DCSC 自动化专员
查看雇主原标题
DCSC Automation SpecialistCloudflare · Hybrid
职位信息来自雇主公开的招聘页面。申请前请务必在雇主官网核实详情。
为什么值得关注?
发现指数 60/100,仅依据与该职位一起存储的证据计算。
- 新的雇主官方职位
- 远程职位
- 稀有职位匹配
分数构成
- 时效性 (随职位发布时间变化)+18
- 雇主官方来源+15
- 远程职位+8
- 稀有职位+11
- 公司来源健康度+8
该职位未包含:已披露薪资、提及签证担保、提及搬迁、未出现在监控的职位板上。
这些理由来自雇主自己的职位描述与我们核实过的来源检查结果。除了已存储的信号之外,我们不做任何推测。
职位描述
机器翻译关于我们
在 Cloudflare,我们的使命是帮助构建更好的互联网。如今,公司运营着全球最大的网络之一,为从个人博主到中小企业再到《财富》500 强企业的客户提供支持,驱动着数百万个网站和其他互联网资产。Cloudflare 无需添加硬件、安装软件或更改一行代码,即可保护和加速任何在线互联网应用。由 Cloudflare 驱动的互联网资产,其网络流量都会通过其智能全球网络进行路由,而该网络会随着每一次请求变得更加智能。因此,它们的性能显著提升,垃圾邮件和其他攻击也减少了。Cloudflare 曾入选《Entrepreneur》杂志的顶级公司文化榜单,并被《Fast Company》评为全球最具创新力公司之一。
在 Cloudflare,我们寻找的不是等待一份完美路线图的人;我们寻找的是那些看到互联网裂缝、而其他人都只是学会与之共处的建设者。我们看重那些有直觉发现“被正常化”的问题,并具备 AI 原生好奇心、能够使用最新工具创造解决方案的候选人。我们的文化建立在迭代之上,利用 AI 在今天更快交付,从而让明天更好,同时确保每一项改进,无论多小,都能在团队中共享,提升每个人。如果你是那种重视好奇心胜过官僚主义,并认为 AI 是解决棘手问题、推动互联网前进的伙伴的人,你会非常适合这里。
可选工作地点:
• Austin, TX
• Atlanta, GA
• Denver, CO
• Seattle, WA
• Washington, DC
职位概述
Cloudflare 正在寻找一名自动化专家,来改变我们全球数据中心安全合规(DCSC)团队的运作方式。这一关键职位隶属于基础设施运营组织,该组织负责在遍布全球 700 多个站点构建、扩展和运行 Cloudflare 的数据中心和网络基础设施。
DCSC 团队管理业内最复杂、最分布式的基础设施布局之一的物理访问控制和合规审计,覆盖 105 多个供应商门户、数百个非门户运营商中立和边缘合作伙伴站点,以及包括 SOC 2、ISO 27001、FedRAMP、ISMAP 和 IRAP 在内的多个监管框架。这项工作的运营负担很重,且主要依靠人工:用户列表靠手工拉取,访问控制列表靠肉眼核对,证据包逐张工单组装,证明周期每季度消耗协调员数周时间。
这个职位正是为了改变这一点而设立。DCSC 自动化专家将设计、构建和运营 AI 辅助及自动化工作流,消除 DCSC 运营模式中最耗时的重复性人工工作,让合规协调员能够专注于异常处理、利益相关方关系和监管判断,而不是数据收集和核对。
这是一个建设者角色。你将访谈团队以了解每个工作流,识别最具杠杆效应的自动化目标,并交付能够显著减少完成 QAR 周期、生成审计证据包或管理一批访问权限开通请求所需时间的工具。你将与 DCSC 协调员及现有自动化开发人员紧密合作,并负责 DCSC 运营工具路线图。
主要职责
• 门户自动化与用户列表提取
• 浏览器自动化:设计并维护自动化脚本(Playwright、Puppeteer 或同等工具),用于登录供应商数据中心门户、提取用户访问列表,并将结构化输出送入 DCSC Portal 和比较流水线,取代覆盖 338+ 个站点、105+ 个门户的手工逐门户数据收集。
• 韧性与覆盖:为阻止或限流自动化访问的门户构建回退处理;记录例外情况,并维护按门户跟踪自动化状态的覆盖登记表。
• 计划执行:将提取任务按与 QAR 和 MAR 周期一致的重复杂节奏投入运营,并在失败和漂移时发出告警。
• ACL 核对与差异引擎
• 自动比较:构建工具,用于摄取门户提取的用户列表,并将其与主访问控制列表(ACL)进行比较,自动暴露差异:存在于门户但不在 ACL 中的用户、在 ACL 中但没有有效门户访问权限的用户,以及角色或访问级别不匹配。
• 仅异常输出:将已确认的差异直接路由到预填充的 Jira 工单,供人工审查和操作,从而消除协调员每季度对每条用户记录进行完整人工审查的需要。
• 审计追踪:确保所有比较运行都生成不可变、带时间戳的记录,以满足 SOC 2、ISO 27001 和 FedRAMP 证据要求。
• 证明与证据自动化
• 证明模块:负责并扩展 DCSC Portal 内的证明工作流,包括自动触发周期、通知经理、捕获带时间戳的确认以及异常升级,取代基于截图的手工证据收集。
• Ev
岗位职责
• 门户自动化与用户列表提取
• 浏览器自动化:设计并维护自动化脚本(Playwright、Puppeteer 或同等工具),用于登录供应商数据中心门户、提取用户访问列表,并将结构化输出送入 DCSC Portal 和比较流水线,取代覆盖 338+ 个站点、105+ 个门户的手工逐门户数据收集。
• 韧性与覆盖:为阻止或限流自动化访问的门户构建回退处理;记录例外情况,并维护按门户跟踪自动化状态的覆盖登记表。
• 计划执行:将提取任务按与 QAR 和 MAR 周期一致的重复杂节奏投入运营,并在失败和漂移时发出告警。
• ACL 核对与差异引擎
• 自动比较:构建工具,用于摄取门户提取的用户列表,并将其与主访问控制列表(ACL)进行比较,自动暴露差异:存在于门户但不在 ACL 中的用户、在 ACL 中但没有有效门户访问权限的用户,以及角色或访问级别不匹配。
• 仅异常输出:将已确认的差异直接路由到预填充的 Jira 工单,供人工审查和操作,从而消除协调员每季度对每条用户记录进行完整人工审查的需要。
• 审计追踪:确保所有比较运行都生成不可变、带时间戳的记录,以满足 SOC 2、ISO 27001 和 FedRAMP 证据要求。
• 证明与证据自动化
• 证明模块:负责并扩展 DCSC Portal 内的证明工作流,包括自动触发周期、通知经理、捕获带时间戳的确认以及异常升级,取代基于截图的手工证据收集。
• 证据包构建器:构建自动化流水线,为 SOC 2、ISO 27001、FedRAMP、ISMAP 和 IRAP 控制周期汇编可供审计的证据包,将证明日志、门户提取结果、差异报告和往来通信汇总为按特定控制 ID 索引的结构化包。
• GRC 对齐:直接与 GRC 对口人员合作,在部署前验证自动化证据格式满足审计师和监管要求。
• AI 辅助异常检测与分诊
• 访问模式分析:对 QAR 周期输出实施基于 LLM 的审查,以暴露需要人工升级的模式:前员工保留访问权限、随时间累积的权限蔓延、休眠账户,以及跨站点的异常角色分配。
• 工单智能:构建自动化,读取传入的 Jira 入职和离职工单,并生成结构化的、针对具体门户的操作清单,减少协调员的认知负担,并防止多门户开通工作流中遗漏步骤。
• 持续改进:持续监控自动化输出质量,在门户结构变化时重新训练或重新校准模型,并与协调员就误报和漏检保持反馈闭环。
• DCSC Portal 所有权与工具路线图
• 平台管理:负责 DCSC Portal 作为所有自动化和工作流工具的运营运行时,确保其保持稳定、有文档记录,并可由协调员在日常任务中无需工程支持即可使用。
• 路线图管理:维护按时间节省、合规影响和实施复杂度评估的自动化机会优先级待办列表;向 DCSC 领导层提交季度进展和优先事项。
• 文档:为每项自动化编写运行手册,确保没有任何运营能力只存在于某个人的头脑中或本地机器上。
理想技能 / 经验:
• 自动化工程:具有针对真实世界 Web 应用构建浏览器自动化(Playwright、Puppeteer、Selenium 或同等工具)的证明经验,包括处理身份验证流程、动态内容和反机器人缓解措施。
• TypeScript 熟练度:具备脚本编写、数据整理、结构化文件 I/O 和 API 集成的强大技能。能够编写可维护、有文档记录且非工程师也能操作的代码。
• LLM 集成:具有将 LLM API(OpenAI、Anthropic、Google 或同等服务)集成到生产工作流中用于分类、起草、摘要或异常检测任务的实操经验。
• 数据工程基础:能够自如处理大规模结构化和半结构化数据、比较数据集差异、规范化不一致格式,并为下游审计用途生成干净输出。
• API 与工作流集成:具有通过 REST API 与工单或 ITSM 系统(优先 Jira)构建集成的经验,包括自动创建工单、状态更新和附件处理。
• 系统思维:能够梳理端到端人工工作流,识别最具杠杆效应的自动化插入点,并在不等待完美解决方案的情况下增量交付。
• 工作流考古:能够通过结构化访谈从主题专家处提取流程知识,将部落知识转化为有文档记录、可自动化的工作流。
• 偏向简单:具备强大的产品直觉,能够找到带来真实时间节省的最小可行自动化,而不是为边缘情况过度工程化。
• 合规意识:理解合规场景中准确性的利害关系,明白错误的 ACL 差异或缺失的证据工件会产生真实的审计后果。
软技能:
• 沟通:能够向非技术利益相关方(包括合规协调员和 GRC 合作伙伴)清晰解释自动化设计决策和权衡。
• 容忍模糊性:供应商门户没有文档。工作流靠口头传承。你需要从零开始弄清楚事情,并从中获得动力。
任职要求
• 熟悉 GRC/合规框架(SOC 2、FedRAMP、ISO 27001)的运营层面——不是作为审计员,而是足以理解为什么证据完整性很重要
• 具备 RPA 工具经验(UiPath、Power Automate),作为应对无法被无头浏览器处理的门户网站的备用方案
• 曾在基础设施运营、数据中心或物理安全环境中工作过
Cloudflare 有何特别之处?
我们不仅仅是一家雄心勃勃的大型科技公司。我们是一家有灵魂的、雄心勃勃的大型科技公司。我们帮助构建更好的互联网这一使命的根本,是保护自由和开放的互联网。
Project Galileo:自 2014 年以来,我们已为 111 个国家的 2,400 多个新闻和公民社会组织提供了强大的工具,帮助他们抵御那些否则会审查其工作的攻击,这些技术已被 Cloudflare 的企业客户使用——而且是免费的。
Athenian Project:2017 年,我们创建了 Athenian Project,以确保州和地方政府免费获得最高级别的保护和可靠性,从而让他们的选民能够获取选举信息和选民登记。自该项目启动以来,我们已为 33 个州的 425 多个地方政府选举网站提供服务。
1.1.1.1:我们发布了 1.1.1.1,通过构建一个更快、更安全且以隐私为中心的公共 DNS 解析器,帮助修复互联网的基础。这项服务面向所有人公开可用——这是 Cloudflare 有史以来发布的第一个面向消费者的服务。事情是这样的——我们永远不会存储客户端 IP 地址。我们将继续遵守我们的隐私承诺,确保不会将任何用户数据出售给广告商或用于定向投放消费者。
听起来像是你想参与的事情?我们很乐意听到你的消息!
请注意,进入面试流程录用阶段的申请人可能会被要求前往 Cloudflare 办公室或 Cloudflare Hub 之一参加现场面试。有关这方面的更多详细信息将在面试流程的该阶段提供。
该职位可能需要访问受美国出口管制法律(包括美国出口管理条例)保护的信息。请注意,任何录用通知都可能以您能够在无需申请出口许可证担保的情况下接收受这些美国出口法律管制的软件或技术为条件。
Cloudflare 自豪地成为一家提供平等机会的雇主。我们致力于为所有人提供平等的就业机会,并高度重视多元化和包容性。所有符合条件的申请人都会在就业中被考虑,不论其或任何其他人的实际或被认为的种族、肤色、宗教、性别、性别认同、性别表达、性取向、国籍、血统、公民身份、年龄、身体或精神残疾、医疗状况、家庭照护状况或任何其他受法律保护的基础。我们是 AA/退伍军人/残疾人雇主。
Cloudflare 为符合条件的残障人士提供合理便利。如果您在申请工作时需要合理便利,请告诉我们。合理便利的示例包括但不限于:更改申请流程、以其他格式提供文件、使用手语翻译或使用专业设备。如果您在申请工作时需要合理便利,请通过电子邮件 hr@cloudflare.com 或邮寄至 101 Townsend St. San Francisco, CA 94107 与我们联系。
以上内容由机器翻译自动生成,可能存在错误;投递前请以雇主原文为准。
查看雇主原文
职位描述
About Us
At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine’s Top Company Cultures list and ranked among the World’s Most Innovative Companies by Fast Company.
At Cloudflare, we’re not looking for people who wait for a polished roadmap; we’re looking for the builders who see the cracks in the Internet that everyone else has simply learned to live with. We value candidates who have the instinct to spot a "normalized" problem and the AI-native curiosity to create a solution using the latest tools. Our culture is built on iteration, leveraging AI to ship faster today to make it better tomorrow, while ensuring that every improvement, no matter how small, is shared across the team to lift everyone up. If you’re the type of person who values curiosity over bureaucracy, and that AI is a partner in solving tough problems to keep the Internet moving forward, you’ll fit right in.
Available Locations:
• Austin, TX
• Atlanta, GA
• Denver, CO
• Seattle, WA
• Washington, DC
Position Overview
Cloudflare is looking for an Automation Specialist to transform how our global Data Center Security Compliance (DCSC) team operates. This critical role is part of the Infrastructure Operations organization, which is responsible for building, scaling, and running Cloudflare's data center and network infrastructure across 700+ sites worldwide.
The DCSC team manages physical access control and compliance auditing across one of the most complex and distributed infrastructure footprints in the industry, spanning more than 105 vendor portals, hundreds of non-portal carrier-neutral and edge partner sites, and multiple regulatory frameworks including SOC 2, ISO 27001, FedRAMP, ISMAP, and IRAP. The operational burden of this work is substantial and largely manual: user lists are pulled by hand, access control lists are reconciled by eye, evidence packages are assembled ticket by ticket, and attestation cycles consume weeks of coordinator time every quarter.
This role exists to change that. The DCSC Automation -Specialist will design, build, and operate AI-assisted and automated workflows that eliminate the most time-consuming manual work in the DCSC operating model, freeing compliance coordinators to focus on exception handling, stakeholder relationships, and regulatory judgment rather than data gathering and reconciliation.
This is a builder role. You will interview the team to understand each workflow, identify the highest-leverage automation targets, and ship tooling that demonstrably reduces the time it takes to close a QAR cycle, produce an audit evidence package, or manage a batch of access provisioning requests. You will work in close partnership with the DCSC coordinators, and existing automation developers, and will own the DCSC operational tooling roadmap.
Key Responsibilities
• Portal Automation & User List Extraction
• Browser Automation: Design and maintain automated scripts (Playwright, Puppeteer, or equivalent) that log into vendor data center portals, extract user access lists, and feed structured output into the DCSC Portal and comparison pipelines replacing manual portal-by-portal data collection across 105+ portals covering 338+ sites.
• Resilience & Coverage: Build fallback handling for portals that block or rate-limit automated access; document exceptions and maintain a coverage registry tracking automation status per portal.
• Scheduled Execution: Operationalize extraction jobs on a recurring cadence aligned to QAR and MAR cycles, with alerting for failures and drift.
• ACL Reconciliation & Diff Engine
• Automated Comparison: Build tooling that ingests portal-extracted user lists and compares them against the master Access Control List (ACL), automatically surfacing discrepancies: users present in a portal but absent from the ACL, users on the ACL without active portal access, and role or access-level mismatches.
• Exception-Only Output: Route confirmed discrepancies directly to pre-populated Jira tickets for human review and action, eliminating the need for coordinators to perform full manual review of every user record each quarter.
• Audit Trail: Ensure all comparison runs produce immutable, timestamped records suitable for SOC 2, ISO 27001, and FedRAMP evidence requirements.
• Attestation & Evidence Automation
• Attestation Module: Own and extend the attestation workflow within the DCSC Portal, including automated cycle triggering, manager notification, time-stamped confirmation capture, and exception escalation, replacing manual screenshot-based evidence gathering.
• Ev
岗位职责
• Portal Automation & User List Extraction
• Browser Automation: Design and maintain automated scripts (Playwright, Puppeteer, or equivalent) that log into vendor data center portals, extract user access lists, and feed structured output into the DCSC Portal and comparison pipelines replacing manual portal-by-portal data collection across 105+ portals covering 338+ sites.
• Resilience & Coverage: Build fallback handling for portals that block or rate-limit automated access; document exceptions and maintain a coverage registry tracking automation status per portal.
• Scheduled Execution: Operationalize extraction jobs on a recurring cadence aligned to QAR and MAR cycles, with alerting for failures and drift.
• ACL Reconciliation & Diff Engine
• Automated Comparison: Build tooling that ingests portal-extracted user lists and compares them against the master Access Control List (ACL), automatically surfacing discrepancies: users present in a portal but absent from the ACL, users on the ACL without active portal access, and role or access-level mismatches.
• Exception-Only Output: Route confirmed discrepancies directly to pre-populated Jira tickets for human review and action, eliminating the need for coordinators to perform full manual review of every user record each quarter.
• Audit Trail: Ensure all comparison runs produce immutable, timestamped records suitable for SOC 2, ISO 27001, and FedRAMP evidence requirements.
• Attestation & Evidence Automation
• Attestation Module: Own and extend the attestation workflow within the DCSC Portal, including automated cycle triggering, manager notification, time-stamped confirmation capture, and exception escalation, replacing manual screenshot-based evidence gathering.
• Evidence Package Builder: Build automated pipelines that compile audit-ready evidence packages for SOC 2, ISO 27001, FedRAMP, ISMAP, and IRAP control cycles, pulling attestation logs, portal extraction results, diff reports, and correspondence into structured packages keyed to specific control IDs.
• GRC Alignment: Work directly with GRC counterparts to validate that automated evidence formats meet auditor and regulatory requirements before deployment.
• AI-Assisted Anomaly Detection & Triage
• Access Pattern Analysis: Implement LLM-based review passes over QAR cycle output to surface patterns warranting human escalation: former employees retaining access, access creep over time, dormant accounts, and anomalous role assignments across sites.
• Ticket Intelligence: Build automation that reads incoming Jira onboarding and offboarding tickets and generates structured, portal-specific action checklists reducing coordinator cognitive load and preventing missed steps across multi-portal provisioning workflows.
• Continuous Improvement: Monitor automation output quality over time, retrain or recalibrate models as portal structures change, and maintain a feedback loop with coordinators on false positives and missed detections.
• DCSC Portal Ownership & Tooling Roadmap
• Platform Stewardship: Own the DCSC Portal as the operational runtime for all automation and workflow tooling ensuring it remains stable, documented, and usable by coordinators without engineering support for day-to-day tasks.
• Roadmap Management: Maintain a prioritized backlog of automation opportunities, assessed by time savings, compliance impact, and implementation complexity; present quarterly progress and priorities to DCSC leadership.
• Documentation: Produce runbooks for every automation, ensuring that no operational capability lives only in one person's head or on a local machine.
Desirable skills / Experience:
• Automation Engineering: Demonstrated experience building browser automation (Playwright, Puppeteer, Selenium, or equivalent) against real-world web applications, including handling authentication flows, dynamic content, and anti-bot mitigations.
• TypeScript Proficiency: Strong skills for scripting, data wrangling, structured file I/O, and API integration. Ability to write maintainable, documented code that non-engineers can operate.
• LLM Integration: Hands-on experience integrating LLM APIs (OpenAI, Anthropic, Google, or equivalent) into production workflows for classification, drafting, summarization, or anomaly detection tasks.
• Data Engineering Fundamentals: Comfort working with structured and semi-structured data at scale, diffing datasets, normalizing inconsistent formats, and producing clean outputs for downstream audit use.
• API & Workflow Integration: Experience building integrations with ticketing or ITSM systems (Jira preferred) via REST API, including automated ticket creation, status updates, and attachment handling.
• Systems Thinking: Ability to map an end-to-end manual workflow, identify the highest-leverage automation insertion points, and ship incrementally without waiting for a perfect solution.
• Workflow Archaeology: Comfortable extracting process knowledge from subject-matter experts through structured interviews turning tribal knowledge into documented, automatable workflows.
• Bias Toward Simplicity: Strong product intuition for the minimum viable automation that delivers real time savings, rather than over-engineering for edge cases.
• Compliance Awareness: Appreciation for the stakes of accuracy in a compliance context, understanding that an incorrect ACL diff or a missing evidence artifact has real audit consequences.
Soft Skills:
• Communication: Able to explain automation design decisions and tradeoffs clearly to non-technical stakeholders including compliance coordinators and GRC partners.
• Ambiguity Tolerance: Vendor portals don't come with documentation. Workflows are passed down verbally. You need to be energized by figuring things out from scratch.
任职要求
• Familiarity with GRC/compliance frameworks (SOC 2, FedRAMP, ISO 27001) at an operational level — not as an auditor, but enough to understand why evidence integrity matters
• RPA tooling experience (UiPath, Power Automate) as fallback for portals that defeat headless browsers
• Prior work in infrastructure operations, data center, or physical security environments
What Makes Cloudflare Special?
We’re not just a highly ambitious, large-scale technology company. We’re a highly ambitious, large-scale technology company with a soul. Fundamental to our mission to help build a better Internet is protecting the free and open Internet.
Project Galileo : Since 2014, we've equipped more than 2,400 journalism and civil society organizations in 111 countries with powerful tools to defend themselves against attacks that would otherwise censor their work, technology already used by Cloudflare’s enterprise customers--at no cost.
Athenian Project : In 2017, we created the Athenian Project to ensure that state and local governments have the highest level of protection and reliability for free, so that their constituents have access to election information and voter registration. Since the project, we've provided services to more than 425 local government election websites in 33 states.
1.1.1.1 : We released 1.1.1.1 to help fix the foundation of the Internet by building a faster, more secure and privacy-centric public DNS resolver. This is available publicly for everyone to use - it is the first consumer-focused service Cloudflare has ever released. Here’s the deal - we don’t store client IP addresses never, ever. We will continue to abide by our privacy commitment and ensure that no user data is sold to advertisers or used to target consumers.
Sound like something you’d like to be a part of? We’d love to hear from you!
Please note that applicants who progress to the offer stage of the interview process may be asked to attend an in-person interview within one of the Cloudflare Offices or Cloudflare Hubs. More details about this will be available at that stage of the interview process.
This position may require access to information protected under U.S. export control laws, including the U.S. Export Administration Regulations. Please note that any offer of employment may be conditioned on your authorization to receive software or technology controlled under these U.S. export laws without sponsorship for an export license.
Cloudflare is proud to be an equal opportunity employer. We are committed to providing equal employment opportunity for all people and place great value in both diversity and inclusiveness. All qualified applicants will be considered for employment without regard to their, or any other person's, perceived or actual race, color, religion, sex, gender, gender identity, gender expression, sexual orientation, national origin, ancestry, citizenship, age, physical or mental disability, medical condition, family care status, or any other basis protected by law. We are an AA/Veterans/Disabled Employer.
Cloudflare provides reasonable accommodations to qualified individuals with disabilities. Please tell us if you require a reasonable accommodation to apply for a job. Examples of reasonable accommodations include, but are not limited to, changing the application process, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment. If you require a reasonable accommodation to apply for a job, please contact us via e-mail at hr@cloudflare.com or via mail at 101 Townsend St. San Francisco, CA 94107.