Compliance Manager, Business
Listed on 2026-10-04
-
Business
Enterprise work still moves by hand: copy-pasting between spreadsheets, endless email threads, and clunky legacy UIs. We started Duvo to end that for good.
We’ve already earned the trust of a range of customers, and our agents are helping them automate business-critical processes. We are growing fast, but to win from here we need exceptional people; that’s where you come in.
What we are buildingWe’re building the AI operations platform for large enterprises, currently focused on retail and consumer packaged goods customers. In Duvo, customers build AI agents that execute work wherever it needs to get done—SAP, spreadsheets, supplier portals, email, APIs, you name it. Duvo is heavy on browser and computer use.
In Duvo, business users specify the outcome; agents plan, act, request approvals on exceptions, and learn with every run. To help customers understand what to automate, we also help them map their processes by digesting interviews and internal documentation, which gets our foot in the door. We start with automating the parts of companies that we know best (category management, supply chain, finance ops) where we can show value fast, then expand to adjacent functions and sectors.
Velocity is our moat: ship fast, iterate faster, compound learning.
The RoleYou are the function owner and, for now, its sole occupant. You report to the Head of Engineering and work daily with our Security Lead - you jointly own policies, access reviews, incident evidence and our Trust Center configuration.
You are succeeding in the role when a buyer, an auditor, or a regulator’s customer can get an accurate, evidenced answer about the Duvo the first time they ask. You decide what ships in a questionnaire, whether a vendor passes review, and how the answer library is structured and governed.
Why this role existsOur agents hold credentials to customers' core systems and act inside them. That makes every enterprise deal a security review, and every security review a test of whether we can produce a straight, evidenced answer quickly.
We hold SOC 2 Type II, ISO 27001, ISO 42001, GDPR and NIS2 commitments, and the surface keeps growing. Banks and telcos now ask about our subprocessor chain because their own regulators require it of them.
This role makes Duvo reviewable. We need someone to own the answers, the evidence, the audits and the vendor chain.
What you'll ownThe Q&A library - our source of truth. Every due-diligence answer we have, mapped to ISO 27001, SOC 2, ISO 42001, NIS2 and GDPR. Each row carries an owner, approval status, evidence link, confidentiality class and review date. Fast-moving facts get reviewed monthly, process answers quarterly, stable facts annually. One version of every fact across the library, the trust center, the Trust Center portal, our policies and what engineering actually does — with write-back from every questionnaire, audit finding and product change.
Customer security reviews. Intake to delivery for every customer questionnaire, tracked in our system against an agreed turnaround. Unverified answers get validated by Security, Engineering or Product before they ship, then flow back into the library. You keep the customer document set current on the public trust center and the NDA-gated Trust portal.
The audit and certification programme. You run the annual calendar: SOC 2 Type II renewal, ISO 27001 and ISO 42001 surveillance, NIS2 assessment, pen test and retest, and customer right-to-audit requests. Evidence gathering, DPO and auditor liaison, findings and remediation, management assertion.
Between audits you keep the ISMS and AIMS actually operating with the Security Lead: risk register, statement of applicability, policy lifecycle, access reviews, internal audit,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).