Duettoresearch

Duettoresearch

Lead Security Engineer

United States

Sponsorship not specifiedDetected 55 days ago
AWSCloud PlatformsKubernetesCI/CDDevOpsCybersecurityPenetration TestingNetwork SecuritySOC OperationsIncident ResponseComplianceCommunication

About the role

  • If you're a hands-on security engineer who can operate at the technical depth of a cloud security specialist and communicate at the level of an executive or enterprise customer, this is the role.
  • Trusted by clients ranging from independent boutique hotels to global chains, we've been named the #1 Revenue Management Software by HotelTechAwards four years running and the #1 Best Place to Work in Hotel Tech in 2025.
  • The scope is real and so is the impact. - AI is how we work.

Responsibilities

  • You'll own Duetto's overall security posture across cloud, product, infrastructure, IT, compliance, and customer assurance - leading cloud security across AWS (IAM, logging, network security, encryption, Kubernetes and container security, backup posture, and configuration risk) and partnering with Engineering and DevOps to embed security into the SDLC, CI/CD pipelines, and production operations.
  • You'll lead vulnerability management end-to-end - owning Snyk Pro and Lacework (or equivalents) for code, dependency, and cloud security operations, including alert triage, posture management, prioritisation, remediation tracking, and reporting across infrastructure, application, cloud, containers, and endpoints.
  • You'll serve as the primary security incident leader for major incidents, investigations, escalations, root cause analysis, and executive reporting - and lead IR tabletop exercises, DR tabletop exercises, backup testing coordination, and BCP security reviews.
  • You'll own SOC 2 Type 2 readiness, ISO 27001 readiness, ISO 42001 AI governance alignment, and NIST CSF maturity tracking - maintaining the security risk register, risk treatment plans, security roadmap, and security debt backlog.
  • You'll partner with Legal and Privacy on DPA, DTIA, DPF, GDPR, SCCs, and subprocessor management, and own customer-facing security assurance including strategic RFPs, security questionnaires, enterprise security reviews, Trust page content, and sales support calls.

Requirements

  • You may be a good fit if you have:
  • 8+ years of experience in security, cloud security, DevSecOps, security engineering, infrastructure security, or security operations
  • Strong hands-on knowledge of AWS - you can review cloud architecture and identify risk, not just read about it
  • Experience securing DevOps environments, CI/CD pipelines, Kubernetes and container environments, cloud IAM, logging, secrets management, and infrastructure-as-code
  • Experience with SOC 2 Type 2 audits and a working familiarity with ISO 27001, NIST CSF, and GDPR security requirements
  • Experience with vulnerability management, penetration testing programmes, and incident response
  • Hands-on experience with Snyk, Lacework, Vanta, MDM platforms, endpoint protection, and cloud posture tools
  • Experience supporting enterprise SaaS security reviews and customer trust programmes
  • Familiarity with ISO 42001 or AI governance frameworks

Skills

  • Engineering / Security
  • Duetto is an equal opportunity employer.

This listing is sourced directly from Duettoresearch's careers page and normalized into a canonical job model.