Staff Security Engineer (Compliance)
Job description
About the role
You define how engineering shapes compliance and evidence integrity across the ServiceNow platform. You replace manual oversight with automated platforms that keep evidence perpetually current and audit-ready. Every audit becomes a verification of ongoing operation rather than a frantic collection effort. You view compliance as code and design systems that scale without adding friction to engineers. You will own the technical execution behind our certifications and lead engagements for external auditors across multiple frameworks. You build and operate systems that continuously validate controls while keeping evidence accessible at all times. Success is measured by audits that confirm existing practices instead of discovering gaps. You challenge existing approaches and replace paper-heavy workflows with software-driven, engineering-first solutions.
Key facts
What you'll do
Automate evidence collection pipelines that integrate cloud infrastructure, identity providers, source control, ticketing systems, and security tooling into a unified compliance fabric. Implement continuous control monitoring so that compliance is measured in real time instead of only during audit windows and manual checklists. Challenge existing compliance approaches by identifying manual dependencies and replacing paper-heavy workflows with software-driven, engineering-first alternatives. Define technical strategies for future certifications and regulatory frameworks, designing solutions that reduce operational overhead and recurring effort. Use artificial intelligence where appropriate to map controls to evidence, validate findings, detect drift, and assist in the generation of documentation and policy artifacts. Lead initiatives for ISO 27001, ISO 27017, ISO 27018, ISO 27701, ISO 42001, SOC 2 Type 2, CSA STAR Level 2, NIST 800-171, GDPR, and other relevant frameworks where compliance and security intersect. Manage auditor relationships to ensure smooth processes, timely responses, and clear resolution of observations or gaps. Produce and update compliance documentation, including policies, procedures, control artifacts, and implementation guides that support audit readiness. Partner with stakeholders to embed controls deeply into products and workflows while closing identified gaps quickly and sustainably. Drive an automation-first culture that eliminates repetitive manual tasks as soon as they appear and scales secure practices across teams.
Requirements
U.S. citizenship is required for this position and must be verified as part of the hiring process. Bring eight or more years of experience in information security, with a strong focus on security compliance, risk management, and control implementation. Hold a Bachelor's degree in a relevant technical field, with preferred advanced security credentials such as CISSP, CISM, or similar. Default to removing manual effort by automating recurring tasks instead of accepting them as inevitable constraints. Demonstrate hands-on experience with security policies and compliance frameworks such as ISO 27001, ISO 42001, NIST, GDPR, and SOC 2 Type 2 in complex environments. Show understanding of security principles, controls, and associated technologies and products that support secure system design. Exhibit fluency in cloud security practices and provider-specific compliance standards, including AWS and Azure, along associated attestations and service offerings. Maintain deep expertise with AWS services and operational experience deploying, operating, and securing workloads. Use strong communication, writing, and presentation skills to engage diverse stakeholders, from technical engineers to executive leadership. Ability to identify risks, define practical mitigations, and drive end-to-end remediation across teams and timelines while maintaining clarity and transparency. Navigate international and domestic security regulations with precision, ensuring that policies and technical implementations remain consistent and current.
Nice to have
Experience applying AI agents to compliance engineering and evidence validation, including prompt design, evaluation frameworks, and integration into existing workflows.
Practical notes
Logistics.
Location: Mountain View, US.
Engagement: Full-time.
Compensation: $224,900.00 per year.
Moveworks is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, national origin, age, disability, gender identity, veteran status, or any other protected category. Qualified applicants with arrest or conviction records will be considered in accordance with applicable law. If you require a reasonable accommodation to complete any part of this process, contact globaltalentss@servicenow.com for assistance.
What you'll do
- Meet the bar Practical notes