Security Engineering Lead at Dovetail | AU | Rezi

Security Engineering Lead at Dovetail

Security Engineering Lead

Dovetail · AU

1 months ago

Security Engineering Lead

Dovetail · AU

a month ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now
Resume preview

Tailor your resume to this Security Engineering Lead role.

Rezi rewrites your resume against Dovetail's job description. Free.

Resume score gauge reading 58 out of 100

Don't guess if your resume is good enough.

See how it scores against the Security Engineering Lead posting at Dovetail — free, in seconds.

About the Role

As our Security & Compliance Lead, you will own the governance, risk, and compliance function, proving end-to-end compliance across SOC 2, ISO/IEC 27001, and ISO/IEC 42001. This role involves automating controls and pushing into security engineering to build tooling and automation that makes compliance a by-product of daily work. You will also shape governance for new AI products, defining how we assess, document, and control AI systems.

Responsibilities

  • Own security risk, including maintaining the risk register, running risk assessments, driving mitigations, and managing third-party and vendor risk.
  • Own the compliance program, running SOC 2, ISO/IEC 27001, and ISO/IEC 42001 certification cycles end-to-end.
  • Act as the technical voice in enterprise deals, handling security questionnaires and customer trust reviews.
  • Automate evidence collection, control monitoring, and posture reporting.
  • Grow into hands-on security engineering, including detection and response tooling, cloud security posture, and vulnerability management.
  • Set the standard for AI governance, defining assessment and control for AI systems.
  • Contribute to security incident response processes.
  • Build security culture by working with and mentoring engineers, product, and design teams.

Requirements

  • Deep GRC experience, having run compliance programs against SOC 2 and ISO/IEC 27001 in a software business.
  • Understanding the difference between a control that satisfies an auditor and one that actually reduces risk.
  • Comfortable with AI compliance or eager to own it; familiarity with ISO/IEC 42001 and emerging AI assurance frameworks is advantageous.
  • Technical credibility to discuss cloud architecture and security controls with engineers.
  • Exposure to AWS security tooling (GuardDuty, Security Hub, Inspector, Detective) and EKS, TypeScript, or infrastructure as code (Pulumi, Terraform) is beneficial.
  • Desire to build automation for manual processes and become more technical.
  • Experience with enterprise customers, their procurement teams, and security reviewers.
  • Pragmatic and flexible approach, comfortable with ambiguity and resourceful problem-solving.
  • High quality standards, shipping top-notch work and cutting scope before quality.
  • Excellent, concise communication skills, able to explain risks to diverse audiences.
  • Embedding AI into day-to-day work, using it thoughtfully and pragmatically.

Skills

  • Governance, Risk, and Compliance (GRC)
  • SOC 2
  • ISO/IEC 27001
  • ISO/IEC 42001
  • Security Engineering
  • Cloud Security (AWS)
  • Risk Assessment
  • Control Design
  • Vendor Risk Management
  • Security Questionnaires
  • Automation Tooling
  • Detection and Response
  • Vulnerability Management
  • AI Governance
  • Incident Response
  • Security Culture Building
  • AWS Security Tooling
  • EKS
  • TypeScript
  • Infrastructure as Code (Pulumi, Terraform)

Location

  • Surry Hills HQ

Work Type

  • In person first (4 days a week)
  • Remote (US team)
  • Flexible

Experience Level

  • Individual contributor

Salary/Compensations

  • Competitive base salary plus options

Benefits

  • Equity for everyone
  • Competitive base salary plus options
  • Flexible L&D and wellness benefits ($3000 L&D allowance or up to $1000 on wellness)
  • Four weeks of accrued leave
  • Floating public holidays
  • Gifted bonus Kit Kat days
  • Four weeks from anywhere (work from anywhere in the world)
  • Generous parental leave (20 weeks for primary, 12 weeks for secondary, plus return-to-work support)
  • Four weeks off after four years of service
  • Comprehensive US health, dental, vision, 401(k) (through Sequoia)

About the Company

  • Dovetail is the Customer Intelligence Platform for the entire organization, unifying fragmented feedback into a single AI-powered intelligence layer.
  • Founded in 2017, Dovetail has 100+ employees across Sydney and San Francisco offices.
  • We work with thousands of teams from Fortune 500 companies to innovative startups.
  • Our mission is to help teams turn customer interaction noise into signal to move faster, prioritize better, and drive revenue.
  • Roughly 15% of the Fortune 500 trust us with their customer data.

Equal Opportunity

  • At Dovetail, we're building a place where every team member feels supported and valued.
  • We celebrate individualism and want you to show up as your authentic self every day.
  • Diversity builds the best teams, so we highly encourage applications from people who identify as part of an underrepresented group.