22h ago
New

Security Compliance Analyst

ColombiaColombiaRemotefull-timemid
Finance & AccountingCompliance Analyst
1 views0 saves0 applied

Quick Summary

Key Responsibilities

plan them, carry them out, gather evidence, and follow up on any findings until they're resolved. Perform manual and tool-based security controls,

Technical Tools
Finance & AccountingCompliance Analyst

You will join the Security team at Masabi. Masabi builds Justride, a mobile ticketing and fare collection platform used by public transport authorities and agencies around the world. Our customers trust us with their riders' data and payments, so security and compliance are central to our business.

As a Security Compliance Analyst, you will help us run our security controls consistently and on time. You will own selected control processes from start to finish, carry out reviews, manage third-party risk and support our commercial teams when customers and prospects ask about our security. This role is a good fit for someone who is careful, organised and enjoys finding ways to make repeatable work simpler and more reliable.

// This role is only available to candidates based in Colombia in a fully remote model.

Responsibilities

~1 min read
  • →

    Own assigned security control processes end to end: plan them, carry them out, gather evidence, and follow up on any findings until they're resolved.

  • →

    Perform manual and tool-based security controls, helping us close gaps where controls are missing or not run consistently.

  • →

    Carry out regular reviews, such as user access reviews, and make sure results and actions are recorded.

  • →

    Run our Third-Party Risk Management (TPRM) process: assessing new and existing suppliers, reviewing their security posture, tracking risks, and scheduling reassessments.

  • →

    Maintain the registers that keep our security and privacy processes on track (for example supplier, risk, asset, and data processing registers), keeping them accurate and current.

  • →

    Help analyse security and privacy requirements in bids and tenders from transport agencies, and work with the wider team to prepare clear, accurate answers.

  • →

    Respond to security questionnaires and information requests from existing customers.

  • →

    Support audits and certifications (such as ISO 27001, SOC 2, PCI DSS and Cyber Essentials) by preparing evidence and documentation.

  • →

    Look for opportunities to automate or improve control processes, including with AI tools, so they are faster, more consistent and easier to scale.

  • Detail-oriented and consistent: you follow a process carefully and don't let things slip through the cracks.

  • Some hands-on experience in information security, IT compliance, internal control, audit, or a similar field.

  • A working understanding of core security concepts, like access control, risk management, and data protection.

  • Curious about technology, with a habit of learning how systems, cloud services, and SaaS tools fit together.

  • Clear writing and a knack for structuring information well, whether that's documentation, registers, or questionnaire answers.

  • Organised enough to juggle several recurring tasks and deadlines at once.

  • Comfortable taking ownership of your work, and not afraid to ask questions when something isn't clear.

We don't expect you to tick every box. What matters most is curiosity, a willingness to learn, and the motivation to take ownership of your work.

Nice to Have

~1 min read
  • Experience with Third-Party Risk Management or vendor security assessments.

  • Knowledge of frameworks such as ISO 27001, SOC 2, PCI DSS, GDPR or NIST.

  • Experience supporting RFPs, tenders or customer security questionnaires.

  • Hands-on experience with compliance automation or GRC platforms (for control monitoring, evidence collection and audit management).

  • Interest in automation, such as scripting, low-code tools (e.g. n8n, Make) or using AI to improve workflows.

  • Experience with Jira or Confluence.

// AI is becoming part of how we work at Masabi. You don't need professional experience using AI tools, but we'd expect you've experimented with them and are curious about how they can help you learn, solve problems, and work more effectively.

What We Offer

~1 min read
✓15 days paid vacation per year plus 18 public holidays
✓Private Healthcare
✓Monthly team bonding allowance
✓Menopause support
✓Choice of a workstation
✓Ability to work for up to 3 months per year from any country in the world
✓Fun and collaborative environment with a focus on making a difference in the world

// We are a network of innovators from all walks of life, passionate about making a difference. At Masabi, we operate with openness and trust, creating an environment where everyone feels empowered to bring their whole, authentic selves to work.

Location & Eligibility

Where is the job
Colombia
Remote within one country
Who can apply
CO

Listing Details

Posted
September 28, 2026
First seen
September 28, 2026
Last seen
September 28, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
66%
Scored at
September 28, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

Security Compliance Analyst