עדיין מחפשים עבודה במנועי חיפוש? הגיע הזמן להשתדרג!
במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.
מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.
About Duve
Duve is a fast-growing hospitality tech company transforming how hotels and vacation rentals connect with their guests. Our platform helps them deliver personalized, digital guest experiences at scale from the moment a booking is made and throughout the entire stay.
Founded in 2016 and headquartered in Tel Aviv, Duve is trusted by 1,000+ customers across 70+ countries, serving millions of travelers worldwide.
Following a $60M funding round, Duve is entering its next phase of growth, with AI playing a central role in the evolution of our platform. As we continue to expand globally, we’re investing in advanced technology to shape the future of guest experience and how hotels and vacation rentals operate and connect with their guests.
About this Role
We’re looking for a hands-on IT & Compliance Manager to own Duve’s internal IT environment and lead our security, privacy, and compliance operations.
You’ll be responsible for the systems our employees rely on every day, while driving our compliance program across frameworks such as SOC 2, ISO 27001, ISO 27701, PCI DSS, and GDPR.
Working closely with R&D, DevOps, HR, Legal, Sales, Customer Success, and external vendors, you’ll ensure our internal environment is secure, scalable, audit-ready, and able to support the requirements of our growing enterprise customer base.
This is an individual contributor role reporting directly to the CTO, with end-to-end ownership and responsibility for managing relevant external vendors and partners.
Requirements
Must-have
- 4+ years of experience in IT, Information Security, Compliance/GRC, or a similar role
- Hands-on ownership of at least one SOC 2 or ISO 27001 audit or certification cycle
- Experience with identity and endpoint management tools such as JumpCloud, Okta, Google Workspace, Entra ID, or similar
- Working knowledge of AWS security fundamentals, including IAM, logging, network boundaries, and encryption
- Practical experience with GDPR and privacy operations, including DSRs, ROPA, and DPAs
- Experience creating and maintaining security policies, procedures, controls, and audit documentation
- Ability to independently own recurring IT, security, and compliance processes end-to-end
- Strong communication skills and the ability to work effectively with both technical teams and enterprise customers
- Fluency in English and Hebrew
Nice-to-have
- Experience with Vanta, Drata, or a similar compliance automation platform
- Experience with ISO 27701, PCI DSS, or NIST CSF
- Certifications such as ISO 27001 Lead Implementer/Lead Auditor, CISSP, CISM, CIPP/E, or equivalent
- Familiarity with Kubernetes, CI/CD security, vulnerability management, or dependency scanning tools
- Scripting or automation experience
- Experience in a B2B SaaS environment, particularly with enterprise customers
- Familiarity with AI governance and emerging enterprise security requirements around AI
What You’ll Do
- Own and continuously improve Duve’s information security and privacy management programs, including controls, policies, evidence, risk management, and corrective actions
- Lead compliance and certification activities across SOC 2 Type II, ISO 27001, ISO 27701, PCI DSS, and GDPR
- Manage external audits end-to-end, including preparation, evidence collection, auditor coordination, findings, and remediation
- Own enterprise security questionnaires, customer security requirements, and security documentation supporting Sales and Customer Success
- Manage identity, access, and endpoint operations, including employee onboarding and offboarding, MFA, permissions, and periodic access reviews
- Own core IT operations, including asset management, device security, office IT, and employee support escalations
- Manage privacy processes alongside the DPO, including data inventory, ROPA, DSRs, retention, DPAs, and privacy impact assessments
- Manage third-party and vendor security risk, including due diligence, ongoing reviews, and subprocessor management
- Coordinate security incident response, vulnerability management, security awareness, and business continuity processes
- Partner closely with R&D and DevOps on security controls, infrastructure risks, remediation, logging, monitoring, and technical security initiatives
- Identify opportunities to automate repetitive IT and compliance processes and improve operational efficiency
במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.
מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.
ירושלים
ערב