Security Compliance Analyst
Hace 22 horas
Bogotá, Bogotá, Distrito Capital, Colombia
Masabi
Jornada completa
EUR 198,70 - EUR 298,04/año
Gratis con email o Google
Guarda esta oferta y sigue tu búsqueda
Crea una cuenta gratis para guardar empleos, crear alertas y volver a esta oferta desde tu panel.
Gratis con email o Google
Al continuar, aceptas nuestros Términos & Política de Privacidad.
About Us
_ // At Masabi, we’re driving the fare payment revolution, powering the journeys of millions all over the world. We build fare collection platforms that allow riders to seamlessly buy and present tickets for public transport either on their mobile phones, from a ticket machine, or even by tapping their bank card to travel. Our Justride platform is used in over 250 locations globally, including some of the largest cities in the world. With our industry-first mobile ticketing SDK, we’ve partnered with large players in the transport space, including Uber, Moovit and Transit. Your own journey is important to us too. Choosing a role here means joining a network of innovators from all walks of life; a group of passionate individuals who consistently deliver. Here, you’ll find the tools you need to build the career you want. Whether you’re taking the direct route or trying a new path, we’ll support you no matter what. The Role_ You will join the Security team at Masabi. Masabi builds Justride, a mobile ticketing and fare collection platform used by public transport authorities and agencies around the world. Our customers trust us with their riders' data and payments, so security and compliance are central to our business. As a Security Compliance Analyst, you will help us run our security controls consistently and on time. You will own selected control processes from start to finish, carry out reviews, manage third-party risk and support our commercial teams when customers and prospects ask about our security. This role is a good fit for someone who is careful, organised and enjoys finding ways to make repeatable work simpler and more reliable. Location_ // This role is only available to candidates based in Colombia in a fully remote model. Responsibilities_
- Own assigned security control processes end to end: plan them, carry them out, gather evidence, and follow up on any findings until they're resolved.
- Perform manual and tool-based security controls, helping us close gaps where controls are missing or not run consistently.
- Carry out regular reviews, such as user access reviews, and make sure results and actions are recorded.
- Run our Third-Party Risk Management (TPRM) process: assessing new and existing suppliers, reviewing their security posture, tracking risks, and scheduling reassessments.
- Maintain the registers that keep our security and privacy processes on track (for example supplier, risk, asset, and data processing registers), keeping them accurate and current.
- Help analyse security and privacy requirements in bids and tenders from transport agencies, and work with the wider team to prepare clear, accurate answers.
- Respond to security questionnaires and information requests from existing customers.
- Support audits and certifications (such as ISO 27001, SOC 2, PCI DSS and Cyber Essentials) by preparing evidence and documentation.
- Look for opportunities to automate or improve control processes, including with AI tools, so they are faster, more consistent and easier to scale. About You_
- Detail-oriented and consistent: you follow a process carefully and don't let things slip through the cracks.
- Some hands-on experience in information security, IT compliance, internal control, audit, or a similar field.
- A working understanding of core security concepts, like access control, risk management, and data protection.
- Curious about technology, with a habit of learning how systems, cloud services, and SaaS tools fit together.
- Clear writing and a knack for structuring information well, whether that’s documentation, registers, or questionnaire answers.
- Organised enough to juggle several recurring tasks and deadlines at once.
- Comfortable taking ownership of your work, and not afraid to ask questions when something isn't clear. We don't expect you to tick every box. What matters most is curiosity, a willingness to learn, and the motivation to take ownership of your work. Nice to Have_
- Experience with Third-Party Risk Management or vendor security assessments.
- Knowledge of frameworks such as ISO 27001, SOC 2, PCI DSS, GDPR or NIST.
- Experience supporting RFPs, tenders or customer security questionnaires.
- Hands-on experience with compliance automation or GRC platforms (for control monitoring, evidence collection and audit management).
- Interest in automation, such as scripting, low-code tools (e.g. n8n, Make) or using AI to improve workflows.
- Experience with Jira or Confluence. AI at Masabi_ // AI is becoming part of how we work at Masabi. You don't need professional experience using AI tools, but we'd expect you've experimented with them and are curious about how they can help you learn, solve problems, and work more effectively. Some Of Our Benefits_
- 15 days paid vacation per year plus 18 public holidays
- Private Healthcare
- Monthly team bonding allowance
- Menopause support
- Choice of a workstation
- Ability to work for up t