> Markdown version of [/jobs/ext/83888-lead-security-engineer](https://www.wearedevelopers.com/jobs/ext/83888-lead-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Security Engineer - **Company:** Duetto Research, Inc. - **Location:** Austin, TX, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Backup Devices, Cloud Computing Security, Cloud Engineering, Cyber Security, Continuous Integration, DevOps, Identity and Access Management, Information Security Management, Key Management, Network Security, Systems Development Life Cycle, Software Engineering, Software Vulnerability Management, Data Logging, Kubernetes, Devsecops - **Published:** May 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=1c647d3b18135aab ## About the Role Do you have experience in Vulnerability management?, You may be a good fit if you have: * 8+ years of experience in security, cloud security, DevSecOps, security engineering, infrastructure security, or security operations * Strong hands-on knowledge of AWS - you can review cloud architecture and identify risk, not just read about it * Experience securing DevOps environments, CI/CD pipelines, Kubernetes and container environments, cloud IAM, logging, secrets management, and infrastructure-as-code * Experience with SOC 2 Type 2 audits and a working familiarity with ISO 27001, NIST CSF, and GDPR security requirements * Experience with vulnerability management, penetration testing programmes, and incident response * The ability to translate technical risks into business-level priorities and communicate clearly with Engineering, Legal, Sales, auditors, customers, and executives Strong candidates may also have: * Hands-on experience with Snyk, Lacework, Vanta, MDM platforms, endpoint protection, and cloud posture tools * Prior ownership of SOC 2 Type 2 audit readiness end-to-end * ISO 27001 implementation or certification support experience * Experience supporting enterprise SaaS security reviews and customer trust programmes * Familiarity with ISO 42001 or AI governance frameworks, You don't need every item on this list. If you're a hands-on security engineer with strong AWS and DevSecOps chops, compliance programme experience, and the communication skills to operate across Engineering, Legal, and enterprise customers - we'd love to hear from you. ## Description * You'll own Duetto's overall security posture across cloud, product, infrastructure, IT, compliance, and customer assurance - leading cloud security across AWS (IAM, logging, network security, encryption, Kubernetes and container security, backup posture, and configuration risk) and partnering with Engineering and DevOps to embed security into the SDLC, CI/CD pipelines, and production operations. * You'll lead vulnerability management end-to-end - owning Snyk Pro and Lacework (or equivalents) for code, dependency, and cloud security operations, including alert triage, posture management, prioritisation, remediation tracking, and reporting across infrastructure, application, cloud, containers, and endpoints. * You'll serve as the primary security incident leader for major incidents, investigations, escalations, root cause analysis, and executive reporting - and lead IR tabletop exercises, DR tabletop exercises, backup testing coordination, and BCP security reviews. * You'll own SOC 2 Type 2 readiness, ISO 27001 readiness, ISO 42001 AI governance alignment, and NIST CSF maturity tracking - maintaining the security risk register, risk treatment plans, security roadmap, and security debt backlog. * You'll partner with Legal and Privacy on DPA, DTIA, DPF, GDPR, SCCs, and subprocessor management, and own customer-facing security assurance including strategic RFPs, security questionnaires, enterprise security reviews, Trust page content, and sales support calls. * You'll provide security guidance to IT on MDM, endpoint security, AV/EDR coverage, access reviews, and SaaS security controls - and report security posture, risks, incidents, remediation status, and audit readiness to executive leadership., * Full ownership of a consequential security programme. This isn't a supporting role in a large security team - you'll own the posture, the compliance roadmap, the incident response, and the customer trust programme. The scope is real and so is the impact. * AI is how we work. Duetto is an AI-first engineering organisation, which makes AI governance and ISO 42001 alignment genuinely relevant here - you'll be working at the frontier of how security intersects with AI-augmented software development. * Technical depth meets commercial exposure. You'll be reviewing cloud architecture with Engineering one day and supporting an enterprise security review with a global hotel brand the next - the breadth keeps the work interesting. * A platform that demands real security. Millions of pricing decisions processed daily, 80+ integration partners, global enterprise customers - the stakes are high enough to make the work matter. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)