
Security and Compliance Analyst
Posted 13 hours ago

Posted 13 hours ago
This is a fully remote position, open to applicants in Mexico.
• Oversee the daily operations of compliance programs, including SOC 2, PCI DSS, NF525, GDPR, and accessibility.
• Lead the audit and certification processes from start to finish, serving as the primary contact for auditors.
• Manage the scoping, timelines, evidence requests, findings, and follow-up on remediation actions.
• Take ownership of the Drata compliance platform, ensuring the maintenance of control mappings, evidence, and policies.
• Continuously enhance security policies, procedures, controls, and the risk register.
• Identify control deficiencies, propose solutions, and drive remediation efforts to completion.
• Conduct access reviews, policy evaluations, risk assessments, business continuity reviews and testing documentation, as well as vendor security/privacy assessments.
• Oversee the data protection program, which includes managing records of processing, data processing agreements, impact assessments, data subject requests, and standards for data classification and retention.
• Collaborate with Legal on breach assessment and notification processes.
• Lead customer security and privacy questionnaire responses and RFPs alongside the Sales team.
• Coordinate accessibility compliance efforts with Product, Design, and Engineering teams.
• Provide updates on program status, risks, and audit readiness to leadership.
• Leverage AI and automation to minimize repetitive compliance tasks and develop AI-assisted security-answer workflows.
• Work collaboratively with Engineering, DevOps, IT, Product, Sales, Legal, HR, external auditors, and technical experts.
• 3–5 years of experience in security compliance, GRC, IT audit, risk management, or a related discipline.
• Proven experience in managing or supporting at least one complete SOC 2 Type II or PCI DSS audit cycle.
• Familiarity with SOC 2 trust services criteria and/or PCI DSS requirements.
• Experience with a GRC or compliance automation platform, such as Drata or similar.
• Background in conducting vendor or third-party security risk assessments.
• Experience in responding to customer security questionnaires or RFPs.
• Strong understanding of access controls, authentication, vulnerability management, encryption, logging, incident response, change management, and cloud infrastructure.
• Excellent organizational skills and ability to follow through, managing multiple work streams independently.
• Ability to communicate clearly in writing and verbally with engineers, business teams, auditors, and leadership.
• Authorized to work in Mexico.
• Preferred qualifications: experience with Drata, WCAG, NF525, SaaS/cloud infrastructure, AI tools or agents, AI governance, EU AI Act, ISO/IEC 42001, and relevant certifications such as CISA, CRISC, CIPP/E, or Security+.
• Equity opportunities.
• Remote work flexibility.
• Commitment to equal-opportunity employment.
• Disability assistance available during the application process.
WorkOS
Fortive
Brown and Caldwell
Galileo
Get handpicked remote jobs straight to your inbox weekly.