
11 - 50 employees
đ¤ Artificial Intelligence
âď¸ SaaS
đ˘ Enterprise
Artificial Intelligence ⢠SaaS ⢠Enterprise
duvo. ai is a no-code AI automation platform that creates persistent AI agents to execute end-to-end business workflows across web apps, legacy portals, email, phone, and data systems. It lets teams describe processes in natural language, connects to tools via APIs or a secure browser, and runs scheduled or event-driven jobs to complete tasks, update systems, and produce evidence â all with enterprise-grade security and auditing. duvo. ai is positioned for operations teams seeking to replace manual, repetitive work with automated execution at scale.
đĽ 13 hours ago
Improve your chances of getting an interview by checking your resume score before you apply.

11 - 50 employees
đ¤ Artificial Intelligence
âď¸ SaaS
đ˘ Enterprise
Artificial Intelligence ⢠SaaS ⢠Enterprise
duvo. ai is a no-code AI automation platform that creates persistent AI agents to execute end-to-end business workflows across web apps, legacy portals, email, phone, and data systems. It lets teams describe processes in natural language, connects to tools via APIs or a secure browser, and runs scheduled or event-driven jobs to complete tasks, update systems, and produce evidence â all with enterprise-grade security and auditing. duvo. ai is positioned for operations teams seeking to replace manual, repetitive work with automated execution at scale.
⢠Own the Q&A library mapped to ISO 27001, SOC 2, ISO 42001, NIS2, and GDPR ⢠Govern ownership, approval status, evidence links, confidentiality classifications, and review dates for the Q&A library ⢠Maintain consistency across the Q&A library, trust center, Trust Center portal, policies, and engineering practices ⢠Manage customer security reviews from questionnaire intake through delivery ⢠Validate unverified answers with Security, Engineering, or Product ⢠Keep public trust-center and NDA-gated Trust portal document sets current ⢠Run the annual audit and certification programme, including SOC 2 Type II renewal, ISO 27001 and ISO 42001 surveillance, NIS2 assessment, penetration testing and retesting, and customer right-to-audit requests ⢠Gather evidence and liaise with the DPO and auditors ⢠Manage audit findings, remediation, and management assertions ⢠Operate the ISMS and AIMS with the Security Lead, including the risk register, statement of applicability, policy lifecycle, access reviews, internal audit, management review, and security steering cadence ⢠Own vendor policy and third-party risk processes, including intake, tiering, due diligence, DPA terms, AI-provider data-retention and no-training commitments, approval, re-review, and offboarding ⢠Manage subprocessor reviews, customer notifications, DPA updates, and portal updates ⢠Report to the Head of Engineering and work daily with the Security Lead
⢠Experience running a certification programme end to end through a real audit cycle, including SOC 2, ISO 27001, or equivalent ⢠Ability to write precise, evidenced, and honest security questionnaire answers ⢠Experience building or running a third-party/vendor review process ⢠Experience maintaining an accurate subprocessor list under contractual notice obligations ⢠Evidence-gathering discipline and audit-readiness ⢠Judgment about escalation to Engineering, Security, or Legal ⢠Ability and willingness to use AI tooling and agents ⢠Plain writing skills ⢠Experience with financial services or telco buyers is a plus ⢠Experience with AI governance or ISO 42001 is a plus ⢠Experience with GRC platforms such as Vanta, Drata, Mycroft, Segregato, or similar is a plus ⢠Experience working on the vendor side as a processor answering to controllers is a plus
⢠Unlimited AI budget ⢠Autonomy to do your best work ⢠Professional development and mentoring autonomy ⢠Ability to fly out to talk to important customers ⢠Real AI product with real enterprise customers
Apply Nowđ September 18
Senior Regulatory Affairs Associate managing Czech and EU clinical trial and marketing authorisation submissions for Parexel. Supporting CTIS, lifecycle maintenance, product information, and regulatory interactions.
đ August 5
Compliance Manager supporting BETERâs global B2B gambling licensing and regulatory compliance. Managing legal research, KYC, Due Diligence, and partner compliance records across jurisdictions.
đ June 5
Regulatory Affairs Specialist managing Czech clinical-trial submissions for Worldwide Clinical Trials, a global CRO. Coordinating EU-CTR regulatory dossiers, compliance, and country-specific documentation.
đŁď¸đ¨đż Czech Required