Staff Security Engineer (Compliance) - Moveworks

ServiceNowMountain View, CA
Remote

About The Position

This role focuses on automating security compliance processes, moving away from manual evidence collection and control monitoring. The goal is to treat compliance as code, ensuring continuous adherence to controls and making audits a confirmation of existing operations. The position involves building intelligent, automated platforms to replace legacy compliance methods, leveraging AI and LLMs throughout the compliance engineering lifecycle. This is an individual contributor tech lead role that requires hands-on work. The role will own the software engineering for compliance certifications, including ISO 27001, ISO 27017, ISO 27018, ISO 27701, ISO 42001, SOC 2 Type 2, CSA STAR Level 2, and others. The objective is to build and operate systems for continuous control validation and evidence availability, making audits a confirmation of current operations. The individual will shape the company's compliance strategy and define the future of compliance automation.

Requirements

  • US Citizenship required
  • 8+ years of experience in information security roles, with a specific focus on security compliance and risk management.
  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field.
  • A bias to remove manual work. When you see a recurring manual task, your instinct is to automate it away.
  • Demonstrated experience in developing, managing, and implementing security policies and compliance frameworks such as ISO 27001, ISO 42001, NIST, GDPR, and SOC 2 Type 2.
  • Knowledge of security principles, controls, and technologies/products.
  • Familiarity with cloud security practices and cloud provider compliance standards (AWS, Azure, GCP).
  • Expertise with AWS services.
  • Exceptional communication, written, and presentation skills capable of engaging a wide range of stakeholders.
  • Skills in identifying security risks, implementing mitigation strategies, and driving remediation end-to-end.
  • Experience with navigating international and domestic security regulations.

Nice To Haves

  • Advanced degrees or certifications (e.g., CISM, CISSP, CISA) are preferred.

Responsibilities

  • Build and own automated evidence collection pipelines that integrate with cloud infrastructure, identity providers, source control, ticketing systems, and other security tooling.
  • Design and implement continuous control monitoring, ensuring compliance is measured in real time rather than only during audit periods.
  • Challenge the status quo of compliance. Replace manual, paper-driven processes with software and engineering-first systems.
  • Own the technical strategy for future certifications and regulatory frameworks, evaluating new requirements and designing scalable solutions that minimize operational overhead.
  • Use AI where it fits. Apply LLMs and agents to map controls to evidence, validate it, and flag drift.
  • Spearhead compliance initiatives such as ISO 27001, ISO 27017, ISO 27018, ISO 27701, ISO 42001, SOC 2 Type 2, CSA STAR Level 2, NIST 800-171, GDPR, etc.
  • Navigate auditor relationships with adept expertise, ensuring smooth and compliant audits.
  • Lead and drive the charge in partnering with key stakeholders to ensure compliance and controls are effectively implemented, and any findings are remediated.
  • Create and transform documentation such as policies, procedures, and other compliance written material.

Benefits

  • Flexible scheduling
  • Remote work options
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service