Compliance Manager

Duvo Inc · EU/UK - Remote

Spotted 2h agoFullTime
AI Agent Apply · Ashby & Greenhouse

You find the fit. Your agent handles the form.

Choose a role or send your matches to the agent. It uses your original résumé and saved details, applies in the cloud, and keeps every result in one place.

Review with AI agent
Job description

About this role

Employer-provided description, formatted for easier reading.

Who we are

Enterprise work still moves by hand: copy-pasting between spreadsheets, endless email threads, and clunky legacy UIs. We started Duvo to end that for good.

We’ve already earned the trust of a range of customers, and our agents are helping them automate business-critical processes. We are growing fast, but to win from here we need exceptional people; that’s where you come in.

What we are building

We’re building the AI operations platform for large enterprises, currently focused on retail and consumer packaged goods customers. In Duvo, customers build AI agents that execute work wherever it needs to get done—SAP, spreadsheets, supplier portals, email, APIs, you name it. Duvo is heavy on browser and computer use.

In Duvo, business users specify the outcome; agents plan, act, request approvals on exceptions, and learn with every run. To help customers understand what to automate, we also help them map their processes by digesting interviews and internal documentation, which gets our foot in the door.

We start with automating the parts of companies that we know best (category management, supply chain, finance ops) where we can show value fast, then expand to adjacent functions and sectors.

Velocity is our moat: ship fast, iterate faster, compound learning.

The Role

You are the function owner and, for now, its sole occupant. You report to the Head of Engineering and work daily with our Security Lead - you jointly own policies, access reviews, incident evidence and our Trust Center configuration.

You are succeeding in the role when a buyer, an auditor, or a regulator’s customer can get an accurate, evidenced answer about the Duvo the first time they ask. You decide what ships in a questionnaire, whether a vendor passes review, and how the answer library is structured and governed.

Why this role exists

Our agents hold credentials to customers' core systems and act inside them. That makes every enterprise deal a security review, and every security review a test of whether we can produce a straight, evidenced answer quickly.

We hold SOC 2 Type II, ISO 27001, ISO 42001, GDPR and NIS2 commitments, and the surface keeps growing. Banks and telcos now ask about our subprocessor chain because their own regulators require it of them.

This role makes Duvo reviewable. We need someone to own the answers, the evidence, the audits and the vendor chain.

What you'll own

The Q&A library - our source of truth. Every due-diligence answer we have, mapped to ISO 27001, SOC 2, ISO 42001, NIS2 and GDPR. Each row carries an owner, approval status, evidence link, confidentiality class and review date.

Fast-moving facts get reviewed monthly, process answers quarterly, stable facts annually. One version of every fact across the library, the trust center, the Trust Center portal, our policies and what engineering actually does — with write-back from every questionnaire, audit finding and product change.

Customer security reviews. Intake to delivery for every customer questionnaire, tracked in our system against an agreed turnaround. Unverified answers get validated by Security, Engineering or Product before they ship, then flow back into the library.

You keep the customer document set current on the public trust center and the NDA-gated Trust portal.

The audit and certification programme.

You run the annual calendar

SOC 2 Type II renewal, ISO 27001 and ISO 42001 surveillance, NIS2 assessment, pen test and retest, and customer right-to-audit requests. Evidence gathering, DPO and auditor liaison, findings and remediation, management assertion.

Between audits you keep the ISMS and AIMS actually operating with the Security Lead: risk register, statement of applicability, policy lifecycle, access reviews, internal audit, management review, security steering cadence.

Third-party and subprocessor risk. You own the vendor policy and the process behind it: intake, tiering by data access and criticality, due diligence on SOC 2 and ISO evidence, DPA terms, and zero-data-retention and no-training commitments from AI providers. Then approval, re-review, off-boarding, as required.

The subprocessor list is a contractual commitment, not a page on the website. You manage review, customer notification, DPA updates and portal updates as one process.

What we're looking for

These are the things we'll specifically evaluate you on.

  • You've run a certification programme end to end. SOC 2, ISO 27001 or equivalent, through a real audit cycle - not just supported someone else's.
  • You write answers that survive a hostile reviewer. Precise, evidenced, and honest about what we don't do. You know the difference between an answer and a deflection.
  • Third-party risk in practice. You've built or run a vendor review process and held a subprocessor list accurate under contractual notice obligations.
  • Evidence discipline. You think in terms of what an auditor will ask for in nine months, and you capture it while the work is happening rather than reconstructing it later.
  • Judgement about escalation. You know which questions are yours to answer, which need Engineering or Security, and which need legal sign-off.
  • You use AI tooling properly. You'll be running agents over your own workload and correcting them. Curiosity about where automation breaks is more useful here than caution about using it.
  • Plain writing. Most of this job is written output read by people under time pressure.

You might also

  • Have dealt with financial services or telco buyers, and know why DORA and NIS2 changed what they ask vendors for.
  • Have worked on AI governance or ISO 42001 specifically.
  • Have run a GRC platform Vanta, Drata, Mycroft, Segregato or similar, rather than just filled one in.
  • Have sat on the vendor side of the table, as a processor answering to controllers, rather than only in-house.

This is not for you if

  • You want to write policy and hand the evidence work to someone else. Here they're the same job.
  • You want a team to manage. This is a sole-occupant function, and will be for a while.
  • You want a predictable calendar. Scope changes when a deal stalls on it.

How we work

These are real tradeoffs we've made, not aspirations:

  • Initiative-driven. We organize around customer problems, not org charts. Problems surface through product feedback, competitive analysis, and direct customer conversations — then we prioritize, build, and ship weekly.
  • Customer-obsessed. We solve real problems, not hypothetical ones. Features that don't move customer metrics get cut.
  • Iterative by default. We ship small, learn fast, and never get attached to yesterday's code. This means things break sometimes — we fix forward.
  • AI-first leverage. We use AI to move faster and focus human time where it matters most. If a tool can do it, a person shouldn't.
  • Direct feedback. We give each other actionable feedback immediately. This can feel uncomfortable — we think that's worth it.
  • Autonomy with accountability. We trust people to make decisions and hold them to outcomes, not process.

What we offer

  • Unlimited AI budget. We don't just allow AI tools — we strongly encourage them. Want to try a new tool? Buy it. Want to automate part of your workflow? Do it.
  • Autonomy to do your best work. Want to meet someone to learn from? Set it up. Want a mentor? Go get one. Want to fly out to talk to an important customer? Just ask.
  • A real AI product with real customers. You're not building demos or internal tools. Enterprise customers use what you ship, and their feedback drives what you build next.

How we hire

We respect your time and aim to move fast.

  • Interview with our Security Lead. (1h) What you've worked with, how you work, how you fit into this role.
  • Interview with our Head of Engineering. (30 minutes) Cultural fit in line with Engineering expectation.
  • Final round. Meet the team in Prague.

We aim to close the process in two weeks.

Interested in this role?Continue on Duvo Inc's careers page.
Apply on Duvo Inc