Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
Peek is the operating system powering the experiences industry, handling over $7B in bookings with an AI-powered platform. Clients include MoMA, Whitney Museum, Seattle Aquarium, Bryant Park, and Looping Group. The company has raised $150M from investors like Westcap, Goldman Sachs, and SpringCoast Partners.
About the Role
Peek is hiring a Security & Compliance Analyst to lead and strengthen security, compliance, and governance programs across the organization.
You’ll oversee day-to-day compliance operations, including SOC 2, PCI DSS, NF525, accessibility, GDPR, and CCPA. As the primary auditor liaison, you’ll partner with Sales to handle customer security reviews. Collaboration with the DevSecOps Engineer ensures technical controls are implemented and verified.
Experience running audit cycles independently is required. Deep expertise in every area isn’t necessary—NF525 and accessibility can be learned on the job.
You’ll work closely with Engineering, DevOps, IT, Product, Sales, Legal, and external auditors to align on requirements, gather evidence, identify gaps, coordinate remediations, and streamline security and compliance operations at scale.What You’ll Do
Own and manage compliance programs for SOC 2, PCI DSS, NF525, GDPR, and accessibility.
Lead end-to-end audit and certification cycles, including scoping, timelines, evidence collection, requests, findings, and remediation follow-ups.
Maintain the compliance platform (Drata), ensuring control mappings, evidence, and policies are up-to-date.
Update and enhance security policies, procedures, controls, and the risk register. Identify gaps, recommend fixes, and drive remediation with control owners across Engineering, DevOps, IT, Product, HR, and other teams.
Conduct periodic governance activities, such as access reviews, policy reviews, risk assessments, business continuity plan reviews, vendor security and privacy assessments, and higher-risk vendor evaluations.
Manage the data protection program daily, including records of processing, data processing agreements, impact assessments for new features, data subject requests, and data classification and retention standards. Collaborate with Legal on breach assessments and notifications.
Lead responses to customer security and privacy questionnaires and RFPs with Sales, maintaining a reusable answer library.
Coordinate accessibility compliance with Product, Design, and Engineering, tracking assessments, findings, and remediations.
Report on program status, risks, and audit readiness to leadership.
Use AI and automation to reduce repetitive tasks like evidence collection, control mapping, questionnaires, and reporting. Build AI-assisted workflows to help teams find accurate security answers.
What We’re Looking For
Required:
3–5 years in security compliance, Governance, Risk, and Compliance (GRC), IT audit, risk management, or a related field.
Hands-on experience running or supporting at least one SOC 2 Type II or PCI DSS audit cycle end-to-end.
Working knowledge of SOC 2 trust services criteria and/or PCI DSS requirements.
Experience with a GRC or compliance automation platform (Drata or similar).
Experience conducting vendor or third-party security risk assessments.
Experience responding to customer security questionnaires or RFPs.
A solid understanding of access controls, authentication, vulnerability management, encryption, logging, incident response, change management, and cloud infrastructure to evaluate evidence and challenge control owners.
Strong organizational skills and ability to manage multiple work streams independently.
Clear written and verbal communication skills with engineers, business teams, auditors, and leadership.
Nice to Haves:
Experience with Drata.
Knowledge of WCAG accessibility standards.
Familiarity with NF525.
Experience working with SaaS products, cloud infrastructure, or engineering teams.
Experience using AI tools or building AI agents and automations for security, compliance, or governance work.
Familiarity with AI governance, particularly the EU AI Act and ISO/IEC 42001 standards.
Certifications such as CISA, CRISC, CIPP/E, or Security+.
What We Value
Ownership: Track details, follow through, and ensure nothing falls through the cracks.
Curiosity: Be comfortable exploring new areas and figuring things out.
Pragmatism: Ensure controls and processes reduce real risk and are practical for teams.
Clear communication: Translate requirements into actionable steps and communicate effectively across teams.
Continuous improvement: Improve repetitive, confusing, or overly manual processes.
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
More Openings at Peek
Explore Top Companies in this Space
Bounce
TravelTech & Luggage Storage / Physical Crowdsourcing Marketplace / Retail Monetization SaaS / Consumer Services App
AssistIQ
Healthcare / AI / Enterprise Software / Healthcare Technology Systems
Capitex
Financial Services / Compliance / Staffing / Professional Services
Blueground
Real Estate / Property Management / Hospitality / Digital Marketplaces
Peek (Peek Travel Inc.) is a highly disruptive, industry-leading travel technology company fundamentally designed to revolutionize the tours, activities, and experiences market. Founded in 2012 by Ruzwana Bashir and Oskar Bruening, the company operates as a powerful dual-sided ecosystem combining a massive consumer-facing discovery marketplace with Peek Pro, a robust B2B backend SaaS platform. Under the hood, Peek Pro empowers tour operators, activity providers, and attractions to seamlessly digitize their operations—offering advanced tools for real-time inventory management, point-of-sale (POS) payments, dynamic pricing, and automated marketing. Their primary target audience spans millions of travelers seeking highly curated, unforgettable experiences, as well as thousands of SMB and enterprise merchants who desperately need to move away from analog booking systems to scale their revenue. What sets Peek apart in the fiercely competitive Travel Tech landscape is its staggering scale and institutional backing; supported by technology titans and processing over $7 billion in bookings for 150 million customers, it completely transforms how global experiences are managed, marketed, and consumed.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.






