Security Governance & Compliance Specialist

CiscoSan José, San JoséOn-siteFull-timeMid level, 2–5 yearsListed 16 hours ago

Apply now

About this role

Splunk is here to build a safer and more resilient digital world. The world’s leading enterprises use our unified security and observability platform to keep their digital systems secure and reliable.

Join Splunk’s Tech Compliance team, where we lead security and compliance programs that are integral to the trust customers place in Splunk. We build consultative partnerships with product owners, engineering, and security teams to drive risk mitigation and controls management across commercial frameworks and cloud environments, while building more automated and scalable compliance operations.

Your Impact

As a Security Governance & Compliance Specialist, you will bridge security policy and engineering execution. You will lead and support commercial security compliance programs, strengthen audit readiness, and build automation that improves the quality, speed, and scalability of evidence collection and compliance operations.

You will partner closely with wide array of teams, including but not limited to; product, engineering, DevOps, and security, to translate sophisticated compliance directives into practical implementation guidance, integrate controls into engineering workflows, and help maintain a continuous compliance posture across Splunk’s cloud environments.

Key Responsibilities

- Plan and execute security and technology audit from planning through to certification or report delivery, including auditor coordination, evidence collection, control mapping, remediation tracking, and stakeholder communication.

- Serve as main contact for internal and external auditors for assigned commercial compliance programs.

- Conduct gap assessments and audit readiness reviews for products, services, and new regulatory requirements; supervise remediation activities through closure.

- Translate compliance requirements into clear, actionable guidance for engineering, product, and operational teams.

- Partner with DevOps and Engineering to incorporate compliance controls, validation, and evidence generation into CI/CD and operational workflows.

- Design, build, and run automated solutions for collecting, and validating audit evidence, as well as simplifying audit workstreams.

- Support continuous monitoring activities to maintain compliance posture between audit cycles.
- Help define, implement, and monitor controls for enterprise AI tools and AI/ML systems, including their secure use, configuration, and governance.
- Contribute to the ongoing evolution of scalable, AI centric, automation-forward compliance processes.

Minimum Qualifications

- Bachelor’s degree plus 5+ years of experience in technical compliance, security, risk, audit, or a related field; equivalent practical experience may be considered.
- Direct experience supporting or leading audit or certification programs from scoping through delivery, including control mapping, evidence collection, remediation, and auditor engagement; practical experience with commercial security and privacy frameworks, including SOC 1 & 2, ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, and HIPAA.
- Experience building and implementing automation for evidence collection, compliance testing, control validation, or compliance reporting; solid understanding of security controls and governance in cloud-hosted environments, including AWS, GCP, and Azure.
- Engineering fluency, including experience with scripting or automation tools such as Python, Go, Terraform, CloudFormation, or similar technologies.
- Strong written and verbal communication skills, with the ability to engage auditors, engineers, and senior leaders effectively.

Preferred Qualifications

- Experience with ISO/IEC 42001, AI governance concepts, and emerging AI risk-management frameworks.

- Familiarity with CSA STAR, PCI DSS, and commercial privacy or customer-assurance programs.

- Experience integrating compliance controls and evidence generation into CI/CD pipelines or infrastructure-as-code workflows.

- Proven program-management skills, including coordinating multi-functional workstreams and delivering under evolving priorities.

- Relevant certifications such as CISA, CISSP, CISM, CRISC, or cloud security certifications.

Why Cisco?

At Cisco, we’re revolutionizing how data and infrastructure connect and protect organizations in the AI era – and beyond. We’ve been innovating fearlessly for 40 years to create solutions that power how humans and technology work together across the physical and digital worlds. These solutions provide customers with unparalleled security, visibility, and insights across the entire digital footprint.

Fueled by the depth and breadth of our technology, we experiment and create meaningful solutions. Add to that our worldwide network of doers and experts, and you’ll see that the opportunities to grow and build are limitless. We work as a team, collaborating with empathy to make really big things happen on a global scale. Because our solutions are everywhere, our impact is everywhere.

We are Cisco, and our power starts with you.