Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Peek

Security and Compliance Analyst

Peek

. Own day-to-day operation of compliance programs including SOC 2, PCI DSS, NF525, GDPR, and accessibility .

Posted 9/23/2026full-timeRemote • MexicoMid-LevelSenior💰 MX$80,000 - MX$90,000 per monthWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in managing compliance programs such as SOC 2, PCI DSS, and GDPR, with a strong focus on audit cycles, risk assessments, and security policy development. Proficient in using compliance automation platforms like Drata to enhance operational efficiency and ensure adherence to regulatory standards.

Highest-signal resume keywords
SOC 2 Type II Audit ExperiencePCI DSS Compliance ManagementGRC Automation Platform ProficiencyVendor Security Risk AssessmentClear Communication Skills

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Security Compliance ManagementRisk AssessmentAudit Cycle ManagementAccess ControlIncident ResponseVulnerability ManagementData Protection Program ManagementPolicy DevelopmentCloud Infrastructure KnowledgeChange Management
Soft Skills
Strong OrganizationFollow-ThroughCollaborationClear Written CommunicationVerbal Communication
Tools & Technologies
Drata Compliance PlatformAI ToolsCompliance Automation ToolsSecurity Answer Workflows
Certifications & Qualifications
CISACRISCCIPP/ESecurity+
Industry Keywords
SOC 2PCI DSSGDPRNF525Accessibility ComplianceEU AI ActISO/IEC 42001Data ClassificationData Retention StandardsBusiness Continuity Reviews

Tech Stack

Tools & technologies
Cloud

About the role

Key responsibilities & impact
  • Own day-to-day operation of compliance programs including SOC 2, PCI DSS, NF525, GDPR, and accessibility
  • Lead audit and certification cycles end to end as primary auditor contact
  • Manage scoping, timelines, evidence, requests, findings, and remediation follow-up
  • Own the Drata compliance platform and maintain control mappings, evidence, and policies
  • Maintain and improve security policies, procedures, controls, and the risk register
  • Identify control gaps, recommend fixes, and drive remediation to closure
  • Run access reviews, policy reviews, risk assessments, business continuity reviews and testing documentation, and vendor security/privacy assessments
  • Run the data protection program, including records of processing, data processing agreements, impact assessments, data subject requests, and data classification and retention standards
  • Partner with Legal on breach assessment and notification
  • Lead customer security and privacy questionnaire and RFP responses with Sales
  • Coordinate accessibility compliance with Product, Design, and Engineering
  • Report program status, risks, and audit readiness to leadership
  • Use AI and automation to reduce repetitive compliance work and build AI-assisted security-answer workflows
  • Collaborate with Engineering, DevOps, IT, Product, Sales, Legal, HR, external auditors, and technical experts

Requirements

What you’ll need
  • 3–5 years in security compliance, GRC, IT audit, risk, or a related field
  • Hands-on experience running or supporting at least one SOC 2 Type II or PCI DSS audit cycle end to end
  • Working knowledge of SOC 2 trust services criteria and/or PCI DSS requirements
  • Experience with a GRC or compliance automation platform (Drata or similar)
  • Experience conducting vendor or third-party security risk assessments
  • Experience responding to customer security questionnaires or RFPs
  • Solid understanding of access controls, authentication, vulnerability management, encryption, logging, incident response, change management, and cloud infrastructure
  • Strong organization and follow-through, with the ability to manage multiple work streams independently
  • Clear written and verbal communication with engineers, business teams, auditors, and leadership
  • Mexican work authorization
  • Nice to have: Drata, WCAG, NF525, SaaS/cloud infrastructure, AI tools or agents, AI governance, EU AI Act, ISO/IEC 42001, and certifications such as CISA, CRISC, CIPP/E, or Security+

Benefits

Comp & perks
  • Equity
  • Remote work
  • Equal-opportunity employment
  • Disability assistance during the application process