Skip to content

Open nowPosted 8 days ago

Security and Compliance Analyst

Peek12 open roles

Pay
MX$80,000 – MX$90,000 a year
Where
Mexico
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSecurity and Compliance AnalystPeek · Mexico
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Peek's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. Peek postings stay open a median of 20 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 8 days ago

Peek median: 20 days open

The posting

Peek is the operating system powering the experiences industry - from museums and attractions to tours and activities. With over $7B in bookings, Peek’s AI-powered platform has helped thousands of merchants to increase revenues, save time, and deliver seamless guest experiences. Customers include MoMA, Whitney Museum, Seattle Aquarium, Bryant Park & Looping Group. The company has raised over $150 million from institutional investors Westcap, Goldman Sachs, and SpringCoast Partners. Learn more at www.peek.com http://www.peek.com.

As a remote-first company recognized by Forbes as one of America's Best Startup Employers and by Built In as a 2025 and 2026 Best Place to Work, we are a global team of "Peeksters" who "Obsess Over Our Customers," "Accomplish Big Things," "Collaborate With Purpose," and "Get Better Every Day.

THE ROLE

We're hiring a Security & Compliance Analyst to run and strengthen our security, compliance, and governance programs across Peek.

You'll own day-to-day operation of our compliance programs, including SOC 2, PCI DSS, NF525, and accessibility, and various data protection regulations (GDPR, CCPA, CPRA…). You'll be the primary point of contact for auditors and a trusted partner to Sales on customer security reviews. You'll work closely with our DevSecOps Engineer: they own technical controls and remediation, and you run the program that shows those controls work.

You should have run audit cycles before and be comfortable driving work across teams independently. We don't expect deep expertise in every area. NF525 and accessibility, for example, can be learned on the job.

You’ll work closely with Engineering, DevOps, IT, Product, Sales, Legal, and external auditors to understand requirements, collect evidence, identify gaps, coordinate remediation, and help make security and compliance easier to operate at scale.

WHAT YOU’LL DO

- Own day-to-day operation of our compliance programs, including SOC 2, PCI DSS, NF525, GDPR, and accessibility.

- Lead audit and certification cycles end to end as the primary point of contact for auditors: scoping, timelines, evidence, requests, findings, and remediation follow-up.

- Own our compliance platform (Drata), keeping control mappings, evidence, and policies current.

- Maintain and improve security policies, procedures, controls, and the risk register. Identify control gaps, recommend fixes, and drive remediation to closure with control owners in Engineering, DevOps, IT, Product, HR, and other teams.

- Run periodic governance activities: access reviews, policy reviews, risk assessments, business continuity plan reviews and test documentation, and vendor security and privacy assessments, bringing in technical experts for higher-risk vendors.

- Run our data protection program day to day: records of processing, data processing agreements, impact assessments for new features, data subject requests, and data classification and retention standards. Partner with Legal on breach assessment and notification.

- Lead responses to customer security and privacy questionnaires and RFPs with Sales, and maintain a reusable answer library.

- Coordinate accessibility compliance with Product, Design, and Engineering, tracking assessments, findings, and the remediation those teams own.

- Report on program status, risks, and audit readiness to leadership.

- Use AI and automation to reduce repetitive work such as evidence collection, control mapping, questionnaires, and reporting, including building AI-assisted workflows that help teams find accurate security answers.

WHAT WE’RE LOOKING FOR

Required

- 3–5 years in security compliance, GRC, IT audit, risk, or a related field

- Hands-on experience running or supporting at least one SOC 2 Type II or PCI DSS audit cycle end to end

- Working knowledge of SOC 2 trust services criteria and/or PCI DSS requirements

- Experience with a GRC or compliance automation platform (Drata or similar)

- Experience conducting vendor or third-party security risk assessments

- Experience responding to customer security questionnaires or RFPs

- A solid understanding of access controls, authentication, vulnerability management, encryption, logging, incident response, change management, and cloud infrastructure, enough to evaluate evidence and challenge control owners when needed

- Strong organization and follow-through, with the ability to manage multiple work streams independently

- Clear written and verbal communication with engineers, business teams, auditors, and leadership

NICE TO HAVES

- Experience with Drata

- Accessibility standards such as WCAG

- Familiarity with NF525

- Working with SaaS products, cloud infrastructure, or engineering teams

- Using AI tools or building AI agents and automations for security, compliance, or governance work

- Familiarity with AI governance, particularly the EU AI Act and standards such as ISO/IEC 42001, and a view on how they apply to a company like Peek.

- Certifications such as CISA, CRISC, CIPP/E, or Security+

WHAT WE VALUE

A few things that will make you successful in this role:

- Ownership. You keep track of the details, follow through, and make sure things don’t quietly fall through the cracks.

- Curiosity. Security and compliance cover a lot of ground. We value people who are comfortable saying “I don’t know yet” and then figuring it out.

- Pragmatism. Compliance shouldn’t exist just to check a box. We want controls and processes that reduce real risk and work for the teams operating them.

- Clear communication. You can translate requirements into understandable actions and communicate effectively with engineers, auditors, customers, and business teams.

- Continuous improvement. If a process is repetitive, confusing, or overly manual, you’ll look for ways to make it better.

Peek Travel Inc. is an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, sex, sexual orientation, gender identity, veteran status, disability, or other legally protected status.

If you are unable to apply due to incompatible assistive technology or a disability, please contact us at [email protected]. We will make every effort to respond to your request for disability assistance as soon as possible.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Peek's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Peek's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Peek's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.