Senior Specialist Security and Operations Compliance | 31407

Finance & Accounting Atlanta, Georgia San Diego, California Santa Clara, California Kirkland, Washington Waltham, Massachusetts


Senior Specialist, Security & Operations Compliance 


Work matters. It’s where we spend a third of our lives, and fortunately, the workplace of the future is going to be a great place. We’re dedicated to bringing that to life for people everywhere. That’s why we put people at the heart of everything we do.

People matter. Our people have a passion for learning, building, and innovating. Whether you’re an engineer, a sales professional, a finance professional, or anything in-between, our roles aim to provide each person with meaningful impact and plenty of space to grow.

The Senior Specialist, Security & Compliance will be responsible for contributing to and executing on the Foundational Certification strategy as defined by Audit Risk and Compliance leadership.  This consists of maintaining existing third-party assurance programs already held by ServiceNow, as well as driving the analysis and adoption of new programs as directed by ServiceNow leadership. This role will work collaboratively with members of the Enterprise Risk, Compliance Engineering, Sales, Security, and Operations teams.

This role will also effectively monitor ServiceNow’s controls by understanding intent, and implementation of controls, as well as drive changes within the organization through effective testing. The successful candidate must be reliable, resourceful and have a “can-do” attitude. 

What you get to do in this role:

  • Support and lead various third-party assurance programs including ISO, SOC, PCI and more.
  • Perform activities to help measure and monitor compliance with company policies and procedures
  • Facilitate customer and certifier requests and information gathering for audit activities and lead onsite audits.
  • Successfully project manage and drive testing activities across various teams within the organization
  • Contribute in enhancing our GRC tool and processes to meet compliance business needs

In order to be successful in this role, we need someone who has:

  • Minimum 7 to 9+ years working in the field of compliance or audit
  • Practical working involvement, and successful history of facilitating and delivering PCI-DSS certifications
  • Deep understanding of common certifications and attestations to include ISO 27001, PCI-DSS, SSAE18 SOC 1, SOC2, HITRUST, ISO 27701
  • Prior experience of working in the Security and Compliance group at a SaaS/Cloud company or with Security & Risk practice of a Big 4 firm
  • Relevant professional certifications such as CISSP, CISA, CISM, CIPP, GIAC, PMP
  • Strong organizational skills, attention to detail and ability to multi task
  • Prior experience with GRC systems
  • Ability to understand the intent of compliance requirements to provide effective and meaningful analysis
  • Excellent verbal and written skills
  • Be able to work effectively with other members of the GRC organization to drive results, to include a remote team

Work Environment

We provide competitive compensation, generous benefits and a professional atmosphere. This is a very collaborative and inclusive work environment where individuals strong on aptitude and attitude will have an opportunity to grow their professional careers through working with some of the most advanced technology and talented developers in the business.



ServiceNow is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, national origin, age, disability, gender identity, or veteran status. If you are an individual with a disability and require a reasonable accommodation to complete any part of the application process, or are limited in the ability or unable to access or use this online application process and need an alternative method for applying, you may contact us at for assistance.