Senior Security Compliance Specialist
Lead Cloudflare's CCCS CSP ITS assessment and maintain CCCS requirements in the Common Control Framework. Requires 5+ years in security compliance, deep CCCS knowledge, and cross-functional collaboration with engineering, legal, and product teams.
About the job
What you’ll do
- Lead Cloudflare through the CCCS CSP ITS Assessment process
- Update and maintain CCCS requirements within Cloudflare’s Common Control Framework
- Work cross-functionally with Engineering, Legal, Product, and operational teams to drive security control implementation for the organization
- Improve the maturity of Cloudflare’s Security Compliance program
- Help guide our overall security policy and governance architecture
- Have input into the overall security compliance strategy
Examples of desirable skills, knowledge and experience
- 5+ years of experience working in Security Compliance
- Led the pursuit of, or maintained a CCCS Medium / PBMM certification
- Deep understanding of the CCCS CSP ITS assessment processes
- Deep understanding of CCCS requirements
- Familiarity with additional security standards and frameworks such as ISO 27000, SOC 2, PCI DSS, HITRUST, FedRAMP
- Ability to work cross-functionally with internal stakeholders and strong communications skills
- Ability to work closely with auditors and articulate technical concepts
- Ability to work efficiently and independently in a fast-paced, high-volume environment
- Willingness to travel occasionally to engage with regulators and auditors
Skills
Security Compliance, Cccs, Csp Its, Pbmm, Iso 27000, SOC 2, Pci Dss, Hitrust, FedRAMP
Similar jobs
Security Engineering jobsLeads enterprise information security for regulated digital-health products, overseeing security operations, privacy compliance, secure development, audits, risk management, and regulatory documentation. Requires healthcare or similarly regulated-industry experience, broad security-framework knowledge, and strong cross-functional leadership.
Leads Calendly’s Product Security and Security Operations functions, setting strategy, managing technical teams, and strengthening application security, detection, and incident response. Requires 7+ years of cybersecurity experience and 4+ years managing security teams.
Leads enterprise IT governance, risk, and compliance programs, including third-party risk, audits, policies, and customer security enablement. Requires 7+ years of GRC, audit, or cybersecurity experience and expertise with SOC 2, ISO 27001, NIST CSF, and privacy regulations.
Senior security operations engineer responsible for cloud security, detection and response, vulnerability remediation, threat hunting, incident response, and security automation. Requires 6+ years of security experience in complex cloud environments and strong AWS or Azure expertise.
Leads cloud-native security operations, incident response, threat hunting, and forensic investigations while mentoring SOC analysts and improving detection processes. Requires 8+ years in information security, including hands-on cloud incident response and experience with Kubernetes, CI/CD, and advanced security tools.