Skip to content
All jobs

This job comes from Lyft careers page, not from an Interstack member. You apply on their site, so Interstack can't track your application or tell you when it has been seen.

L

Security Assurance Analyst, Security and Privacy

Lyft · Mexico City, Mexico

Security & Privacy Posted 1 month ago

Skills this job asks for

Data protection ISO 27001 SOC 2 LLMs

About the role

At Lyft, our purpose is to serve and connect. We aim to achieve this by cultivating a work environment where all team members belong and have the opportunity to thrive. Lyft connects people to transportation to change the way we live and get around our communities. Our drivers and passengers entrust Lyft with their personal information and travel details to get where they are going and expect us to keep that data safe. Lyft's Privacy and Compliance team ensures that appropriate security controls and data protections are applied to meet our compliance requirements and customer obligations We conduct security risk assessments, consult with organizational stakeholders, monitor and continuously improve Lyft's Information Security program, facilitate third-party security audits, work with engineering teams to implement, automate, and monitor security controls, develop policies, and advise on all matters related to information security assurance. We also conduct risk assessments of our third parties to ensure we understand and can mitigate any associated risk. We are looking for a highly motivated, organized, and detail-oriented individual to join our Privacy and Compliance team. As a senior member of this team, you will support our third party risk management program by conducting risk assessments and recommending mitigations. You will also help our Customer Trust team by completing inbound security and data protection questionnaires from potential partners and customers. Responsibilities: Third Party Risk Assessments Review vendor or partner requests from internal stakeholders, understanding the business purpose Work with external stakeholders to collect relevant security and data protection information from third parties Review the information and accurately assess and document the risk, and propose potential mitigations Security Questionnaires Draft responses to customer security questionnaires (e.g., CAIQ, SIG) and assist in the management of our external trust center (SafeBase) Program Management Help senior team members in managing workflows, queues, and tools Help the team track and compile reporting and metrics Experience: Required 1-3 years of program management experience supporting third party risk management and security compliance and assurance Knowledge of security frameworks such as ISO 27001, SOC 2, PCI DSS, SOX ITGC, or with international privacy/security regulations such as GDPR, EU AI Act, NIS2, or other international privacy/security compliance experience Excellent attention to detail and organizational skills Ability to manage a large workload and competing priorities amid resourcing constraints and tight deadlines Strong written and verbal communication skills across technical, business, and executive audiences Interest in leveraging AI tools or large language models (LLMs), including tools like Claude or Gemini, to automate, improve, or design compliance and assurance processes, documentation, or controls — for example AI-assist...

A summary from the original listing. Read the full details on their site.

Apply on Lyft's site

Opens in a new tab.

Similar jobs