Duetto
Hospitality
InformationSecurityAnalyst
Neural analysis suggests this role is
optimal for Mid candidates.
“Information Security Analyst at Duetto. Skills: Security GRC, IT audit, Compliance, Risk management, SOC 2, ISO 27001, NIST CSF, Vanta. Administer and maintain Vanta (or equivalent GRC platform). Collect and maintain SOC 2 Type 2 evidence”
Industry & Context.
What They're Looking For.
Must Have
2–4+ years of experience in security GRC, IT audit, compliance, security operations, risk management, or technical programme coordination, Familiarity with SOC 2, ISO 27001, NIST CSF, access reviews, vendor security, and audit evidence collection, Experience using Vanta or a comparable GRC/compliance platform, documentation, follow-up, and project tracking skills, The ability to work with technical teams and understand security evidence in context, written communication skills for RFPs, questionnaires, policies, and audit responses
Nice to Have
Experience in SaaS environments, Familiarity with AWS evidence, MDM, endpoint security, vulnerability management, and incident response documentation, Experience supporting customer security reviews or sales security questionnaires, A basic understanding of GDPR, DPA, DTIA, DPF, and subprocessor management
What You'll Do.
Administer and maintain Vanta (or equivalent GRC platform)
Collect and maintain SOC 2 Type 2 evidence
and internal control mapping efforts
Coordinate access reviews across production systems
and business-critical systems
Maintain the governance policy inventory
Keep the risk register
risk treatment tracker
remediation due dates
and exception evidence current
Support vendor and third-party security reviews
Track penetration test findings
vulnerability remediation plans
Draft and maintain approved responses for RFPs
and customer trust materials
Maintain the Live Trust page
Support incident response documentation
Coordinate phishing simulations
security awareness training
Assist with ad hoc security requests
internal evidence requests
and compliance reporting
How You'll Work.
Team & Collaboration
Work with technical teams; Cross-functional exposure across Engineering, IT, Legal, HR, and Sales
Communication Scope
Written communication skills for RFPs, questionnaires, policies, and audit responses
Process & Methodology
Documentation, Follow-up, Project tracking
Full Job Description
Security compliance doesn't run itself — and at a company processing real-time pricing decisions for thousands of hotels worldwide, getting it right matters. As Security Engineer at Duetto, you'll be the operational backbone of our security programme: keeping SOC 2 and ISO 27001 evidence current, running access reviews, managing vendor security assessments, supporting RFPs, and ensuring the governance infrastructure that underpins customer trust and audit readiness stays organised and on track. It's a detail-oriented, cross-functional role that touches Engineering, IT, Legal, HR, and Sales — and it's central to how Duetto earns and keeps the confidence of enterprise customers globally. What Makes Us Different? Duetto is the hospitality industry's leading revenue management platform, founded in 2012 by former Wynn Resorts executives who knew the industry needed better technology. We built the world's first Revenue & Profit Operating System — a suite of tools (GameChanger, ScoreBoard, BlockBuster, Advance and more) that goes beyond room pricing to give hotels, resorts and casinos a complete picture of their revenue and profitability. Trusted by clients ranging from independent boutique hotels to global chains, we've been named the #1 Revenue Management Software by HotelTechAwards four years running and the #1 Best Place to Work in Hotel Tech in 2025. Backed by GrowthCurve Capital since 2024, we're accelerating our investment in AI — and we're genuinely passionate about the industry we serve. We build products we're proud of, for customers we care about. What You'll Be Doing You'll administer and maintain Vanta (or equivalent GRC platform), collecting and maintaining SOC 2 Type 2 evidence across IT, Engineering, HR, Legal, and Security — and supporting ISO 27001, ISO 42001, NIST CSF, and internal control mapping efforts. You'll coordinate access reviews across production systems, cloud platforms, SaaS tools, privileged accounts, and business-critical systems — tracking
Applying for this Information Security Analyst role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Greenhouse
- Create a Greenhouse profile before applying — it saves time across multiple applications.
- Upload your resume as a PDF; the parser handles it better than Word.
- Answer all knockout questions carefully — wrong answers auto-reject before a human sees you.
- Enable email notifications to track application status in real time.
ANONYMOUS · UNFILTERED
What do employees actually say about Duetto?
Real rants from real employees. Read before you apply.