Staff Security Engineer (Compliance) - Moveworks
ServiceNow · Mountain View, US
Skills in this posting
Extracted from the posting text by the instrument — the demand side, read literally.
The posting
Security compliance is still mostly manual work: screenshots, spreadsheets, and evidence pulled together by hand in the weeks before an audit. We want to run it the opposite way.
This role builds the automation so evidence collection and control monitoring happen continuously, and we could pass an audit in any given month because the system is always current. You will treat compliance as code, and you will care about getting the controls right, not just getting them checked.
Your mission will be to replace legacy compliance processes with intelligent, automated platforms that scale effortlessly.
We want someone who looks at traditional compliance and thinks, "There has to be a better way." You are an AI-native engineer who knows how and when to apply AI across the entire compliance engineering lifecycle—from writing software and automating evidence collection to validating controls, generating documentation, streamlining audits, and building the next generation of compliance automation.
This is an IC tech lead role. You will be hands on.
You will own the software engineering behind our compliance certifications, leading technical engagements with external auditors for ISO 27001, ISO 27017, ISO 27018, ISO 27701, ISO 42001, SOC 2 Type 2, CSA STAR Level 2, and future certifications. Rather than treating audits as periodic projects, you will build and operate systems that keep our controls continuously validated and our evidence continuously available. Success means audits become a confirmation of how we already operate.
Your vision will color the blueprint of our compliance strategy, propelling Moveworks not just to meet the future but to define it. Ready to make a monumental impact? Join us and transform the essence of compliance at Moveworks.
What you get to do in this role
Build and own automated evidence collection pipelines that integrate with cloud infrastructure, identity providers, source control, ticketing systems, and other security tooling.
Design and implement continuous control monitoring, ensuring compliance is measured in real time rather than only during audit periods.
Challenge the status quo of compliance. Replace manual, paper-driven processes with software and engineering-first systems. We're looking for builders who believe compliance should be automated, elegant, and designed—not buried in paperwork.
Own the technical strategy for future certifications and regulatory frameworks, evaluating new requirements and designing scalable solutions that minimize operational overhead.
Use AI where it fits. Apply LLMs and agents to map controls to evidence, validate it, and flag drift.
Spearhead compliance initiatives such as ISO 27001, ISO 27017, ISO 27018, ISO 27701, ISO 42001, SOC 2 Type 2, CSA STAR Level 2, NIST 800-171, GDPR, etc.
Navigate auditor relationships with adept expertise, ensuring smooth and compliant audits.
Lead and drive the charge in partnering with key stakeholders to ensure compliance and controls are effectively implemented, and any findings are remediated.
Create and transform documentation such as policies, procedures, and other compliance written material.
To be successful in this role you have
US Citizenship required
8+ years of experience in information security roles, with a specific focus on security compliance and risk management.
Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field. Advanced degrees or certifications (e.g., CISM, CISSP, CISA) are preferred.
A bias to remove manual work. When you see a recurring manual task, your instinct is to automate it away.
Demonstrated experience in developing, managing, and implementing security policies and compliance frameworks such as ISO 27001, ISO 42001, NIST, GDPR, and SOC 2 Type 2.
Knowledge of security principles, controls, and technologies/products.
Familiarity with cloud security practices and cloud provider compliance standards (AWS, Azure, GCP).
Expertise with AWS services.
Exceptional communication, written, and presentation skills capable of engaging a wide range of stakeholders.
Skills in identifying security risks, implementing mitigation strategies, and driving remediation end-to-end.
Experience with navigating international and domestic security regulations.
Work Personas
We approach our distributed world of work with flexibility and trust. Work personas (flexible, remote, or required in office) are categories that are assigned to ServiceNow employees depending on the nature of their work and their assigned work location. Learn more here . To determine eligibility for a work persona, ServiceNow may confirm the distance between your primary residence and the closest ServiceNow office using a third-party service.
Equal Opportunity Employer
ServiceNow is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, national origin, age, disability, gender identity, veteran status, or any other category protected by law. In addition, all qualified applicants with arrest or conviction records will be considered for employment in accordance with legal requirements.
Accommodations
We strive to create an accessible and inclusive experience for all candidates. If you require a reasonable accommodation to complete any part of the application process, or are unable to use this online application and need an alternative method to apply, please contact globaltalentss@servicenow.com for assistance.
Export Control Regulations
For positions requiring access to controlled technology subject to export control regulations, including the U.S. Export Administration Regulations (EAR), ServiceNow may be required to obtain export control approval from government authorities for certain individuals. All employment is contingent upon ServiceNow obtaining any export license or other approval that may be required by relevant export control authorities.
From Fortune. ©2026 Fortune Media IP Limited. All rights reserved. Used under license.
Excerpt from the original listing. The full, current text lives at the source. Read and apply there →
The PivotHop read
- What a security engineer actually earnsmedian, seniority, by country
- What security engineers do insteadevery measured route out
- All open security engineer rolesthe full board
Where these skills also reach
Adjacent occupations measured from the same postings — readiness is what a security engineer’s profile already covers.
- 15 open penetration tester roles66% readiness from security engineer
- 54 open network engineer roles62% readiness from security engineer
- 250 open systems administrator roles47% readiness from security engineer
- 250 open solutions architect roles38% readiness from security engineer
More security engineer roles
- Staff Cloud Security EngineerTemporal Technologies · USA
- OT Security Engineer Biogasanlagen mit Homeoffice (m/w/d)PolyTALENT GmbH · Lohne (Oldenburg), Niedersachsen, Deutschland
- Security Engineer - ProductWizinc · Berlin; Munich
- Information Security Engineer (CISO track)Tangible · London
- Cybersecurity Engineer (F/M/D)Omnisent · Munich
Backfilled listing, refreshed with the nightly scrape; the employer has not claimed it yet. Are you the employer? Claim this listing and it can be featured to the candidates whose skills already reach it, first month free.