Staff Security Engineer (Compliance) - Moveworks

ServiceNowMountain View, CA

About The Position

Security compliance is still mostly manual work: screenshots, spreadsheets, and evidence pulled together by hand in the weeks before an audit. This role builds the automation so evidence collection and control monitoring happen continuously, and we could pass an audit in any given month because the system is always current. This role treats compliance as code, and cares about getting the controls right, not just getting them checked. The mission is to replace legacy compliance processes with intelligent, automated platforms that scale effortlessly. This role is for someone who looks at traditional compliance and thinks, "There has to be a better way." This is an AI-native engineer who knows how and when to apply AI across the entire compliance engineering lifecycle—from writing software and automating evidence collection to validating controls, generating documentation, streamlining audits, and building the next generation of compliance automation. This is an IC tech lead role. You will be hands on. You will own the software engineering behind our compliance certifications, leading technical engagements with external auditors for ISO 27001, ISO 27017, ISO 27018, ISO 27701, ISO 42001, SOC 2 Type 2, CSA STAR Level 2, and future certifications. Rather than treating audits as periodic projects, you will build and operate systems that keep our controls continuously validated and our evidence continuously available. Success means audits become a confirmation of how we already operate. Your vision will color the blueprint of our compliance strategy, propelling Moveworks not just to meet the future but to define it. Ready to make a monumental impact? Join us and transform the essence of compliance at Moveworks.

Requirements

  • US Citizenship required
  • 8+ years of experience in information security roles, with a specific focus on security compliance and risk management.
  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field.
  • A bias to remove manual work. When you see a recurring manual task, your instinct is to automate it away.
  • Demonstrated experience in developing, managing, and implementing security policies and compliance frameworks such as ISO 27001, ISO 42001, NIST, GDPR, and SOC 2 Type 2.
  • Knowledge of security principles, controls, and technologies/products.
  • Familiarity with cloud security practices and cloud provider compliance standards (AWS, Azure, GCP).
  • Expertise with AWS services.
  • Exceptional communication, written, and presentation skills capable of engaging a wide range of stakeholders.
  • Skills in identifying security risks, implementing mitigation strategies, and driving remediation end-to-end.
  • Experience with navigating international and domestic security regulations.

Nice To Haves

  • Advanced degrees or certifications (e.g., CISM, CISSP, CISA) are preferred.

Responsibilities

  • Build and own automated evidence collection pipelines that integrate with cloud infrastructure, identity providers, source control, ticketing systems, and other security tooling.
  • Design and implement continuous control monitoring, ensuring compliance is measured in real time rather than only during audit periods.
  • Challenge the status quo of compliance. Replace manual, paper-driven processes with software and engineering-first systems.
  • Own the technical strategy for future certifications and regulatory frameworks, evaluating new requirements and designing scalable solutions that minimize operational overhead.
  • Use AI where it fits. Apply LLMs and agents to map controls to evidence, validate it, and flag drift.
  • Spearhead compliance initiatives such as ISO 27001, ISO 27017, ISO 27018, ISO 27701, ISO 42001, SOC 2 Type 2, CSA STAR Level 2, NIST 800-171, GDPR, etc.
  • Navigate auditor relationships with adept expertise, ensuring smooth and compliant audits.
  • Lead and drive the charge in partnering with key stakeholders to ensure compliance and controls are effectively implemented, and any findings are remediated.
  • Create and transform documentation such as policies, procedures, and other compliance written material.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service