Staff Security Engineer (Compliance) - Moveworks
RemoteUnited States
Job Summary
Build automated evidence collection pipelines integrating with cloud infrastructure, identity providers, and security tooling to replace manual compliance processes. Design continuous control monitoring systems that validate evidence in real time rather than during periodic audits. Spearhead initiatives for ISO 27001, SOC 2 Type 2, CSA STAR Level 2, and other frameworks while navigating auditor relationships and driving stakeholder remediation. Apply LLMs and agents to map controls, validate evidence, and flag drift. Lead technical strategy for future certifications and regulatory frameworks, ensuring controls are engineered as code.
Required Qualifications
- US Citizenship
- 8+ years of experience in information security roles, with a specific focus on security compliance and risk management
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related field
- A bias to remove manual work
- Demonstrated experience in developing, managing, and implementing security policies and compliance frameworks such as ISO 27001, ISO 42001, NIST, GDPR, and SOC 2 Type 2
- Knowledge of security principles, controls, and technologies/products
- Familiarity with cloud security practices and cloud provider compliance standards (AWS, Azure, GCP)
- Expertise with AWS services
- Exceptional communication, written, and presentation skills capable of engaging a wide range of stakeholders
- Skills in identifying security risks, implementing mitigation strategies, and driving remediation end-to-end
- Experience with navigating international and domestic security regulations
Desired Qualifications
- Advanced degrees or certifications (e.g., CISM, CISSP, CISA)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.