Skip to content
← Back to job listings

Lead Security Engineer

Duetto · United States

External listingfull-time3 months ago

About The Role

Join Duetto as a Lead Security Engineer, where you'll be responsible for the overall security posture across cloud, product, infrastructure, IT, compliance, and customer assurance. You'll lead vulnerability management, serve as the primary security incident leader, and own SOC 2 Type 2 readiness, ISO 27001 readiness, and NIST CSF maturity tracking. You'll also partner with Legal and Privacy on various compliance matters and provide security guidance to IT. This position offers work-from-home opportunities and health insurance.

  • Assumer la responsabilité de la posture de sécurité globale de l'entreprise, en dirigeant la sécurité cloud et en collaborant avec les équipes d'ingénierie et DevOps.
  • Diriger la gestion des vulnérabilités de bout en bout, en possédant les outils de sécurité pour les opérations de sécurité du code, des dépendances et du cloud.
  • Servir de leader principal en matière d'incidents de sécurité, en dirigeant les exercices de simulation et en coordonnant les tests de sauvegarde.
  • The ability to translate technical risks into business-level priorities and communicate clearly with Engineering, Legal, Sales, auditors, customers, and executives
  • Strong hands-on knowledge of AWS — you can review cloud architecture and identify risk, not just read about it
  • Experience with vulnerability management, penetration testing programmes, and incident response
  • 8+ years of experience in security, cloud security, DevSecOps, security engineering, infrastructure security, or security operations
  • Experience securing DevOps environments, CI/CD pipelines, Kubernetes and container environments, cloud IAM, logging, secrets management, and infrastructure-as-code
  • Experience with SOC 2 Type 2 audits and a working familiarity with ISO 27001, NIST CSF, and GDPR security requirements
  • Familiarity with ISO 42001 or AI governance frameworks
  • Hands-on experience with Snyk, Lacework, Vanta, MDM platforms, endpoint protection, and cloud posture tools
  • ISO 27001 implementation or certification support experience
  • Prior ownership of SOC 2 Type 2 audit readiness end-to-end
  • Experience supporting enterprise SaaS security reviews and customer trust programmes
  • You don't need every item on this list. If you're a hands-on security engineer with strong AWS and DevSecOps chops, compliance programme experience, and the communication skills to operate across Engineering, Legal, and enterprise customers — we'd love to hear from you

This is an external listing. JobSpring does not represent or verify the employer. Report this listing