Cloudflare Logo

Cloudflare

IT Risk Management Specialist

Posted 3 Days Ago
Be an Early Applicant
Hybrid
Austin, TX
Senior level
Hybrid
Austin, TX
Senior level
The IT Risk Management Specialist manages IT audits and compliance programs, ensures adherence to frameworks, and enhances data governance. They lead teams in audit processes, design controls, and collaborate across departments to mitigate risk and improve compliance.
The summary above was generated by AI
Available Locations: Austin TX
About the role
The IT Risk Management Specialist is a critical role within the Enterprise Operations organization, reporting to the Sr. IT Operations Manager. This individual will be the driving force behind the organization's adherence to IT compliance frameworks and data governance best practices, primarily within the Office of the CIO and Enterprise Operations.
The Specialist will be responsible for leading recurring IT system audits, designing and implementing robust data governance processes, and ensuring continuous compliance with ISO, SOX, SOC, and FedRAMP control requirements. This role requires a seasoned IT audit and compliance professional who can effectively collaborate with cross-functional teams to mitigate risk, drive continuous improvement, and ensure data quality and integrity across the enterprise.
Key Responsibilities
  • IT Audit & Compliance Program Management:
    • Lead and support recurring IT system audits, ensuring compliance verification and adherence to Electronic Audit Evidence (EAE) requirements.
    • Plan, execute, and document audit testing activities, including Tests of Design (TODs), Tests of Effectiveness (TOEs), and Quarterly Access Reviews (QARs).
    • Design and operationalize recurring audit procedures, Standard Operating Procedures (SOPs), and evidence collection frameworks for SOX, FedRAMP, and internal governance.
    • Assist in external audit walkthroughs, control documentation preparation, and alignment of evidence with auditor expectations.
  • Governance & Control Implementation:
    • Monitor, assess, and enforce compliance with SOX, SOC, and internal IT General Control (ITGC) requirements, driving continuous improvement and remediation of identified gaps.
    • Design, implement, and maintain FedRAMP-related controls for IT systems, ensuring alignment with NIST 800-53 security and privacy controls.
    • Contribute to the development and maintenance of a unified IT compliance framework, integrating requirements from ISO 27001, SOC 2, FedRAMP, and internal risk objectives to reduce audit fatigue.
  • Data Governance & Quality:
    • Lead the design, implementation, and enhancement of Data Governance processes, including facilitating stakeholder alignment and developing policy documentation.
    • Lead data stewardship initiatives and promote the ownership of data quality and security best practices across the enterprise.
  • Training & Collaboration:
    • Collaborate with cross-functional teams (IT Security, Infrastructure, Data Owners) to remediate compliance gaps and uphold governance standards.
    • Assist in training efforts for QAR owners, control performers, and IT stakeholders on evidence expectations, validation procedures, and governance alignment.
Desirable Skills, Knowledge, and Experience:
  1. Experience: 6+ years of progressive IT audit and compliance experience, preferably in a large enterprise or highly regulated environment.
  2. Framework Expertise: Hands-on experience with SOX, SOC, FedRAMP, and PCI frameworks, including the implementation and auditing of ITGCs and system security controls.
  3. Technical Knowledge: Working knowledge of industry-recognized frameworks such as NIST 800-53 (FedRAMP), ISO/IEC 27001 (including Annex A controls), and COBIT, with proven ability to map controls for unified compliance strategies.
  4. Risk Management: Strong foundation in IT risk management, governance, and data protection principles, with a demonstrated ability to identify compliance gaps and design effective controls.
  5. Process & Documentation: Proficiency in process design and documentation, including the ability to develop and optimize workflows, policies, and robust Standard Operating Procedures (SOPs).
  6. Communication: Exceptional written communication and technical writing skills, with the ability to produce clear and concise compliance reports, governance policies, and training materials for all audience levels.

Adaptability: Demonstrated ability to adapt control design and audit planning to complex environments with system limitations and evolving business requirements.

Top Skills

Cobit
Fedramp
Iso 27001
Nist 800-53
Pci
Soc
Sox

Cloudflare Denver, Colorado, USA Office

Denver, Colorado, United States, 80014

Similar Jobs at Cloudflare

3 Hours Ago
Hybrid
4 Locations
166K-224K Annually
Mid level
166K-224K Annually
Mid level
Cloud • Information Technology • Security • Software • Cybersecurity
Responsible for leading Cloudflare's Workers KV and Hyperdrive products, driving strategy and roadmap, and enhancing developer experiences. Collaborate with teams to deliver features and engage developers for feedback.
Top Skills: GoJavaScriptRustSQLTypescript
3 Hours Ago
Hybrid
Austin, TX, USA
Senior level
Senior level
Cloud • Information Technology • Security • Software • Cybersecurity
Collaborate with Design Engineers to develop frontend experiences improving developer experience, focusing on coding, aesthetics, and user interactions.
Top Skills: FigmaReactTypescript
3 Hours Ago
Hybrid
Austin, TX, USA
78K-96K Annually
Junior
78K-96K Annually
Junior
Cloud • Information Technology • Security • Software • Cybersecurity
Perform risk-based audits, evaluate processes and controls, document audit observations, and support tracking of remediation actions while contributing to continuous improvement efforts.
Top Skills: AIAutomationData Analysis Tools

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account