Skip to content

Security Engineering Lead

Dovetail Sydney, NSW, AustraliaAugust 24, 2026
Hybrid
Full-time
GRC
Management

Dovetail is the Customer Intelligence Platform for the entire organization. We unify fragmented feedback from every touchpoint, including sales calls, support tickets, and research, into a single AI-powered intelligence layer that empowers every team to build, sell, and serve with confidence. Founded in 2017, we are a team of 100+ across our offices in Sydney and San Francisco, working with thousands of teams from Fortune 500 companies to the world’s most innovative startups.

The best never guess. We help teams turn the noise of thousands of customer interactions into the signal required to move faster, prioritize better, and drive revenue.

The role

Roughly 15% of the Fortune 500 trust us with their customer data. That trust is the product. As our Security & Compliance Lead you own the governance, risk and compliance function that proves it, end to end, across SOC 2, ISO/IEC 27001 and ISO/IEC 42001.

This is a compliance role in a company that ships every day. The certifications matter, but so does what sits underneath them, and we would rather automate a control than evidence it by hand twice a year. You will start with deep GRC ownership and we expect you to push hard into security engineering from there, building the tooling and automation that makes compliance a by-product of how we work rather than a quarterly scramble. Dovetail is one of Australia's most AI forward engineering teams and you will have the runway, the tooling and the support to make that move.

You will also be shaping what governance looks like for AI products that are genuinely new. We were early to ISO/IEC 42001 and the questions our enterprise customers ask about model use, data handling and agentic workflows do not have settled answers yet. You get to write them.

This is an individual contributor role reporting into engineering leadership. It is in person first (4 days a week) from our Surry Hills HQ.

What you'll do here

  • Own security risk. Maintain the risk register, run risk assessments on new products and features, drive mitigations to close with the teams who own them, and manage third party and vendor risk as our supply chain grows.

  • Own our compliance programme. Run SOC 2, ISO/IEC 27001 and ISO/IEC 42001 certification and surveillance cycles end to end, including scoping, control design, evidence, internal audit and the external auditor relationship.

  • Be the technical voice in enterprise deals. Handle security questionnaires, customer trust reviews and due diligence for some of the largest companies in the world, and work with sales and legal to unblock them quickly.

  • Automate the boring parts. Build and improve tooling that collects evidence, monitors control drift and reports posture continuously, working alongside platform engineering rather than handing them a ticket.

  • Grow into hands-on security engineering. Pick up detection and response tooling, cloud security posture work across AWS, and vulnerability management, with the support to build genuine engineering depth.

  • Set the standard for AI governance. Define how we assess, document and control AI systems, model providers and agentic features, and stay ahead of where frameworks like the EU AI Act and the NIST AI Risk Management Framework are heading.

  • Be part of security incident response. Contribute to our response process and help mature how we detect, escalate and learn from incidents.

  • Build the security culture. Work with and mentor engineers, product and design so that good security decisions get made without you in the room.

Your background

  • Deep GRC experience. You have run compliance programmes against SOC 2 and ISO/IEC 27001 in a software business, not just supported them. You know the difference between a control that satisfies an auditor and a control that actually reduces risk, and you care about both.

  • Comfortable with AI compliance, or hungry to own it. Familiarity with ISO/IEC 42001 and emerging AI assurance frameworks is a real advantage. If you do not have it yet, you are excited by the chance to become one of the people who does.

  • Technical credibility. You can hold your own with engineers on cloud architecture and security controls. Exposure to AWS security tooling such as GuardDuty, Security Hub, Inspector and Detective, and to EKS, TypeScript or infrastructure as code like Pulumi or Terraform, will set you up well here.

  • Wants to build, not just assess. You are looking for a role where the natural answer to a manual process is to write something that removes it, and you want to spend the next few years getting materially more technical.

  • Enterprise fluency. You have been across the table from large customers, their procurement teams and their security reviewers, and you know how to move a deal forward without overcommitting.

  • You are pragmatic and flexible. Like your new teammates, you are used to doing what is necessary to get the job done. You will need to be comfortable with ambiguity, be resourceful in solving problems, and adjust to shifting deadlines and goals.

  • When you do it, you nail it. You share our keen eye for quality. What you ship is top notch, and you cut scope before cutting quality.

  • Excellent, concise communicator. You can explain a risk to an engineer, a board member and a customer's CISO on the same day, and articulate effort versus impact clearly to each of them.

Why you'll love it here

We hire smart people and look after them well! Here's the deal:

📈 Equity for everyone. Competitive base salary plus options, so every builder is aligned on long-term impact.

🏢 A place to do your best work, wherever you are. Our Sydney office is built for in-person first collaboration. Our US team runs on a flexible remote setup. Either way, you've got what you need.

🤝 Built in connection. Join a Doveclub, bond with your team regularly, and celebrate the small wins, big milestones, and cultural moments with the whole company.

📚 Learn and thrive. Flexible L&D and wellness benefits, choose between a generous $3000 L&D allowance, or up to $1000 on wellness.

🌴 Time to recharge. Four weeks of accrued leave, floating public holidays, and gifted bonus Kit Kat days sprinkled throughout the year.

🌍 Four weeks from anywhere. Up to four weeks a year doing your job from anywhere in the world. Split it up or use it all at once.

🍼 Generous parental leave. We offer 20 weeks for primary caregivers, 12 weeks for secondary caregivers, plus return-to-work support.

🎉 Four weeks at four years. Four years is a long time in tech, and we value loyalty. Take an additional four weeks off to reset and recharge.

🩺 Stellar US benefits. Comprehensive health, dental, vision, 401(k), and more through Sequoia.

At Dovetail, we're building a place where every team member feels supported and valued. We celebrate individualism and want you to show up as your authentic self every day. It’s no secret that diversity builds the best teams, large or small, so we highly encourage applications from people who identify as part of an underrepresented group.

On AI: We expect candidates to already be embedding AI into their day-to-day work. We look for people who are thoughtful and pragmatic in how they use AI—knowing when to leverage it, how to direct it effectively, and how to apply it to improve the quality, speed, and impact of their work.

Job Details

Experience

Management

Tools & Tech

AWS
EKS
GuardDuty
Pulumi
Security Hub
Terraform
TypeScript