Duetto Research logo
Duetto Research

Duetto is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. All qualified applicants will receive consideration for employment without regard to race, colour, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other characteristic protected by applicable law. Sound like you? If this role has you excited, we'd love to hear from you — even if you don't tick every box. At Duetto, we hire for potential, perspective, and the drive to make things happen. Apply and let's start a conversation.

Information Security Analyst

Security AnalystSecurity AnalystFull TimeRemoteMid LevelTeam 51-200

Location

Croatia

Posted

16 days ago

Salary

0

Seniority

Mid Level

Job Description

Information Security Analyst

Duetto Research

Role Description Security compliance doesn't run itself — and at a company processing real-time pricing decisions for thousands of hotels worldwide, getting it right matters. As Security Engineer at Duetto, you'll be the operational backbone of our security programme: - Keeping SOC 2 and ISO 27001 evidence current. - Running access reviews. - Managing vendor security assessments. - Supporting RFPs. - Ensuring the governance infrastructure that underpins customer trust and audit readiness stays organised and on track. It's a detail-oriented, cross-functional role that touches Engineering, IT, Legal, HR, and Sales — and it's central to how Duetto earns and keeps the confidence of enterprise customers globally. Qualifications - 2–4+ years of experience in security GRC, IT audit, compliance, security operations, risk management, or technical programme coordination. - Familiarity with SOC 2, ISO 27001, NIST CSF, access reviews, vendor security, and audit evidence collection. - Experience using Vanta or a comparable GRC/compliance platform. - Strong documentation, follow-up, and project tracking skills. - The ability to work with technical teams and understand security evidence in context. - Strong written communication skills for RFPs, questionnaires, policies, and audit responses. Requirements - Experience in SaaS environments. - Familiarity with AWS evidence, MDM, endpoint security, vulnerability management, and incident response documentation. - Experience supporting customer security reviews or sales security questionnaires. - A basic understanding of GDPR, DPA, DTIA, DPF, and subprocessor management. Benefits - Compliance work with real commercial stakes. - Cross-functional exposure from day one. - AI is how we work. - A growing security programme with real scope. Company Description Duetto is the hospitality industry's leading revenue management platform, founded in 2012 by former Wynn Resorts executives who knew the industry needed better technology. We built the world's first Revenue & Profit Operating System — a suite of tools that goes beyond room pricing to give hotels, resorts, and casinos a complete picture of their revenue and profitability. - Trusted by clients ranging from independent boutique hotels to global chains. - Named the #1 Revenue Management Software by HotelTechAwards four years running. - Recognized as the #1 Best Place to Work in Hotel Tech in 2025. - Backed by GrowthCurve Capital since 2024, accelerating investment in AI.

Related Job Pages

More Security Analyst Jobs

Intermediate Security Analyst

Northbridge Financial

We’re Northbridge Financial. We’re proud to be 100% Canadian and owned by Fairfax Financial. We serve through our Northbridge Insurance, Federated Insurance, and TruShield Insurance brands. We have a reputation for being one of Canada’s leading commercial property and casualty insurance companies. Our employees are dedicated to understanding the needs of our customers and we go above and beyond to help Canadian businesses have a safer and brighter future. We’re a company of passionate people who put people first. At Northbridge Financial we embrace and celebrate you and are committed to creating an inclusive workplace for all! No matter who you are or what makes you unique, we welcome you. Please let us know how we can assist or accommodate you during the selection process.

Security Analyst17 days ago

Role Description As an Intermediate Security Analyst, you’ll play a hands-on role in protecting our technology environment while helping improve how we operate. In this contract opportunity, you’ll support day‑to‑day firewall operations using the Palo Alto Networks platform and work closely with experienced security engineers who are eager to mentor and share knowledge. You’ll also have the opportunity to identify inefficiencies in our security operations and help introduce practical automation or technology-driven improvements that make our processes more effective and scalable. This role is open to remote candidates across Canada. Qualifications - Experience in information security, network security, or IT operations - Hands‑on exposure to Palo Alto Networks firewalls (PAN‑OS), including monitoring and rule management - A foundational understanding of networking concepts such as TCP/IP, DNS, routing, and NAT - Experience reviewing firewall logs and understanding traffic flow and security policies - Exposure to improving operational processes through scripting, automation, or technology enhancements (e.g., dashboards, workflows, or tooling) Requirements - Collaborating with cross‑functional teams in a fast‑paced, operational environment - Analyzing logs, alerts, and network traffic to identify security or connectivity issues - Spotting opportunities to improve processes and reduce manual effort through automation or tooling - Following established runbooks while thinking critically about how processes can evolve - Communicating clearly and documenting work in a structured, meaningful way Benefits - Remote‑friendly work options for candidates located anywhere in Canada - Access to mentorship, learning opportunities, and hands‑on experience with enterprise‑grade security platforms - A collaborative, people‑first culture that values curiosity, improvement, and knowledge sharing - Opportunities to contribute to meaningful security and operational initiatives that protect our customers and organization

Canada
ScalableOS logo

Cybersecurity Analyst

ScalableOS

ScalableOS is a premium offshoring solutions provider based in the Philippines.

Security Analyst17 days ago
Full TimeRemoteTeam 201-500H1B No Sponsor

Role Description The Cybersecurity Analyst is a frontline operational role responsible for monitoring, investigating, and responding to security alerts and incidents across the organization’s security tool stack, with a primary focus on Cisco Secure Workload, Cisco Secure Endpoint, and Cisco Umbrella. This position is centered on alert triage, investigation, and execution of incident response activities, leveraging established detections, playbooks, and procedures to identify threats, assess impact, and drive timely remediation. - Monitor, analyze, and respond to security events and incidents utilizing Cisco Secure Workload, Cisco Secure Endpoint, and Cisco Umbrella. - Conduct thorough investigations of security alerts to identify root causes, assess impact, and coordinate effective remediation. - Leverage Cisco Secure Workload (CSW), Cisco Secure Endpoint (CSE), and Cisco Umbrella to enforce network, endpoint, and DNS-layer security controls and mitigate threats. - Perform detailed investigation of security alerts, correlate events across multiple sources, and drive timely incident response. - Collaborate with cross-functional teams (IT, Network, and Application owners) to identify and remediate security risks and vulnerabilities. - Develop and maintain incident response documentation, procedures, and runbooks. - Contribute to the continuous improvement of security monitoring, detection, and response capabilities. - Stay abreast of evolving cyber threats, tactics, techniques, and procedures (TTPs), and emerging industry trends. Qualifications - Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field (or equivalent experience). - Minimum of 5+ years of hands-on experience in cybersecurity operations, preferably within a Security Operations Center (SOC). - Demonstrated expertise with Cisco security technologies, specifically: - Cisco Secure Workload (CSW) - Cisco Secure Endpoint (CSE) - Cisco Umbrella - Strong knowledge of endpoint security, workload security, network security, and threat detection methodologies. - Solid understanding of networking protocols, DNS, and security architecture principles. - Preferred Qualifications - Experience with CrowdStrike Falcon platform for endpoint detection and response. - Proficiency in ServiceNow (SNOW) for incident, problem, and change management. - Relevant industry certifications such as CyberOps, Security+, CySA+, GCIH, CCNA or equivalent. - Experience integrating security tools with SIEM platforms and ticketing systems. Requirements - Should be willing to accept a long-term work-from-home arrangement. - Should be amenable to a permanent night shift schedule.

Philippines
Full TimeRemoteTeam 10,001+Since 1939H1B No Sponsor

• Provide timely, senior‑level security guidance, mentor junior analysts, and influence risk‑mitigation strategies across multiple functions • Lead implementation of technical control frameworks for programs to mitigate risks and continue to enable certification and accreditation of systems • Write, maintain, and own end-to-end policy lifecycle – author, maintain, and programmatically apply procedures; integrate AI for continuous improvement • Proactively monitor U.S. government cyber regulations, synthesize updates from conferences and industry events and disseminate concise briefs to internal stakeholders • Represent GCP in cross-functional committees, aligning security with NG’s strategic objectives

United States
$103.6K - $155.4K / year
Full TimeRemoteTeam 10,001+Since 1978H1B No Sponsor

• Conduct in-depth analysis of identity fraud patterns, including synthetic identity fraud, credential stuffing, account takeovers (ATO), and deepfake-enabled fraud. • Develop AI-powered fraud detection models and continuously refine existing fraud prevention techniques. • Identify adversarial AI threats, including automated bot fraud, GenAI-enabled phishing, and social engineering attacks. • Research and implement machine learning models to detect deepfake-generated identities, voice fraud, and AI-assisted fraud schemes. • Collaborate with security engineers and data scientists to develop countermeasures for deepfake-based fraud attempts. • Perform advanced fraud penetration testing against identity verification and fraud prevention systems. • Monitor and analyze dark web and underground fraud forums for emerging identity fraud trends and tactics. • Work closely with staff analysts, cybersecurity teams, and fraud risk managers to escalate fraud cases and implement risk mitigation strategies.

United States
$100K - $180K / year