Skip to content

Open nowPosted 12 hours ago

Compliance Manager

duvo14 open roles

Where
EU/UK - Remote
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowCompliance Managerduvo · EU/UK - Remote
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on duvo's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. duvo postings stay open a median of 6 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 12 hours ago

duvo median: 6 days open

The posting

WHO WE ARE

Enterprise work still moves by hand: copy-pasting between spreadsheets, endless email threads, and clunky legacy UIs. We started Duvo to end that for good.

We’ve already earned the trust of a range of customers, and our agents are helping them automate business-critical processes. We are growing fast, but to win from here we need exceptional people; that’s where you come in.

WHAT WE ARE BUILDING

We’re building the AI operations platform for large enterprises, currently focused on retail and consumer packaged goods customers. In Duvo, customers build AI agents that execute work wherever it needs to get done—SAP, spreadsheets, supplier portals, email, APIs, you name it. Duvo is heavy on browser and computer use.

In Duvo, business users specify the outcome; agents plan, act, request approvals on exceptions, and learn with every run. To help customers understand what to automate, we also help them map their processes by digesting interviews and internal documentation, which gets our foot in the door. We start with automating the parts of companies that we know best (category management, supply chain, finance ops) where we can show value fast, then expand to adjacent functions and sectors.

Velocity is our moat: ship fast, iterate faster, compound learning.

THE ROLE

You are the function owner and, for now, its sole occupant. You report to the Head of Engineering and work daily with our Security Lead - you jointly own policies, access reviews, incident evidence and our Trust Center configuration.

You are succeeding in the role when a buyer, an auditor, or a regulator’s customer can get an accurate, evidenced answer about the Duvo the first time they ask. You decide what ships in a questionnaire, whether a vendor passes review, and how the answer library is structured and governed.

WHY THIS ROLE EXISTS

Our agents hold credentials to customers' core systems and act inside them. That makes every enterprise deal a security review, and every security review a test of whether we can produce a straight, evidenced answer quickly.

We hold SOC 2 Type II, ISO 27001, ISO 42001, GDPR and NIS2 commitments, and the surface keeps growing. Banks and telcos now ask about our subprocessor chain because their own regulators require it of them.

This role makes Duvo reviewable. We need someone to own the answers, the evidence, the audits and the vendor chain.

WHAT YOU'LL OWN

The Q&A library - our source of truth. Every due-diligence answer we have, mapped to ISO 27001, SOC 2, ISO 42001, NIS2 and GDPR. Each row carries an owner, approval status, evidence link, confidentiality class and review date. Fast-moving facts get reviewed monthly, process answers quarterly, stable facts annually. One version of every fact across the library, the trust center, the Trust Center portal, our policies and what engineering actually does — with write-back from every questionnaire, audit finding and product change.

Customer security reviews. Intake to delivery for every customer questionnaire, tracked in our system against an agreed turnaround. Unverified answers get validated by Security, Engineering or Product before they ship, then flow back into the library. You keep the customer document set current on the public trust center and the NDA-gated Trust portal.

The audit and certification programme. You run the annual calendar: SOC 2 Type II renewal, ISO 27001 and ISO 42001 surveillance, NIS2 assessment, pen test and retest, and customer right-to-audit requests. Evidence gathering, DPO and auditor liaison, findings and remediation, management assertion.

Between audits you keep the ISMS and AIMS actually operating with the Security Lead: risk register, statement of applicability, policy lifecycle, access reviews, internal audit, management review, security steering cadence.

Third-party and subprocessor risk. You own the vendor policy and the process behind it: intake, tiering by data access and criticality, due diligence on SOC 2 and ISO evidence, DPA terms, and zero-data-retention and no-training commitments from AI providers. Then approval, re-review, off-boarding, as required.

The subprocessor list is a contractual commitment, not a page on the website. You manage review, customer notification, DPA updates and portal updates as one process.

WHAT WE'RE LOOKING FOR

These are the things we'll specifically evaluate you on.

- You've run a certification programme end to end. SOC 2, ISO 27001 or equivalent, through a real audit cycle - not just supported someone else's.

- You write answers that survive a hostile reviewer. Precise, evidenced, and honest about what we don't do. You know the difference between an answer and a deflection.

- Third-party risk in practice. You've built or run a vendor review process and held a subprocessor list accurate under contractual notice obligations.

- Evidence discipline. You think in terms of what an auditor will ask for in nine months, and you capture it while the work is happening rather than reconstructing it later.

- Judgement about escalation. You know which questions are yours to answer, which need Engineering or Security, and which need legal sign-off.

- You use AI tooling properly. You'll be running agents over your own workload and correcting them. Curiosity about where automation breaks is more useful here than caution about using it.

- Plain writing. Most of this job is written output read by people under time pressure.

YOU MIGHT ALSO

- Have dealt with financial services or telco buyers, and know why DORA and NIS2 changed what they ask vendors for.

- Have worked on AI governance or ISO 42001 specifically.

- Have run a GRC platform Vanta, Drata, Mycroft, Segregato or similar, rather than just filled one in.

- Have sat on the vendor side of the table, as a processor answering to controllers, rather than only in-house.

THIS IS NOT FOR YOU IF

- You want to write policy and hand the evidence work to someone else. Here they're the same job.

- You want a team to manage. This is a sole-occupant function, and will be for a while.

- You want a predictable calendar. Scope changes when a deal stalls on it.

HOW WE WORK

These are real tradeoffs we've made, not aspirations:

- Initiative-driven. We organize around customer problems, not org charts. Problems surface through product feedback, competitive analysis, and direct customer conversations — then we prioritize, build, and ship weekly.

- Customer-obsessed. We solve real problems, not hypothetical ones. Features that don't move customer metrics get cut.

- Iterative by default. We ship small, learn fast, and never get attached to yesterday's code. This means things break sometimes — we fix forward.

- AI-first leverage. We use AI to move faster and focus human time where it matters most. If a tool can do it, a person shouldn't.

- Direct feedback. We give each other actionable feedback immediately. This can feel uncomfortable — we think that's worth it.

- Autonomy with accountability. We trust people to make decisions and hold them to outcomes, not process.

WHAT WE OFFER

- Unlimited AI budget. We don't just allow AI tools — we strongly encourage them. Want to try a new tool? Buy it. Want to automate part of your workflow? Do it.

- Autonomy to do your best work. Want to meet someone to learn from? Set it up. Want a mentor? Go get one. Want to fly out to talk to an important customer? Just ask.

- A real AI product with real customers. You're not building demos or internal tools. Enterprise customers use what you ship, and their feedback drives what you build next.

HOW WE HIRE

We respect your time and aim to move fast.

1. Interview with our Security Lead. (1h) What you've worked with, how you work, how you fit into this role.

2. Interview with our Head of Engineering. (30 minutes) Cultural fit in line with Engineering expectation.

3. Final round. Meet the team in Prague.

We aim to close the process in two weeks.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against duvo's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on duvo's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    duvo's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.