Splunk is here to build a safer and more resilient digital world. The world’s leading enterprises use our unified security and observability platform to keep their digital systems secure and reliable.
Join Splunk’s Tech Compliance team, where we lead security and compliance programs that are integral to the trust customers place in Splunk. We build consultative partnerships with product owners, engineering, and security teams to drive risk mitigation and controls management across commercial frameworks and cloud environments, while building more automated and scalable compliance operations.
Your Impact
As a Security Governance & Compliance Specialist, you will bridge security policy and engineering execution. You will lead and support commercial security compliance programs, strengthen audit readiness, and build automation that improves the quality, speed, and scalability of evidence collection and compliance operations.
You will partner closely with wide array of teams, including but not limited to; product, engineering, DevOps, and security, to translate sophisticated compliance directives into practical implementation guidance, integrate controls into engineering workflows, and help maintain a continuous compliance posture across Splunk’s cloud environments.
Key Responsibilities
- Plan and execute security and technology audit from planning through to certification or report delivery, including auditor coordination, evidence collection, control mapping, remediation tracking, and stakeholder communication.
- Serve as main contact for internal and external auditors for assigned commercial compliance programs.
- Conduct gap assessments and audit readiness reviews for products, services, and new regulatory requirements; supervise remediation activities through closure.
- Translate compliance requirements into clear, actionable guidance for engineering, product, and operational teams.
- Partner with DevOps and Engineering to incorporate compliance controls, validation, and evidence generation into CI/CD and operational workflows.
- Design, build, and run automated solutions for collecting, and validating audit evidence, as well as simplifying audit workstreams.
- Support continuous monitoring activities to maintain compliance posture between audit cycles.
- Help define, implement, and monitor controls for enterprise AI tools and AI/ML systems, including their secure use, configuration, and governance.
- Contribute to the ongoing evolution of scalable, AI centric, automation-forward compliance processes.
Minimum Qualifications
- Bachelor’s degree plus 5+ years of experience in technical compliance, security, risk, audit, or a related field; equivalent practical experience may be considered.
- Direct experience supporting or leading audit or certification programs from scoping through delivery, including control mapping, evidence collection, remediation, and auditor engagement; practical experience with commercial security and privacy frameworks, including SOC 1 & 2, ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, and HIPAA.
- Experience building and implementing automation for evidence collection, compliance testing, control validation, or compliance reporting; solid understanding of security controls and governance in cloud-hosted environments, including AWS, GCP, and Azure.
- Engineering fluency, including experience with scripting or automation tools such as Python, Go, Terraform, CloudFormation, or similar technologies.
- Strong written and verbal communication skills, with the ability to engage auditors, engineers, and senior leaders effectively.
Preferred Qualifications
- Experience with ISO/IEC 42001, AI governance concepts, and emerging AI risk-management frameworks.
- Familiarity with CSA STAR, PCI DSS, and commercial privacy or customer-assurance programs.
- Experience integrating compliance controls and evidence generation into CI/CD pipelines or infrastructure-as-code workflows.
- Proven program-management skills, including coordinating multi-functional workstreams and delivering under evolving priorities.
- Relevant certifications such as CISA, CISSP, CISM, CRISC, or cloud security certifications.
Why Cisco?
At Cisco, we’re revolutionizing how data and infrastructure connect and protect organizations in the AI era – and beyond. We’ve been innovating fearlessly for 40 years to create solutions that power how humans and technology work together across the physical and digital worlds. These solutions provide customers with unparalleled security, visibility, and insights across the entire digital footprint.
Fueled by the depth and breadth of our technology, we experiment and create meaningful solutions. Add to that our worldwide network of doers and experts, and you’ll see that the opportunities to grow and build are limitless. We work as a team, collaborating with empathy to make really big things happen on a global scale. Because our solutions are everywhere, our impact is everywhere.
We are Cisco, and our power starts with you.
Skills Required
- Bachelor’s degree plus 5 or more years of experience in technical compliance, security, risk, audit, or a related field; equivalent practical experience may be considered.
- Experience supporting or leading audit or certification programs from scoping through delivery, including control mapping, evidence collection, remediation, and auditor engagement.
- Practical experience with commercial security and privacy frameworks, including SOC 1, SOC 2, ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, and HIPAA.
- Experience building and implementing automation for evidence collection, compliance testing, control validation, or compliance reporting.
- Understanding of security controls and governance in cloud-hosted environments, including AWS, GCP, and Azure.
- Engineering fluency, including experience with Python, Go, Terraform, CloudFormation, or similar technologies.
- Strong written and verbal communication skills with auditors, engineers, and senior leaders.
- Experience with ISO/IEC 42001, AI governance concepts, and emerging AI risk-management frameworks.
- Familiarity with CSA STAR, PCI DSS, and commercial privacy or customer-assurance programs.
- Experience integrating compliance controls and evidence generation into CI/CD pipelines or infrastructure-as-code workflows.
- Program-management experience coordinating multifunctional workstreams and delivering under evolving priorities.
- Relevant certifications such as CISA, CISSP, CISM, CRISC, or cloud security certifications.
Cisco Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Cisco and has not been reviewed or approved by Cisco.
-
Healthcare Strength — Health coverage is described as broad, with medical options including PPOs, high-deductible plans, and regional HMOs. Feedback suggests robust wellness and mental-health resources, with some locations offering on-site support and second medical opinions.
-
Leave & Time Off Breadth — Time off is highlighted through paid holidays, paid time off, and additional recharge days such as “Days for Me,” with generous volunteer time also mentioned. Feedback suggests these programs help support rest, volunteering, and critical life events.
-
Parental & Family Support — Parental and family support appears extensive, including paid child-bonding leave, family medical leave, and caregiving resources. Observations also point to family-planning assistance and adoption or surrogacy support in some regions.
Cisco Insights
What We Do
Cisco (NASDAQ: CSCO) enables people to make powerful connections--whether in business, education, philanthropy, or creativity. Cisco hardware, software, and service offerings are used to create the Internet solutions that make networks possible--providing easy access to information anywhere, at any time. Cisco was founded in 1984 by a small group of computer scientists from Stanford University. Since the company's inception, Cisco engineers have been leaders in the development of Internet Protocol (IP)-based networking technologies. Today, with more than 71,000 employees worldwide, this tradition of innovation continues with industry-leading products and solutions in the company's core development areas of routing and switching, as well as in advanced technologies such as home networking, IP telephony, optical networking, security, storage area networking, and wireless technology. In addition to its products, Cisco provides a broad range of service offerings, including technical support and advanced services. Cisco sells its products and services, both directly through its own sales force as well as through its channel partners, to large enterprises, commercial businesses, service providers, and consumers.
.png)
.jpg)





