{"id":1159307,"url":"https://alion.io/job/peek-security-and-compliance-analyst","title":"Security and Compliance Analyst","company":{"id":171889,"name":"Peek","domain":"peek.com","url":"https://alion.io/company/peek-2","size_band":"11-50","is_staffing_agency":false,"is_intermediary":false,"listed_via":null,"ats_vendor":"Ashby","truth_index":null},"role":"Legal","role_family":"Legal","seniority":"middle","employment_type":"full_time","work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"board_field","remote_working_hours":null,"hiring_geo_confidence":"inferred","locations":["Monterrey, Mexico","Mexico City, Mexico","Hermosillo, Mexico","Guadalajara, Mexico"],"countries":["MX"],"hiring_countries":["MX"],"hiring_countries_total":1,"salary":{"min":80000,"max":90000,"currency":"MXN","period":"month","gross":null,"usd_annual":62124},"salary_estimate":null,"experience_years_min":3,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"GDPR","optional":false},{"name":"PCI DSS","optional":false},{"name":"SOC 2","optional":false},{"name":"AI Agents","optional":true},{"name":"EU AI Act","optional":true}],"status":"live","first_seen_at":"2026-09-23T21:11:01Z","employer_posted_date":"2026-09-23","last_verified_at":"2026-09-24T18:55:58Z","board_verified":true,"closed_at":null,"days_open":0,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":0},"description":"Peek is the operating system powering the experiences industry - from museums and attractions to tours and activities. With over $7B in bookings, Peek’s AI-powered platform has helped thousands of merchants to increase revenues, save time, and deliver seamless guest experiences. Customers include MoMA, Whitney Museum, Seattle Aquarium, Bryant Park & Looping Group. The company has raised over $150 million from institutional investors Westcap, Goldman Sachs, and SpringCoast Partners. Learn more at www.peek.com.\nAs a remote-first company recognized by Forbes as one of America's Best Startup Employers and by Built In as a 2025 and 2026 Best Place to Work, we are a global team of \"Peeksters\" who \"Obsess Over Our Customers,\" \"Accomplish Big Things,\" \"Collaborate With Purpose,\" and \"Get Better Every Day.\nThe Role\nWe're hiring a Security & Compliance Analyst to run and strengthen our security, compliance, and governance programs across Peek.\nYou'll own day-to-day operation of our compliance programs, including SOC 2, PCI DSS, NF525, and accessibility, and various data protection regulations (GDPR, CCPA, CPRA…). You'll be the primary point of contact for auditors and a trusted partner to Sales on customer security reviews. You'll work closely with our DevSecOps Engineer: they own technical controls and remediation, and you run the program that shows those controls work.\nYou should have run audit cycles before and be comfortable driving work across teams independently. We don't expect deep expertise in every area. NF525 and accessibility, for example, can be learned on the job.\nYou’ll work closely with Engineering, DevOps, IT, Product, Sales, Legal, and external auditors to understand requirements, collect evidence, identify gaps, coordinate remediation, and help make security and compliance easier to operate at scale.\nWhat you’ll do\nOwn day-to-day operation of our compliance programs, including SOC 2, PCI DSS, NF525, GDPR, and accessibility.\n\nLead audit and certification cycles end to end as the primary point of contact for auditors: scoping, timelines, evidence, requests, findings, and remediation follow-up.\n\nOwn our compliance platform (Drata), keeping control mappings, evidence, and policies current.\n\nMaintain and improve security policies, procedures, controls, and the risk register. Identify control gaps, recommend fixes, and drive remediation to closure with control owners in Engineering, DevOps, IT, Product, HR, and other teams.\n\nRun periodic governance activities: access reviews, policy reviews, risk assessments, business continuity plan reviews and test documentation, and vendor security and privacy assessments, bringing in technical experts for higher-risk vendors.\n\nRun our data protection program day to day: records of processing, data processing agreements, impact assessments for new features, data subject requests, and data classification and retention standards. Partner with Legal on breach assessment and notification.\n\nLead responses to customer security and privacy questionnaires and RFPs with Sales, and maintain a reusable answer library.\n\nCoordinate accessibility compliance with Product, Design, and Engineering, tracking assessments, findings, and the remediation those teams own.\n\nReport on program status, risks, and audit readiness to leadership.\n\nUse AI and automation to reduce repetitive work such as evidence collection, control mapping, questionnaires, and reporting, including building AI-assisted workflows that help teams find accurate security answers.\n\nWhat We’re Looking For\nRequired\n3-5 years in security compliance, GRC, IT audit, risk, or a related field\n\nHands-on experience running or supporting at least one SOC 2 Type II or PCI DSS audit cycle end to end\n\nWorking knowledge of SOC 2 trust services criteria and/or PCI DSS requirements\n\nExperience with a GRC or compliance automation platform (Drata or similar)\n\nExperience conducting vendor or third-party security risk assessments\n\nExperience responding to customer security questionnaires or RFPs\n\nA solid understanding of access controls, authentication, vulnerability management, encryption, logging, incident response, change management, and cloud infrastructure, enough to evaluate evidence and challenge control owners when needed\n\nStrong organization and follow-through, with the ability to manage multiple work streams independently\n\nClear written and verbal communication with engineers, business teams, auditors, and leadership\n\nNice to haves\nExperience with Drata\n\nAccessibility standards such as WCAG\n\nFamiliarity with NF525\n\nWorking with SaaS products, cloud infrastructure, or engineering teams\n\nUsing AI tools or building AI agents and automations for security, compliance, or governance work\n\nFamiliarity with AI governance, particularly the EU AI Act and standards such as ISO/IEC 42001, and a view on how they apply to a company like Peek.\n\nCertifications such as CISA, CRISC, CIPP/E, or Security+\n\nWhat We Value\nA few things that will make you successful in this role:\nOwnership. You keep track of the details, follow through, and make sure things don’t quietly fall through the cracks.\n\nCuriosity. Security and compliance cover a lot of ground. We value people who are comfortable saying “I don’t know yet” and then figuring it out.\n\nPragmatism. Compliance shouldn’t exist just to check a box. We want controls and processes that reduce real risk and work for the teams operating them.\n\nClear communication. You can translate requirements into understandable actions and communicate effectively with engineers, auditors, customers, and business teams.\n\nContinuous improvement. If a process is repetitive, confusing, or overly manual, you’ll look for ways to make it better.\n\nPeek Travel Inc. is an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, sex, sexual orientation, gender identity, veteran status, disability, or other legally protected status.\nIf you are unable to apply due to incompatible assistive technology or a disability, please contact us at . We will make every effort to respond to your request for disability assistance as soon as possible.","description_format":"text","description_chars":6237,"description_truncated":false,"requirements":{"experience_years_min":3,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"Mexico","iso":"MX","kind":"country"},{"name":"Mexico City","iso":null,"kind":"city"},{"name":"Guadalajara","iso":null,"kind":"city"},{"name":"Monterrey","iso":null,"kind":"city"},{"name":"Hermosillo","iso":null,"kind":"city"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Travel & Tourism","Travel Technology"],"lifecycle":[{"event":"open","at":"2026-09-23T23:00:24Z"}],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":0,"expected_fill_days":7,"reasons":["conf:1","velocity","win:early"],"computed_at":"2026-09-24T05:45:00Z"},"pay":{"stated_usd_annual":62124,"is_top_pay":false},"html_url":"https://alion.io/job/peek-security-and-compliance-analyst","json_url":"https://alion.io/job/peek-security-and-compliance-analyst.json","meta":{"generated_at":"2026-09-24T20:45:06Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers"}}