GRC Team Intern (Fall 2026)

GRC Team Intern (Fall 2026)

Internship 63000 - 77000 £ / year (est.) No working from home possible
CloudFlare

At a Glance

  • Tasks: Support privacy and AI governance audits while collaborating with diverse teams.
  • Company: Join Cloudflare, a leader in building a better Internet with a vibrant culture.
  • Benefits: Gain hands-on experience in a fast-paced tech environment with mentorship.
  • Other info: Dynamic internship with opportunities for growth and learning.
  • Why this job: Make a real impact on privacy and security in a global network.
  • Qualifications: Curiosity about privacy, AI governance, and compliance; relevant coursework preferred.

The predicted salary is between 63000 - 77000 £ per year.

At Cloudflare, we are on a mission to help build a better Internet.

Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies.

Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code.

Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request.

As a result, they see significant improvement in performance and a decrease in spam and other attacks.

Cloudflare was named to Entrepreneur Magazine’s Top Company Cultures list and ranked among the World’s Most Innovative Companies by Fast Company.

At Cloudflare, we’re not looking for people who wait for a polished roadmap; we’re looking for the builders who see the cracks in the Internet that everyone else has simply learned to live with.

We value candidates who have the instinct to spot a "normalized" problem and the AI-native curiosity to create a solution using the latest tools.

Our culture is built on iteration, leveraging AI to ship faster today to make it better tomorrow, while ensuring that every improvement, no matter how small, is shared across the team to lift everyone up.

If you’re the type of person who values curiosity over bureaucracy, and that AI is a partner in solving tough problems to keep the Internet moving forward, you’ll fit right in.

  • Available Location: London, United Kingdom
  • About Cloudflare's Security Team

Security is at the heart of Cloudflare’s mission to help build a better Internet.

Anytime we push code, it automatically affects the millions of Internet properties (powering websites, remote teams, APIs, mobile apps, etc.) running on our global network.

Cloudflare's network is one of the largest in the world, spanning over 330 cities in more than 125 countries, and operating within 50 milliseconds of 95% of the Internet-connected population.

The Security Governance, Risk and Compliance team (GRC) is a sub-team of Security.

Our job is to make sure that Cloudflare has the right controls in place to secure our systems and customer data.

We work cross-functionally with almost every team at Cloudflare to implement new controls, manage risk, and demonstrate our security posture to auditors and customers.

About the Role

This internship is designed for candidates who are interested in the intersection of privacy, security, AI governance, and regulatory compliance.

The ideal intern is not only curious about controls and audit readiness, but also interested in how organizations operationalize privacy and responsible AI at scale.

You will work alongside experienced GRC, privacy, and security stakeholders to support Cloudflare’s preparation and coordination for privacy and AI-related framework audits, including work across standards such as ISO 27701, ISO 27018, EU Cloud Code of Conduct, Global CBPR / PRP, and ISO 42001.

This is a strong fit for students in law, public policy, privacy, data protection, AI governance, technology policy, or adjacent disciplines who want practical experience inside a fast-moving technology company.

What you’ll do

As a Privacy & AI Governance / GRC intern, you won’t just be checking boxes. Over the course of the internship, you will:

  • Support preparation and coordination for privacy and AI-related framework audits, including ISO 27701, ISO 27018, Global CBPR / PRP, and ISO 42001.
  • Help build and maintain a comprehensive knowledge base of privacy, personal data protection, AI governance, and related internal processes to support current and future audits.
  • Organize audit-ready documentation, evidence, ownership records, and process maps so that requirements can be located, understood, and presented efficiently.
  • Work with internal stakeholders across Legal, Security, Product, Engineering, People, Procurement, and other teams to gather information required for audit readiness and control validation.
  • Help translate complex privacy, AI, and compliance topics into clear summaries for internal audiences, including support for presenting material to auditors.
  • Track gaps, dependencies, action items, and review cycles across multiple frameworks and workstreams.
  • Contribute to process improvements that make privacy and AI governance work more durable, scalable, and easier to navigate over time.
  • Where useful, prototype lightweight dashboards, trackers, or workflow tools using spreadsheets, low-code/no-code tools, or AI-assisted coding to improve visibility into audit status and evidence readiness.
  • Work closely with a mentor who will provide guidance in GRC, privacy, and audit operations.
  • Present your internship project and recommendations at the end of the program.

You can check out our internship blogs to learn more about our program and hear directly from our past interns.

This role does not provide relocation assistance.

Desirable skills, knowledge and experience

  • Interest in privacy, personal data protection, AI governance, technology regulation, or security compliance through coursework, research, internships, or independent study.
  • Familiarity with privacy and security concepts such as personal data, data lifecycle, purpose limitation, access controls, vendor risk, incident response, or accountability.
  • Exposure to privacy, AI, or security standards and frameworks such as ISO 27701, ISO 27018, Global CBPR, PRP, ISO 42001, ISO 27001, SOC 2, NIST, or similar frameworks.
  • Ability to explain legal, policy, or technical concepts clearly to both expert and non-expert stakeholders.
  • Strong documentation, note-taking, and technical writing skills.
  • Ability to organize information into a durable and navigable repository, tracker, or knowledge base.
  • Comfort engaging internal stakeholders, asking clear follow-up questions, and reconciling incomplete or conflicting information.
  • Analytical thinking and attention to detail when reviewing evidence, controls, and process descriptions.
  • Experience with spreadsheets, dashboards, workflow tooling, or basic automation.
  • Interest in using AI-assisted tools, low-code/no-code platforms, or light scripting to improve workflows and reporting.
  • Demonstrated critical thinking skills and the ability to learn new topics quickly.
  • Curiosity, empathy, discretion, and ability to get things done.
  • Ability to commit to a minimum 12-week fall internship.
  • Ability to work in the office 3–5 days a week in the location of the internship.
  • Coursework or project work in privacy law, data protection, AI policy, cyber law, technology governance, or related fields.
  • Experience conducting research, policy analysis, compliance mapping, or process documentation.
  • Experience building simple dashboards, internal tools, or prototypes using spreadsheets, scripts, or AI-assisted coding.
  • Demonstrated interest in responsible AI, privacy engineering, or governance operations.
  • Familiarity with Cloudflare products such as Workers, Workers AI, R2, or D1.

We’re not just a highly ambitious, large-scale technology company.

We’re a highly ambitious, large-scale technology company with a soul.

Fundamental to our mission to help build a better Internet is protecting the free and open Internet.

Project Galileo

: Since 2014, we've equipped more than 2,400 journalism and civil society organizations in 111 countries with powerful tools to defend themselves against attacks that would otherwise censor their work, technology already used by Cloudflare’s enterprise customers--at no cost.

Athenian Project

: In 2017, we created the Athenian Project to ensure that state and local governments have the highest level of protection and reliability for free, so that their constituents have access to election information and voter registration.

Since the project, we've provided services to more than 425 local government election websites in 33 states.

1.1.1.1

: We released 1.1.1.1 to help fix the foundation of the Internet by building a faster, more secure and privacy-centric public DNS resolver.

This is available publicly for everyone to use - it is the first consumer-focused service Cloudflare has ever released.

Here’s the deal - we don’t store client IP addresses never, ever.

We will continue to abide by our privacy commitment and ensure that no user data is sold to advertisers or used to target consumers.

Sound like something you’d like to be a part of? We’d love to hear from you!

This position may require access to information protected under U.

S. export control laws, including the U.

Export Administration Regulations.

Please note that any offer of employment may be conditioned on your authorization to receive software or technology controlled under these U.

S. export laws without sponsorship for an export license.

Cloudflare is proud to be an equal opportunity employer.

We are committed to providing equal employment opportunity for all people and place great value in both diversity and inclusiveness.

All qualified applicants will be considered for employment without regard to their, or any other person's, perceived or actual race, color, religion, sex, gender, gender identity, gender expression, sexual orientation, national origin, ancestry, citizenship, age, physical or mental disability, medical condition, family care status, or any other basis protected by law.

We are an AA/Veterans/Disabled Employer.

Cloudflare provides reasonable accommodations to qualified individuals with disabilities.

Please tell us if you require a reasonable accommodation to apply for a job.

Examples of reasonable accommodations include, but are not limited to, changing the application process, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment.

If you require a reasonable accommodation to apply for a job, please contact us via e‑mail at hr@cloudflare. com or via mail at 101 Townsend St.

San Francisco, CA 94107.

#J-18808-Ljbffr

GRC Team Intern (Fall 2026) employer: CloudFlare

Cloudflare is an exceptional employer that fosters a culture of innovation and collaboration, making it an ideal place for aspiring AI professionals. Located in London, the company offers a dynamic work environment where interns can gain hands-on experience with cutting-edge technology while receiving mentorship from industry experts. With a strong commitment to employee growth and a mission-driven approach to building a better Internet, Cloudflare provides unique opportunities for meaningful contributions and personal development.

CloudFlare

Contact Details:

CloudFlare Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land GRC Team Intern (Fall 2026)

Get Involved in Cybersecurity Communities

Join local and online cybersecurity groups like OWASP or (ISC)² chapters. Engaging with these communities will help you build connections, learn from experts, and keep you in the loop about internship opportunities. Plus, you might even find mentors who can help you navigate this exciting field!

Attend Cybersecurity Events and Conferences

Look out for conferences and meetups happening in your area or even virtual ones! Events like DEF CON or Black Hat provide a fantastic opportunity to meet industry professionals and discover internship openings while deepening your knowledge of current trends and issues.

Utilise University Resources

Don’t forget about your university’s career services! They often have exclusive internships listed and can connect you with alumni working in cybersecurity. This can be a game-changer to land that coveted spot, so make sure to tap into that resource.

Show Off Your Skills Online

As you build your cybersecurity skills, create a public portfolio showcasing your projects, like any vulnerabilities you've found or secure systems you've built. This will not only demonstrate your passion but also serve as a conversation starter when you’re networking or interviewing—don’t shy away from sharing it with firms like CloudFlare when applying!

We think you need these skills to ace GRC Team Intern (Fall 2026)

Privacy and Data Protection
AI Governance
Regulatory Compliance
ISO 27701
ISO 27018
Global CBPR / PRP
ISO 42001

Some tips for your application 🫡

Show Off Your Skills:In the cybersecurity world, it's all about those technical skills! Make sure to highlight any relevant coursework or certifications, like CompTIA Security+ or Ethical Hacking. If you’ve got any hands-on experience with tools like Wireshark or Metasploit, include that too—it'll really make your application pop!

Demonstrate Your Practical Knowledge:Internships are often about potential and eagerness to learn, so don’t shy away from mentioning personal projects or labs you've worked on. If you've set up your own home network security or participated in any Capture The Flag challenges, definitely put that in your cover letter. It shows initiative and a genuine interest in the field!

Tailor Your CV to the Cybersecurity Landscape:When crafting your CV, look at industry standards – keep it concise and focused on relevant experience. Cybersecurity CVs often benefit from clear sections on skills, projects, and education. Make sure to include technical skills and languages relevant to cybersecurity, like Python or Bash scripting. This helps us see exactly what you bring to the table at CloudFlare!

Let Your Passion Shine Through:Since you're applying for an internship, we want to hear about your motivation for getting into cybersecurity. Don’t be afraid to express your enthusiasm in your cover letter. Tell us about what excites you in the field, whether it's defending against cyber threats or exploring how to secure data. This personal touch can make a big difference in showing your fit for CloudFlare!

How to prepare for a job interview at CloudFlare

Show your passion for security

Make sure to highlight your genuine interest in cybersecurity. Share any personal projects, labs, or games you've engaged with, like capture the flag challenges or online courses. This enthusiasm can set you apart as an intern, showing that you're keen to learn and grow.

Brush up on technical skills

Expect some technical questions that test your understanding of basic cybersecurity concepts like firewalls, encryption, and malware analysis. Familiarise yourself with common tools and platforms such as Wireshark or Metasploit, as these might come up in conversation or practical scenarios during the interview.

Prepare for real-world problem-solving

Be ready to tackle hypothetical scenarios where you must defend a system or respond to a security breach. Practising your thought process on these types of questions can help demonstrate your analytical skills and ability to think on your feet.

Emphasise your learning potential

Since this is an internship, the company is looking for eagerness to learn more than a polished resume. Be open about areas you want to improve in, and express your willingness to tackle challenges head-on. This mindset shows you're ready to grow alongside the team at CloudFlare.