# Security Assurance Analyst, Security and Privacy

**Company:** [Lyft](https://hotfix.jobs/companies/lyft)
**Location:** Mexico City, Mexico
**Role:** Security Engineering
**Skills:** Third-Party Risk Management, Security Compliance, ISO 27001, SOC 2, Pci Dss, Sox Itgc, GDPR, Eu Ai Act, Nis2, Grc Platforms, Safebase, Jira, LLMs
**Posted:** 2026-09-07

> Supports third-party risk assessments, security questionnaires, and compliance program reporting for Lyft’s Privacy and Compliance team. Requires 1–3 years of relevant program management experience, security framework knowledge, strong organization, and familiarity with GRC tools.

## Job Description

## Responsibilities

### Third-Party Risk Assessments
- Review vendor or partner requests from internal stakeholders and understand the business purpose.
- Work with external stakeholders to collect relevant security and data protection information from third parties.
- Assess and document risk accurately and propose potential mitigations.

### Security Questionnaires
- Draft responses to customer security questionnaires, including CAIQ and SIG.
- Assist with management of the external trust center using SafeBase.

### Program Management
- Help manage workflows, queues, and tools.
- Track and compile reporting and metrics.

## Requirements
- 1–3 years of program management experience supporting third-party risk management and security compliance and assurance.
- Knowledge of security frameworks such as ISO 27001, SOC 2, PCI DSS, and SOX ITGC.
- Experience with international privacy and security regulations such as GDPR, EU AI Act, NIS2, or similar frameworks.
- Excellent attention to detail and organizational skills.
- Ability to manage a large workload and competing priorities amid resource constraints and tight deadlines.
- Strong written and verbal communication skills across technical, business, and executive audiences.
- Interest in using AI tools or large language models, including Claude or Gemini, to automate and improve compliance and assurance processes, documentation, or controls.
- Familiarity with GRC platforms such as AuditBoard CrossComply, Vanta, or Drata; SafeBase; Jira; and vendor management tools.

## Nice-to-Haves
- Knowledge of microservices SaaS product infrastructures or technology stacks.
- Bachelor's degree in Information Systems, Computer Science, Cybersecurity, Data Science, or a related field.
- Certifications such as CompTIA Security+, Network+, PMP, or CIPP.

## Work Arrangement
- Hybrid schedule in the Mexico City office, with in-office work three days per week on Mondays, Wednesdays, and Thursdays.
- Hybrid employees may work from anywhere for up to four weeks per year.
- Resume must be submitted in English.

## Similar jobs

- [Platform Security Engineer](https://hotfix.jobs/jobs/e556dd76-0f95-4dfa-9d3d-e476f24057c0) - Supabase - Remote
- [Manager, Security Operations](https://hotfix.jobs/jobs/0a4637da-6072-4ec3-a0a9-8b6d4a412d45) - Vanta - Remote - $178k – $209k/yr
- [Senior Security GRC Analyst](https://hotfix.jobs/jobs/b54fb115-3bb7-4d88-8fdc-b7901d26d90d) - Monarch - Remote - $180k – $215k/yr
- [Lead Product GRC Subject Matter Expert](https://hotfix.jobs/jobs/57c937d5-05e3-4033-875a-890645c4aa6b) - Vanta - Remote - $230k – $270k/yr

**Apply:** https://hotfix.jobs/jobs/abf59dc5-8058-406e-8af9-a3e1bebc8e8b
**Canonical:** https://hotfix.jobs/jobs/abf59dc5-8058-406e-8af9-a3e1bebc8e8b