GRC Careers: AI Governance, Risk and Compliance JobsGovernance · Risk · Compliance Careers

Jobs › Mexico City › Security Assurance Analyst, Security and Privacy

Security Assurance Analyst, Security and Privacy

Lyft
PrivacyOn-siteFull-timeMexico City, Mexico

Lyft is hiring for the job of Security Assurance Analyst, Security and Privacy, Mexico City, Mexico (On-site). This is a Privacy job in the governance, risk, and compliance field. Review the full details below and apply directly with Lyft.

Organization: LyftLocation: Mexico City, MexicoWorkplace: On-siteFocus: PrivacyPosted: Oct 1, 2026
Lyft is hiring for this Privacy job in Mexico City, one of the metros GRC Careers tracks for governance, risk, and compliance hiring.

At Lyft, our purpose is to serve and connect. We aim to achieve this by cultivating a work environment where all team members belong and have the opportunity to thrive.

Lyft connects people to transportation to change the way we live and get around our communities. Our drivers and passengers entrust Lyft with their personal information and travel details to get where they are going and expect us to keep that data safe. Lyft s Privacy and Compliance team ensures that appropriate security controls and data protections are applied to meet our compliance requirements and customer obligations We conduct security risk assessments, consult with organizational stakeholders, monitor and continuously improve Lyft s Information Security program, facilitate third-party security audits, work with engineering teams to implement, automate, and monitor security controls, develop policies, and advise on all matters related to information security assurance. We also conduct risk assessments of our third parties to ensure we understand and can mitigate any associated risk.

We are looking for a highly motivated, organized, and detail-oriented individual to join our Privacy and Compliance team. As a senior member of this team, you will support our third party risk management program by conducting risk assessments and recommending mitigations. You will also help our Customer Trust team by completing inbound security and data protection questionnaires from potential partners and customers.

Responsibilities:

Third Party Risk Assessments
Review vendor or partner requests from internal stakeholders, understanding the business purpose
Work with external stakeholders to collect relevant security and data protection information from third parties
Review the information and accurately assess and document the risk, and propose potential mitigations

Security Questionnaires
Draft responses to customer security questionnaires (e.g., CAIQ, SIG) and assist in the management of our external trust center (SafeBase)

Program Management
Help senior team members in managing workflows, queues, and tools
Help the team track and compile reporting and metrics

Experience:

Required

1-3 years of program management experience supporting third party risk management and security compliance and assurance
Knowledge of security frameworks such as ISO 27001, SOC 2, PCI DSS, SOX ITGC, or with international privacy/security regulations such as GDPR, EU AI Act, NIS2, or other international privacy/security compliance experience

Excellent attention to detail and organizational skills
Ability to manage a large workload and competing priorities amid resourcing constraints and tight deadlines
Strong written and verbal communication skills across technical, business, and executive audiences
Interest in leveraging AI tools or large language models (LLMs), including tools like Claude or Gemini, to automate, improve, or design compliance and assurance processes, documentation, or controls, for example AI-assisted evidence review, policy drafting, questionnaire completion, or pattern analysis across audit findings
Familiarity with with GRC platforms (e.g., AuditBoard CrossComply, Vanta, or Drata), Safebase, Jira, and vendor management tools
Knowledge of microservices SaaS product infrastructures or tech stacks a plus

Education

Bachelor s degree in Information Systems, Computer Science, Cybersecurity, Data Science, or a related field preferred
Relevant certifications such as Comptia Security+, Network+, PMP, CIPP a plus

strong em
Lyft highly values having employees working in-office to foster a collaborative work environment and company culture. This role will be in-office on a hybrid schedule following the establishment of a Lyft office in Mexico City, Team Members will be expected to work in the office 3 days per week on Mondays, Wednesdays, and Thursdays. Lyft considers working in the office at least 3 days per week to be an essential function of this hybrid role. Additionally, hybrid roles have the flexibility to work from anywhere for up to 4 weeks per year. #Hybrid Please submit your resume in English.

Location and market context

This job is based in Mexico City on-site. Local candidates benefit from being close to Lyft's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.

About privacy jobs

Privacy jobs protect personal data across its lifecycle, from data mapping and DPIAs to individual-rights handling. AI systems are widening the scope of what privacy teams must review. Jobs like this one are typically evaluated against frameworks such as GDPR, CCPA and US state privacy laws, ISO/IEC 27701, and privacy-by-design practices.

How to position yourself for this privacy job

Strong candidates emphasize data mapping and inventories, privacy impact assessments, rights handling, and building privacy-by-design into products and AI systems. In your resume and outreach, tie your experience to how Lyft would apply GDPR, CCPA and US state privacy laws, ISO/IEC 27701, and privacy-by-design practices, and lead with concrete outcomes rather than duties.

Similar GRC jobs

More GRC jobs in Mexico City

Hiring for Privacy?

Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.

Post a job  Pricing from $99 · About GRC Careers · Hiring toolkit

Want to be next in a job like this?

Jobs like Security Assurance Analyst, Security and Privacy in Mexico City, Mexico open regularly. Be first to know, privately. No current employer ever sees you looking.

New Privacy jobs, the moment they post.

One click unsubscribe.
Know your GRC? Take the 2-minute AI Governance Challenge. No signup needed.
Play now →

Employer, or see something wrong with this posting? Report this posting and we will review it promptly.