<?xml version="1.0" encoding="UTF-8"?>
<source>
  <jobs>
    <job>
      <externalid>038b4893-89b</externalid>
      <Title>IT Audit Lead</Title>
      <Description><![CDATA[<p>We are seeking an IT Audit Lead to join our Management Controls and Internal Audit Group. As an IT Audit Lead, you will be responsible for leading IT audit engagements, planning and carrying out the audit, and continuously working to improve processes and procedures. You will work closely with the Head of Information Technology Audit to develop and maintain an in-depth understanding of the technology organization, business areas, and support functions.</p>
<p>Primary Responsibilities:</p>
<ul>
<li>Lead and perform IT and integrated audit engagements, with support from IT Auditors, focusing on IT core infrastructure, trade execution and trade processing infrastructure, critical applications, and IT general controls;</li>
<li>Build and maintain relationships with key stakeholders, establishing a culture of engagement while adding value;</li>
<li>Develop and maintain an in-depth understanding of the technology organization, business areas, and support functions;</li>
<li>Support the Head of Information Technology Audit with audit planning, scope design, internal control assessment, raising and reporting of issues, and monitoring of remediation plans;</li>
<li>Participate in department-wide initiatives focused on continually improving firm processes and the control environment;</li>
<li>Assist with annual risk assessment process, audit plan creation, and other departmental administrative projects.</li>
</ul>
<p>Qualifications/Skills Required:</p>
<ul>
<li>12+ years of IT audit experience with exposure to core IT infrastructure, cyber security, equities trading, fixed-income trading, operations, and/or trade support functions;</li>
<li>Strong analytical and reporting skills and effective relationship-building experience;</li>
<li>Effective communication (verbal and written) and inter-personal skills, with the ability to present sophisticated and sensitive issues to management and inspire change;</li>
<li>Knowledge and experience of core IT infrastructure platforms (e.g., Windows, Unix, Sybase, SQL), cyber security, cloud technology, networks, firewalls, and/or data analytics;</li>
<li>Extensive knowledge of the audit lifecycle and the evaluation of IT general controls and IT automated controls;</li>
<li>Bachelor’s degree in Information Systems, Computer Science/Engineering, or other relevant fields;</li>
<li>A related certification (e.g., CISA, CISSP, CIA) is desired;</li>
<li>Domestic and international travel requirements: 0%-10%.</li>
</ul>
<p>The estimated base salary range for this position is $160,000 to $250,000, which is specific to New York and may change in the future.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>onsite</Workarrangement>
      <Salaryrange>$160,000 to $250,000</Salaryrange>
      <Skills>IT audit experience, core IT infrastructure, cyber security, equities trading, fixed-income trading, operations, trade support functions, analytical and reporting skills, relationship-building experience, communication (verbal and written) and inter-personal skills, knowledge of core IT infrastructure platforms, cloud technology, networks, firewalls, data analytics, audit lifecycle, IT general controls, IT automated controls</Skills>
      <Category>IT</Category>
      <Industry>Finance</Industry>
      <Employername>Audit</Employername>
      <Employerlogo>https://logos.yubhub.co/mlp.eightfold.ai.png</Employerlogo>
      <Employerdescription>Millennium is a company that exists to assist with compliance, legal, and ethics oversight.</Employerdescription>
      <Employerwebsite>https://mlp.eightfold.ai</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://mlp.eightfold.ai/careers/job/755953849622</Applyto>
      <Location>New York, New York, United States of America</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>11b88e19-a73</externalid>
      <Title>Data Centre Security Compliance Public Sector Specialist</Title>
      <Description><![CDATA[<p>About Us</p>
<p>At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world&#39;s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies.</p>
<p>We protect and accelerate any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks.</p>
<p>Key Responsibilities</p>
<p><strong>Public Sector &amp; Compliance Governance</strong></p>
<ul>
<li>Serve as the Subject Matter Expert (SME) on NIST 800-53 control families and FedRAMP requirements.</li>
<li>Manage Cloudflare&#39;s continuous monitoring program, inclusive of annual assessments and significant change requests.</li>
<li>Collect, validate, and organize FedRAMP evidence and artifacts to present to auditors, FedRAMP customers, and the FedRAMP PMO.</li>
<li>Help guide our overall security policy and governance architecture to ensure alignment with evolving government regulations.</li>
</ul>
<p><strong>Audit Lifecycle Management</strong></p>
<ul>
<li>Orchestrate end-to-end audit activities for standards such as PCI, SOC2, ISO, NIST, and FedRAMP.</li>
<li>Coordinate with auditors to manage data center access, compliance certificate collection, and evidence defense.</li>
<li>Work cross-functionally with Engineering, Legal, Product, and Operational teams to maintain management and technical controls.</li>
<li>Support compliance and regulatory projects, including implementation of new legislation / regulation.</li>
</ul>
<p><strong>Identity &amp; Access Management (IAM) Operations</strong></p>
<ul>
<li>Execute monthly Periodic Access Reviews (PARs): Compare portal user lists against ACLs to ensure least-privilege access is maintained across all data centers.</li>
<li>Manage the lifecycle of portal access: Auditing access, provisioning/deprovisioning users, and maintaining accurate documentation.</li>
<li>Oversee physical access requests to data centers and ensure strict adherence to security policies.</li>
<li>Drive the resolution of daily DCSC Jira tickets for portal access, physical access, audits, and site decommissioning.</li>
<li>Automate and streamline access review processes where possible, utilizing standard communication templates to site managers.</li>
</ul>
<p><strong>Partner Relations &amp; Reporting</strong></p>
<ul>
<li>Own, influence, and orchestrate relationships within the partner Offering teams that can help drive Cloudflare offerings and strategic positioning.</li>
<li>Monitor and implement changes to individual accountability regime requirements (such as UK, Ireland, Singapore and Australia).</li>
<li>Maintain centralized documentation, databases, dashboards, and reporting mechanisms to track compliance health.</li>
</ul>
<p>Requirements</p>
<ul>
<li>3-6 years working in Security Compliance, Information Security, or Risk Management.</li>
<li>Deep familiarity with all NIST 800-53 control families and FedRAMP requirements.</li>
<li>Ability to work closely with auditors and articulate technical concepts.</li>
<li>Experience in auditing of network, operating system, and application security.</li>
<li>Proven experience managing an audit throughout the full audit lifecycle (from readiness to final report).</li>
<li>Familiarity with additional security standards and frameworks such as ISO 27000, SOC 2, PCI DSS, ISMAP and IRAP.</li>
<li>Ability to work cross-functionally with internal stakeholders and strong communications skills.</li>
<li>High tolerance for ambiguity and ability to work efficiently and independently in a fast-paced, high-volume environment.</li>
<li>Some travel may be required to engage with regulators and auditors.</li>
<li>Certifications: CISSP, CIPP, CIPM, CIPT, CISA, or CRISC.</li>
<li>A relevant professional experience working with technology partners, alliances, or third-party vendors, ideally in the following disciplines: Data center Security Compliance, Access Management, audit administration at a leading high-tech company; offering management.</li>
<li>Technical skills including the ability to understand (1) product roadmaps; (2) market trends and factors; and (3) complex partner requirements.</li>
<li>Strong technical proficiency with spreadsheet software (Excel/Google Sheets) including pivot tables and VLOOKUPs for data reconciliation.</li>
<li>Organized &amp; Disciplined, with a strong focus on driving outcomes.</li>
</ul>
<p>Preferred</p>
<ul>
<li>Prior experience with Data Centre Security Compliance disciplines and audit programs and past history working at a hyperscaler or high-growth tech company.</li>
<li>Superb organizational skills and demonstrated history managing complex processes including audit cycles, Facts gathering and analytical skills.</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>mid</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>NIST 800-53 control families, FedRAMP requirements, Identity &amp; Access Management (IAM), Audit Lifecycle Management, Security Compliance, Information Security, Risk Management, CISSP, CIPP, CIPM, CIPT, CISA, CRISC, Data center Security Compliance, Access Management, audit administration, product roadmaps, market trends and factors, complex partner requirements</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Cloudflare</Employername>
      <Employerlogo>https://logos.yubhub.co/cloudflare.com.png</Employerlogo>
      <Employerdescription>Cloudflare operates one of the world&apos;s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies.</Employerdescription>
      <Employerwebsite>https://www.cloudflare.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/cloudflare/jobs/7477769</Applyto>
      <Location>Hybrid</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
  </jobs>
</source>