← Back to job listings
UC
Security Compliance Analyst
Unknown Company · Remote, Mexico
About The Role
As the Security Compliance Analyst, you will manage security, compliance, and customer assurance programs. You will work directly with the VP of Information Security & Compliance on customer security questionnaires, SOC 2 and other audits, control testing, evidence collection, vendor assessments, and compliance initiatives including CMMC and NIST 800-171. This is a hands-on, technically self-sufficient role, not a policy-only or checklist-driven GRC position.
Responsibilities
- Complete customer security questionnaires, DDQs, RFP security sections, and related security reviews.
- Research technical questions and produce accurate, defensible answers based on the company's actual environment and controls.
- Maintain a reusable library of approved questionnaire responses and supporting evidence.
- Recognize when an existing answer applies, when something has changed, and when a subject-matter expert genuinely needs to be involved.
- Participate in customer security calls when deeper technical or compliance discussions are required.
- Help make the customer assurance process faster without sacrificing accuracy.
- Track findings, exceptions, remediation activities, and control-owner commitments through completion.
- Manage deadlines, maintain and report status, and escalate as needed.
Requirements
- 3+ years of relevant experience across IT, security, GRC, compliance, cloud operations, systems administration, or a similar field.
- Solid understanding of common security concepts.
- Hands-on experience with security compliance work, audit evidence, security questionnaires, or control testing.
- Excellent spoken English, with the ability to participate confidently in meetings with U.S.-based customers, auditors, and internal teams.
- Strong organizational skills and attention to detail, with the ability to manage multiple questionnaires, audit requests, and deadlines simultaneously.
- Hands-on experience administering Windows and cloud-based architectures, including IT Tier 2 or systems administration work.
- Comfortable investigating technical systems directly (for example, AWS, identity platforms, endpoint-management tools, GitHub, ticketing systems) to retrieve evidence rather than relying on Engineering or IT for every request.
- Working knowledge of scripting or automation (for example, PowerShell) to operate efficiently at scale.
- Ability to write clear, accurate technical documentation.
Benefits
- Compensation: $2000 to $3000
- Schedule: U.S. business hours
- PTO: Choice of following the U.S. holiday calendar or your home country's calendar.
- Health & Equipment: Healthcare reimbursement eligibility after 90 days; a device stipend of up to $1,500, or reimbursement if you use your own equipment.
Similar roles you might like
See all →5I
Site Partner II (Study Start Up - Regulatory Submissions)
520 ICR Mexico - MEX
Salary not disclosedPosted today
P
Technical Consultant (Regulatory Affairs Operation)
Parexel
Salary not disclosedPosted 1 day ago
MT
Governance and Compliance Analyst
MEX006 Thomson Reuters Contact Center S.A. de C.V.
Salary not disclosedPosted 1 day ago
EC
Trade Compliance Analyst 2
Emerson Career Site
Salary not disclosedPosted 7 days ago
P
Compliance Analyst
payjoy
Salary not disclosedPosted 7 days ago
F
Trade Compliance Analyst
formerra
Salary not disclosedPosted 7 days ago
7D
Regulatory Affairs Specialist - Temporary (12 Months)
7240-JANSSEN-CILAG DE MEXICO Legal Entity
Salary not disclosedPosted 7 days ago
M(
CAC & Distribution Markets Regulatory Affairs Specialist
MX16 (FCRS = MX016) Sandoz S.A. de C.V.
Salary not disclosedPosted 8 days ago
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
