GRC Engineer
GRC Engineer building automated compliance solutions, AI governance frameworks, and audit-ready infrastructure at Cloudflare. Requires 5+ years experience, IaC/PaC expertise (Terraform, OPA), Python/Go scripting, and full-stack web development skills.
About the job
What you'll do
Automation & Engineering: Develop and implement automated solutions to improve GRC processes and operations, integrating with existing security, engineering, and AI tools. Build modules and maintain our GRC platform and other similar initiatives.
AI Governance: Architect and maintain a technical governance framework for the safe deployment of autonomous AI agents. Ensure that agentic workflows operate within deterministic "action gates" and predefined risk thresholds.
Audit & Infrastructure: Support Cloudflare’s security assessments (e.g., SOC 2, ISO 27001, PCI DSS, FedRAMP). Treat "Audit Readiness" as a product, ensuring our global edge network remains compliant through automated drift detection and self-healing configurations.
Security Integration: Work cross-functionally with Legal, People, Engineering, and Finance teams to integrate security into the fabric of the company, moving away from "gatekeeping" toward a paved-road security model where compliance is the default state for every developer.
Desirable Skills, Knowledge, and Experience
- 5+ years of experience in security, compliance, automation, or engineering functions in a fast-paced environment.
- Builder mindset: enjoy building technical solutions to complex problems; prefer scripting over manual tasks.
- Experience designing or implementing AI-powered automation and agentic workflows; understand risks of non-deterministic systems.
- Deep experience with Infrastructure as Code (Terraform, Pulumi) and Policy as Code (OPA/Rego).
- Proficient in Python, Go, or other scripting languages for automation, API interactions, and data parsing.
- Comfortable working with REST APIs.
- Proven experience building modern web applications, including JavaScript/TypeScript and React; collaborate across frontend and backend.
- Driven by curiosity, anchored by empathy, and defined by a relentless ability to get things done.
Bonus Points
- Demonstrated passion for security and software development (personal projects, open-source, security research community).
- Experience building with Cloudflare developer platform (Cloudflare Workers, R2, D1, or Workers AI).
Compensation & Benefits
This role is eligible to participate in Cloudflare’s equity plan.
Cloudflare offers a complete package of benefits and programs to support you and your family, including medical, dental, and vision insurance, a 401(k) plan with company match, flexible paid time off, and fertility & family-forming benefits.
Skills
Terraform, Pulumi, Opa, Rego, Python, Go, JavaScript, TypeScript, React, REST APIs, Infrastructure As Code, Policy As Code, Ai Governance
Similar jobs
Security Engineering jobsThe Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.
Security Scientist analyzing attacker and user behavior, building data-driven detections, and leading security investigations and design reviews. Requires strong security and anti-abuse knowledge, SQL fluency, scripting proficiency, and experience with distributed data systems and statistical methods.
Own and build the company’s security program as its first full-time security hire, covering product, cloud, infrastructure, incident response, compliance, and customer trust. The role requires hands-on security engineering and incident leadership, with experience operating SOC 2 or comparable frameworks.
Conduct proactive threat hunting and adversary simulation to uncover financial fraud tactics, enrich threat intelligence, and improve platform controls. The role requires at least five years of relevant cybersecurity, abuse, or trust experience plus strong Python, SQL, investigative, and data-analysis skills.
Conduct offensive security operations, red-team engagements, penetration testing, and adversarial simulations across cloud, endpoint, and bare-metal environments. The role requires at least five years of experience, strong engineering skills, and expertise across multiple security domains.