SlipstreamJobsFresh Startup & VC-Backed Jobs

Compliance Manager

Duvo - Remote - Remote - posted 2026-10-02

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Duvo is an AI operations platform for large enterprises that automates business-critical processes across systems like SAP, spreadsheets, supplier portals, and APIs. The company is focused on retail and consumer packaged goods customers and is growing rapidly. You will be the function owner and sole occupant of the Compliance function, reporting to the Head of Engineering and working daily with the Security Lead. You are responsible for making Duvo reviewable and trustworthy to buyers, auditors, and regulators by owning accurate, evidenced answers about the company's security and compliance posture. Key responsibilities include: • Owning and maintaining the Q&A library—a source of truth for all due-diligence answers mapped to ISO 27001, SOC 2, ISO 42001, NIS2, and GDPR. Each entry includes owner, approval status, evidence links, confidentiality class, and review dates. You ensure one version of every fact across the library, trust center, policies, and actual engineering practice, with write-back from questionnaires, audits, and product changes. • Managing customer security reviews end-to-end: intake, delivery tracking, validation of unverified answers by Security/Engineering/Product, and keeping customer documents current on the public trust center and NDA-gated portal. • Running the audit and certification program: annual calendar management for SOC 2 Type II renewal, ISO 27001 and ISO 42001 surveillance, NIS2 assessment, penetration testing, and customer right-to-audit requests. You handle evidence gathering, DPO and auditor liaison, findings, and remediation. • Maintaining the Information Security Management System (ISMS) and AI Management System (AIMS) between audits with the Security Lead: risk register, statement of applicability, policy lifecycle, access reviews, internal audit, management review, and security steering. • Owning third-party and subprocessor risk: vendor policy, intake process, tiering by data access and criticality, due diligence on SOC 2 and ISO evidence, DPA terms, and zero-data-retention/no-training commitments from AI providers. You manage approval, re-review, and off-boarding. The subprocessor list is a contractual commitment; you manage review, customer notification, DPA updates, and portal updates as one integrated process. You succeed when a buyer, auditor, or regulator's customer gets an accurate, evidenced answer the first time they ask. You decide what ships in questionnaires, whether vendors pass review, and how the answer library is structured and governed. Duvo holds SOC 2 Type II, ISO 27001, ISO 42001, GDPR, and NIS2 commitments, with growing surface area. Banks and telcos now ask about the subprocessor chain due to their own regulatory requirements. The company operates with these principles: initiative-driven around customer problems, customer-obsessed (solving real problems, not hypothetical ones), iterative by default (shipping small, learning fast), AI-first leverage (using AI to move faster), direct feedback (actionable and immediate), and autonomy with accountability. Requirements: • You have run a certification program end-to-end (SOC 2, ISO 27001, or equivalent) through a real audit cycle—not just supported someone else's. • You write answers that survive hostile review: precise, evidenced, and honest about what the company doesn't do. You know the difference between an answer and a deflection. • You have hands-on third-party risk experience: built or run a vendor review process and held a subprocessor list accurate under contractual notice obligations. • You have evidence discipline: you think in terms of what an auditor will ask for in nine months and capture it while work is happening rather than reconstructing it later. • You have judgment about escalation: you know which questions are yours to answer, which need Engineering or Security, and which need legal sign-off. • You use AI tooling properly: you will run agents over your own workload and correct them. Curiosity about where automation breaks is more useful than caution. • You write clearly: most of this job is written output read by people under time pressure. Additional experience that is valued: • Experience with financial services or telco buyers and understanding why DORA and NIS2 changed vendor requirements. • Work on AI governance or ISO 42001 specifically. • Running a GRC platform (Vanta, Drata, Mycroft, Segregato, or similar) rather than just filling one in. • Vendor-side experience as a processor answering to controllers, not only in-house roles. This role is not for you if: you want to write policy and hand evidence work to someone else (they are the same job here); you want a team to manage (this is a sole-occupant function for now); or you want a predictable calendar (scope changes when a deal stalls on compliance).

Similar roles