Security Assurance Analyst, Security and Privacy

Lyft

Ciudad de México

Híbrido

MXN 900.000 - 1.200.000

Jornada completa

14 días+
Generador de candidaturas

Una candidatura completa en un minuto — currículum adaptado y carta de presentación, listos para enviar.

Supera los filtros ATS

Ventajas ofrecidas por este puesto de trabajo

Hybrid schedule
Office in Mexico City

Descripción de la vacante

Lyft is seeking a senior Privacy and Compliance professional to join our team in Mexico City. You will lead third party risk assessments, collect security information from vendors, and draft responses to security questionnaires while supporting program management and reporting across the organization.

The role requires 1–3 years in risk management and familiarity with leading compliance frameworks and GRC tools; it is office-based with a hybrid schedule, three days in the office per week in

Formación

  • 1–3 years of program management experience supporting third party risk management and security compliance.
  • Knowledge of security frameworks such as ISO 27001, SOC 2, PCI DSS, SOX ITGC, or GDPR/NIS2/privacy regs.
  • Excellent attention to detail and organizational skills.
  • Ability to manage a large workload and tight deadlines.
  • Strong written and verbal communication across technical, business, and executive audiences.
  • Interest in leveraging AI tools or LLMs to automate compliance processes.
  • Familiarity with GRC platforms (AuditBoard, CrossComply, Vanta, Drata), Safebase, Jira.
  • Knowledge of microservices SaaS product infrastructures is a plus.

Responsabilidades

  • Conduct third party risk assessments, document risk, and propose mitigations.
  • Review vendor requests from stakeholders and collect security data from third parties.
  • Draft responses to security questionnaires (CAIQ, SIG) and manage SafeBase external trust center.
  • Support program management, including workflows, queues, and reporting metrics.

Conocimientos

Program management
Security compliance
Vendor risk management
Communication
AI/mL tools interest
GRC awareness

Educación

Bachelor's in IS/CS/Cybersecurity/Data Science
Certifications (CompTIA Security+, Network+, PMP, CIPP)

Herramientas

AuditBoard
CrossComply
Vanta
Drata
Safebase
Jira

Descripción del empleo

At Lyft, our purpose is to serve and connect. We aim to achieve this by cultivating a work environment where all team members belong and have the opportunity to thrive.

Lyft connects people to transportation to change the way we live and get around our communities. Our drivers and passengers entrust Lyft with their personal information and travel details to get where they are going and expect us to keep that data safe. Lyft's Privacy and Compliance team ensures that appropriate security controls and data protections are applied to meet our compliance requirements and customer obligations We conduct security risk assessments, consult with organizational stakeholders, monitor and continuously improve Lyft's Information Security program, facilitate third-party security audits, work with engineering teams to implement, automate, and monitor security controls, develop policies, and advise on all matters related to information security assurance. We also conduct risk assessments of our third parties to ensure we understand and can mitigate any associated risk.

We are looking for a highly motivated, organized, and detail-oriented individual to join our Privacy and Compliance team. As a senior member of this team, you will support our third party risk management program by conducting risk assessments and recommending mitigations. You will also help our Customer Trust team by completing inbound security and data protection questionnaires from potential partners and customers.

Responsibilities
  • Third Party Risk Assessments

  • Review vendor or partner requests from internal stakeholders, understanding the business purpose

  • Work with external stakeholders to collect relevant security and data protection information from third parties

  • Review the information and accurately assess and document the risk, and propose potential mitigations

  • Security Questionnaires

  • Draft responses to customer security questionnaires (e.g., CAIQ, SIG) and assist in the management of our external trust center (SafeBase)

  • Program Management

  • Help senior team members in managing workflows, queues, and tools

  • Help the team track and compile reporting and metrics

Experience
Required
  • 1-3 years of program management experience supporting third party risk management and security compliance and assurance

  • Knowledge of security frameworks such as ISO 27001, SOC 2, PCI DSS, SOX ITGC, or with international privacy/security regulations such as GDPR, EU AI Act, NIS2, or other international privacy/security compliance experience

  • Excellent attention to detail and organizational skills

  • Ability to manage a large workload and competing priorities amid resourcing constraints and tight deadlines

  • Strong written and verbal communication skills across technical, business, and executive audiences

  • Interest in leveraging AI tools or large language models (LLMs), including tools like Claude or Gemini, to automate, improve, or design compliance and assurance processes, documentation, or controls — for example AI-assisted evidence review, policy drafting, questionnaire completion, or pattern analysis across audit findings

  • Familiarity with with GRC platforms (e.g., AuditBoard CrossComply, Vanta, or Drata), Safebase, Jira, and vendor management tools

  • Knowledge of microservices SaaS product infrastructures or tech stacks a plus

Education
  • Bachelor's degree in Information Systems, Computer Science, Cybersecurity, Data Science, or a related field preferred

  • Relevant certifications such as Comptia Security+, Network+, PMP, CIPP a plus

Lyft highly values having employees working in-office to foster a collaborative work environment and company culture. This role will be in-office on a hybrid schedule following the establishment of a Lyft office in Mexico City — Team Members will be expected to work in the office 3 days per week on Mondays, Wednesdays, and Thursdays. Lyft considers working in the office at least 3 days per week to be an essential function of this hybrid role. Additionally, hybrid roles have the flexibility to work from anywhere for up to 4 weeks per year. #Hybrid

Consigue la evaluación confidencial y gratuita de tu currículum.

o arrastra y suelta tu archivo aquí

Similar jobs

Puestos de trabajo similares que vale la pena comparar

Third-Party Risk & Security Assurance Analyst
Third-Party Risk & Security Assurance Analyst

Socotra, Inc. • Ciudad de México

Híbrido
MXN 600.000 - 900.000
Senior Third-Party Security & Privacy Assurance Analyst
Senior Third-Party Security & Privacy Assurance Analyst

Lyft • Ciudad de México

Híbrido
MXN 900.000 - 1.200.000
Hybrid schedule
Office in Mexico City
Senior Third-Party Risk & Security Assurance Analyst
Senior Third-Party Risk & Security Assurance Analyst

Lyft • Ciudad de México

Híbrido
MXN 420.000 - 640.000
Security Analyst
Security Analyst

Xapply • Ciudad de México

Presencial
MXN 1.457.000 - 2.186.000
Software Engineer - Self Service Intelligence, SCC Eng
Software Engineer - Self Service Intelligence, SCC Eng

Lyft • Ciudad de México

Presencial
MXN 600.000 - 900.000
Security Analyst: Incident Response & Threat Hunting
Security Analyst: Incident Response & Threat Hunting

Xapply • Ciudad de México

Presencial
MXN 1.457.000 - 2.186.000
Software Engineer Intern, Frontend (Summer 2027)
Software Engineer Intern, Frontend (Summer 2027)

Lyft • Ciudad de México

Presencial
MXN 56.000 - 112.000
Senior GRC Specialist
Senior GRC Specialist

Airwallex • Ciudad de México

Híbrido
MXN 900.000 - 1.500.000
Technology Compliance Engineer
Technology Compliance Engineer

Turtle Trax S.A. • Estado de México

Presencial
MXN 70.000 - 90.000
Senior Compassionate Care Escalations Specialist
Senior Compassionate Care Escalations Specialist

Socotra, Inc. • Ciudad de México

Presencial
MXN 360.000 - 480.000