Duetto

Hospitality

InformationSecurityAnalyst

Croatia Remote Friendly
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Mid candidates.

The Brief

“Information Security Analyst at Duetto. Skills: Security GRC, IT audit, Compliance, Risk management, SOC 2, ISO 27001, NIST CSF, Vanta. Administer and maintain Vanta (or equivalent GRC platform). Collect and maintain SOC 2 Type 2 evidence”

Industry & Context.

Hospitality

What They're Looking For.

Must Have

2–4+ years of experience in security GRC, IT audit, compliance, security operations, risk management, or technical programme coordination, Familiarity with SOC 2, ISO 27001, NIST CSF, access reviews, vendor security, and audit evidence collection, Experience using Vanta or a comparable GRC/compliance platform, documentation, follow-up, and project tracking skills, The ability to work with technical teams and understand security evidence in context, written communication skills for RFPs, questionnaires, policies, and audit responses

Nice to Have

Experience in SaaS environments, Familiarity with AWS evidence, MDM, endpoint security, vulnerability management, and incident response documentation, Experience supporting customer security reviews or sales security questionnaires, A basic understanding of GDPR, DPA, DTIA, DPF, and subprocessor management

What You'll Do.

Administer and maintain Vanta (or equivalent GRC platform)

Collect and maintain SOC 2 Type 2 evidence

and internal control mapping efforts

Coordinate access reviews across production systems

and business-critical systems

Maintain the governance policy inventory

Keep the risk register

risk treatment tracker

remediation due dates

and exception evidence current

Support vendor and third-party security reviews

Track penetration test findings

vulnerability remediation plans

Draft and maintain approved responses for RFPs

and customer trust materials

Maintain the Live Trust page

Support incident response documentation

Coordinate phishing simulations

security awareness training

Assist with ad hoc security requests

internal evidence requests

and compliance reporting

How You'll Work.

Team & Collaboration

Work with technical teams; Cross-functional exposure across Engineering, IT, Legal, HR, and Sales

Communication Scope

Written communication skills for RFPs, questionnaires, policies, and audit responses

Process & Methodology

Documentation, Follow-up, Project tracking

Full Job Description

Security compliance doesn't run itself — and at a company processing real-time pricing decisions for thousands of hotels worldwide, getting it right matters. As Security Engineer at Duetto, you'll be the operational backbone of our security programme: keeping SOC 2 and ISO 27001 evidence current, running access reviews, managing vendor security assessments, supporting RFPs, and ensuring the governance infrastructure that underpins customer trust and audit readiness stays organised and on track. It's a detail-oriented, cross-functional role that touches Engineering, IT, Legal, HR, and Sales — and it's central to how Duetto earns and keeps the confidence of enterprise customers globally. What Makes Us Different? Duetto is the hospitality industry's leading revenue management platform, founded in 2012 by former Wynn Resorts executives who knew the industry needed better technology. We built the world's first Revenue & Profit Operating System — a suite of tools (GameChanger, ScoreBoard, BlockBuster, Advance and more) that goes beyond room pricing to give hotels, resorts and casinos a complete picture of their revenue and profitability. Trusted by clients ranging from independent boutique hotels to global chains, we've been named the #1 Revenue Management Software by HotelTechAwards four years running and the #1 Best Place to Work in Hotel Tech in 2025. Backed by GrowthCurve Capital since 2024, we're accelerating our investment in AI — and we're genuinely passionate about the industry we serve. We build products we're proud of, for customers we care about. What You'll Be Doing You'll administer and maintain Vanta (or equivalent GRC platform), collecting and maintaining SOC 2 Type 2 evidence across IT, Engineering, HR, Legal, and Security — and supporting ISO 27001, ISO 42001, NIST CSF, and internal control mapping efforts. You'll coordinate access reviews across production systems, cloud platforms, SaaS tools, privileged accounts, and business-critical systems — tracking

Free ATS check

Applying for this Information Security Analyst role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Greenhouse

  • Create a Greenhouse profile before applying — it saves time across multiple applications.
  • Upload your resume as a PDF; the parser handles it better than Word.
  • Answer all knockout questions carefully — wrong answers auto-reject before a human sees you.
  • Enable email notifications to track application status in real time.

ANONYMOUS · UNFILTERED

What do employees actually say about Duetto?

Real rants from real employees. Read before you apply.

Read Company Rants →