Available Location: London, United Kingdom
About Cloudflares Security Team
Security is at the heart of Cloudflare's mission to help build a better Internet. Anytime we push code, it automatically affects the millions of Internet properties (powering websites, remote teams, APIs, mobile apps, etc.) running on our global network. Cloudflares network is one of the largest in the world, spanning over 330 cities in more than 125 countries, and operating within 50 milliseconds of 95% of the Internet-connected population.
The Security Governance, Risk and Compliance team (GRC) is a sub-team of Security. Our job is to make sure that Cloudflare has the right controls in place to secure our systems and customer data. We work cross-functionally with almost every team at Cloudflare to implement new controls, manage risk, and demonstrate our security posture to auditors and customers.
About the Internship Program
The ideal Security intern is passionate about making the Internet a more secure place. You will work alongside experienced security team members to partner with them in planning, executing and overseeing initiatives that help improve Cloudflare's security posture. We are looking for interns who are curious, proactive, and able to approach problems with a security-first mindset. This is a unique opportunity for candidates who want to learn how to defend systems at a scale that few other companies can offer.
What you'll do
As a GRC intern, you won't just be checking boxes. Over 12 weeks, you will:
• Execute a specialized project that directly improves Cloudflare's security posture. • Improve the maturity of Cloudflare's Security Compliance program by working on projects like: Evaluating the efficacy of Cloudflare security controls implemented across the organization. Developing and implementing automated solutions to improve Governance, Risk, and Compliance processes and operations, integrating with existing security, engineering, and AI tools. Supporting the security risk register by triaging and assessing potential risks, proposing mitigation strategies, and presenting key security insights to leadership. Supporting Cloudflare's security data center audits and assessments. • Work cross-functionally with Legal, People, Engineering, and Finance teams to integrate security into the fabric of the company. • Work closely with a mentor who will provide hands-on guidance in your specific security domain. • Connect and learn from our executives and leadership team including our co-founders. • Present your security project to the entire company at the end of the internship. • Write for our Cloudflare blog and be featured on Cloudflare.tv sessions. • You can check out our internship blogs to learn more about our program and hear directly from our past interns.
Desirable skills, knowledge and experience
Working knowledge of industry-standard frameworks such as NIST 800-53, ISO 27001, or SOC 2 principles through coursework or personal study. Understanding of risk management methodologies - identifying threats, assessing impact/likelihood, and suggesting mitigation strategies. Ability to write basic Python scripts to automate repetitive tasks, such as interacting with APIs or data cleaning. Workflow Logic & Orchestration - experience with if-this-then-that logic in automation platforms. Understanding how to instruct AI models effectively and leverage them to perform day-to-day tasks. Demonstrated critical thinking skills and drive to learn and adapt new technologies. Curiosity, empathy and ability to get things done. Ability to commit to a minimum 12 week summer internship.
In the office 3-5 days a week in the London office
Bonus points
Demonstrated passion for security & software development, such as personal projects, open-source contributions, or experience. You've built something with our developer platform using Cloudflare for Students