Data Centre Security Compliance Public Sector Specialist at Cloudflare ensuring compliance with government regulations and managing audits. Overseeing access and security policy alignment.
Responsibilities
Serve as the Subject Matter Expert (SME) on NIST 800-53 control families and FedRAMP requirements.
Manage Cloudflare’s continuous monitoring program, inclusive of annual assessments and significant change requests.
Collect, validate, and organize FedRAMP evidence and artifacts to present to auditors, FedRAMP customers, and the FedRAMP PMO.
Help guide our overall security policy and governance architecture to ensure alignment with evolving government regulations.
Orchestrate end-to-end audit activities for standards such as PCI, SOC2, ISO, NIST, and FedRAMP.
Coordinate with auditors to manage data center access, compliance certificate collection, and evidence defense.
Work cross-functionally with Engineering, Legal, Product, and Operational teams to maintain management and technical controls.
Support compliance and regulatory projects, including implementation of new legislation / regulation.
Execute monthly Periodic Access Reviews (PARs): Compare portal user lists against ACLs to ensure least-privilege access is maintained across all data centers.
Manage the lifecycle of portal access: Auditing access, provisioning/deprovisioning users, and maintaining accurate documentation.
Oversee physical access requests to data centers and ensure strict adherence to security policies.
Drive the resolution of daily DCSC Jira tickets for portal access, physical access, audits, and site decommissioning.
Automate and streamline access review processes where possible, utilizing standard communication templates to site managers.
Own, influence, and orchestrate relationships within the partner Offering teams that can help drive Cloudflare offerings and strategic positioning.
Monitor and implement changes to individual accountability regime requirements (such as UK, Ireland, Singapore and Australia).
Maintain centralized documentation, databases, dashboards, and reporting mechanisms to track compliance health.
Requirements
3-6 years working in Security Compliance, Information Security, or Risk Management.
Deep familiarity with all NIST 800-53 control families and FedRAMP requirements
Ability to work closely with auditors and articulate technical concepts
Experience in auditing of network, operating system, and application security
Proven experience managing an audit throughout the full audit lifecycle (from readiness to final report)
Familiarity with additional security standards and frameworks such as ISO 27000, SOC 2, PCI DSS, ISMAP and IRAP.
Ability to work cross-functionally with internal stakeholders and strong communications skills
High tolerance for ambiguity and ability to work efficiently and independently in a fast-paced, high-volume environment
Some travel may be required to engage with regulators and auditors
Certifications: CISSP, CIPP, CIPM, CIPT, CISA, or CRISC.
A relevant professional experience working with technology partners, alliances, or third-party vendors, ideally in the following disciplines: Data center Security Compliance, Access Management, audit administration at a leading high-tech company; offering management
Technical skills including the ability to understand (1) product roadmaps; (2) market trends and factors; and (3) complex partner requirements.
Strong technical proficiency with spreadsheet software (Excel/Google Sheets) including pivot tables and VLOOKUPs for data reconciliation.
Organized & Disciplined, with a strong focus on driving outcomes.
Preferred Prior experience with Data Centre Security Compliance disciplines and audit programs and past history working at a hyperscaler or high-growth tech company.
Preferred Superb organizational skills and demonstrated history managing complex processes including audit cycles, Facts gathering and analytical skills.
Benefits
Cloudflare is proud to be an equal opportunity employer.
Committed to providing equal employment opportunity for all people and value in both diversity and inclusiveness.
Reasonable accommodations to qualified individuals with disabilities.
Cybersecurity Sales Specialist driving transformational security outcomes for Fortune 250 accounts. Influencing C - suite leaders and closing large multi - region deals.
Expert Network Security Engineer at DXC Bulgaria, supporting network security services for enterprise customers. Collaborating on critical infrastructure and ensuring reliable service delivery in evolving environments.
Cyber Security Manager at Leonardo handling strategic cyber security for high - profile clients. Collaborating with C - Level executives and internal teams to develop risk - based security strategies across diverse sectors.
Systems Security Engineer ensuring the security of unmanned systems critical to Navy and Marine Corps operations. Develop security solutions to protect against cyber threats in contested environments.
Network Security Engineer maintaining network stability and security at Clearwater Paper. Responsible for operational support, troubleshooting, and security administration across enterprise networks.
Analista de Application Security Pleno ensuring code integrity and security at Evertec, a tech company for the financial sector in Brazil. Responsible for security scanning, remediation support, and CI/CD integration.
Senior Application Security Analyst ensuring code integrity and security at Evertec, leading security strategies and initiatives in software development.
Senior Principal Security Engineer at Workday acting as technical contact for Enterprise Security. Bridging cybersecurity strategy with hands - on execution to tackle complex security challenges.
Leitung des Sachgebiets Infrastruktur und Sicherheit mit Verantwortung für den Betrieb der technischen Basisdienste. Enger Austausch mit Amtsleitung und Fachbereichen zur IT - Strategie der Stadt Elmshorn.
As a Producer, support the Senior Producer in delivering AAA projects for Behaviour Interactive, a gaming industry leader. Collaborate with the leadership team to ensure high - quality product alignment.