryant Park & Looping Group. The company has raised over $150 million from institutional investors Westcap, Goldman Sachs, and SpringCoast Partners. Learn more at www.peek.com http://www.peek.com.
As a remote-first company recognized by Forbes as one of America's Best Startup Employers and by Built In as a 2025 and 2026 Best Place to Work, we are a global team of "Peeksters" who "Obsess Over Our Customers," "Accomplish Big Things," "Collaborate With Purpose," and "Get Better Every Day.
THE ROLE
We're hiring a Security & Compliance Analyst to run and strengthen our security, compliance, and governance programs across Peek.
You'll own day-to-day operation of our compliance programs, including SOC 2, PCI DSS, NF525, and accessibility, and various data protection regulations (GDPR, CCPA, CPRA…). You'll be the primary point of contact for auditors and a trusted partner to Sales on customer security reviews. You'll work closely with our DevSecOps Engineer: they own technical controls and remediation, and you run the program that shows those controls work.
You should have run audit cycles before and be comfortable driving work across teams independently. We don't expect deep expertise in every area. NF525 and accessibility, for example, can be learned on the job.
You’ll work closely with Engineering, DevOps, IT, Product, Sales, Legal, and external auditors to understand requirements, collect evidence, identify gaps, coordinate remediation, and help make security and compliance easier to operate at scale.
WHAT YOU’LL DO
- Own day-to-day operation of our compliance programs, including SOC 2, PCI DSS, NF525, GDPR, and accessibility.
- Lead audit and certification cycles end to end as the primary point of contact for auditors: scoping, timelines, evidence, requests, findings, and remediation follow-up.
- Own our compliance platform (Drata), keeping control mappings, evidence, and policies current.
- Maintain and improve security policies, procedures, controls, and the risk register. Identify control gaps, recommend fixes, and drive remediation to closure with control owners in Engineering, DevOps, IT, Product, HR, and other teams.
- Run periodic governance activities: access reviews, policy reviews, risk assessments, business continuity plan reviews and test documentation, and vendor security and privacy assessments, bringing in technical experts for higher-risk vendors.
- Run our data protection program day to day: records of processing, data processing agreements, impact assessments for new features, data subject requests, and data classification and retention standards. Partner with Legal on breach assessment and notification.
- Lead responses to customer security and privacy questionnaires and RFPs with Sales, and maintain a reusable answer library.
- Coordinate accessibility compliance with Product, Design, and Engineering, tracking assessments, findings, and the remediation those teams own.
- Report on program status, risks, and audit readiness to leadership.
- Use AI and automation to reduce repetitive work such as evidence collection, control mapping, questionnaires, and reporting, including building AI-assisted workflows that help teams find accurate security answers.
WHAT WE’RE LOOKING FOR
Required
- 3–5 years in security compliance, GRC, IT audit, risk, or a related field
- Hands-on experience running or supporting at least one SOC 2 Type II or PCI DSS audit cycle end to end
- Working knowledge of SOC 2 trust services criteria and/or PCI DSS requirements
- Experience with a GRC or compliance automation platform (Drata or similar)
- Experience conducting ven
Toca Postularme y entra con tu cuenta de Google: te llevamos al aviso en Ashby y te ayudamos a armar el CV para este puesto.
PostularmeAvisos parecidos
Preguntas frecuentes
¿Es remoto el puesto de Security and Compliance Analyst?
Es un puesto remoto: contratan desde México.
¿Cuánto paga?
El aviso publica MXN 80.000 a 90.000 por mes.
¿Dónde se publicó este aviso?
En Ashby. DameTrabajo lo encontró ahí y te lleva a postularte en el aviso original.