SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Dovetail is a Customer Intelligence Platform that unifies fragmented customer feedback into an AI-powered intelligence layer. Founded in 2017, the company serves thousands of teams from Fortune 500 companies to innovative startups, with offices in Sydney and San Francisco.
As Security & Compliance Lead, you will own the governance, risk, and compliance function end-to-end, managing SOC 2, ISO/IEC 27001, and ISO/IEC 42001 certifications. This role bridges compliance and security engineering, emphasizing automation and tooling over manual processes.
Key responsibilities include:
- Owning the security risk register, conducting risk assessments on new products and features, and managing vendor risk
- Running compliance certification and surveillance cycles, including scoping, control design, evidence collection, internal audit, and external auditor relationships
- Serving as the technical voice in enterprise security reviews, handling questionnaires and due diligence for Fortune 500 customers
- Building and improving tooling for evidence collection, control monitoring, and continuous compliance reporting
- Developing hands-on security engineering capabilities in detection/response, AWS cloud security posture, and vulnerability management
- Defining AI governance standards for model assessment, documentation, and control, staying ahead of frameworks like the EU AI Act and NIST AI Risk Management Framework
- Contributing to security incident response processes and building security culture across engineering, product, and design teams
You bring deep GRC experience running compliance programs in software businesses, understanding the difference between auditor-satisfying controls and risk-reducing controls. Technical credibility with cloud architecture and AWS security tooling (GuardDuty, Security Hub, Inspector, Detective) is essential. Familiarity with ISO/IEC 42001 and emerging AI assurance frameworks is advantageous. You are pragmatic, quality-focused, and an excellent communicator who can explain risks to engineers, board members, and enterprise CISOs. You prefer building solutions over assessing problems and are comfortable with ambiguity and shifting priorities.
The role is in-person first (4 days/week) from the Surry Hills headquarters, reporting into engineering leadership. This is an individual contributor position with runway to develop genuine security engineering depth.