Skip to content
LyftLyft

Security Assurance Analyst, Security and Privacy

Supports third-party risk assessments, security questionnaires, and compliance program reporting for Lyft’s Privacy and Compliance team. Requires 1–3 years of relevant program management experience, security framework knowledge, strong organization, and familiarity with GRC tools.

About the job

Responsibilities

Third-Party Risk Assessments

  • Review vendor or partner requests from internal stakeholders and understand the business purpose.
  • Work with external stakeholders to collect relevant security and data protection information from third parties.
  • Assess and document risk accurately and propose potential mitigations.

Security Questionnaires

  • Draft responses to customer security questionnaires, including CAIQ and SIG.
  • Assist with management of the external trust center using SafeBase.

Program Management

  • Help manage workflows, queues, and tools.
  • Track and compile reporting and metrics.

Requirements

  • 1–3 years of program management experience supporting third-party risk management and security compliance and assurance.
  • Knowledge of security frameworks such as ISO 27001, SOC 2, PCI DSS, and SOX ITGC.
  • Experience with international privacy and security regulations such as GDPR, EU AI Act, NIS2, or similar frameworks.
  • Excellent attention to detail and organizational skills.
  • Ability to manage a large workload and competing priorities amid resource constraints and tight deadlines.
  • Strong written and verbal communication skills across technical, business, and executive audiences.
  • Interest in using AI tools or large language models, including Claude or Gemini, to automate and improve compliance and assurance processes, documentation, or controls.
  • Familiarity with GRC platforms such as AuditBoard CrossComply, Vanta, or Drata; SafeBase; Jira; and vendor management tools.

Nice-to-Haves

  • Knowledge of microservices SaaS product infrastructures or technology stacks.
  • Bachelor's degree in Information Systems, Computer Science, Cybersecurity, Data Science, or a related field.
  • Certifications such as CompTIA Security+, Network+, PMP, or CIPP.

Work Arrangement

  • Hybrid schedule in the Mexico City office, with in-office work three days per week on Mondays, Wednesdays, and Thursdays.
  • Hybrid employees may work from anywhere for up to four weeks per year.
  • Resume must be submitted in English.

Skills

Third-Party Risk Management, Security Compliance, ISO 27001, SOC 2, Pci Dss, Sox Itgc, GDPR, Eu Ai Act, Nis2, Grc Platforms, Safebase, Jira, LLMs

Supabase

Supabase

Remote

Platform Security Engineer
No salary listedRemote5+ YOESecurity Engineering

Secures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.

Vanta

Vanta

Remote

Manager, Security Operations
$178k+/yrRemote5+ YOESecurity Engineering

Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.

Monarch

Monarch

Remote

Senior Security GRC Analyst
$180k+/yrRemote5+ YOESecurity Engineering

Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.

Vanta

Vanta

Remote

Lead Product GRC Subject Matter Expert
$230k+/yrRemote10+ YOESecurity Engineering

Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.