Paul Goerke
Manager @EY
Signup · Get unlimited contacts
WORK HISTORY
Manager @EY
Salt Lake City, UT, US
EDUCATION
University of Utah - David Eccles School of Business
Bachelor of Science (BS), Computer and Information Systems, Finance
SKILLS
ABOUT PAUL GOERKE
Navigating the ever-evolving landscape of IT risk and compliance requires more than just technical expertise, it demands strategic vision, cross-functional leadership, and a proactive approach to security. With 13+ years of experience in IT Governance, Risk, and Compliance (GRC), I help organizations strengthen security postures, streamline compliance initiatives, and align IT risk strategies with overarching business goals.Throughout my career, I’ve served as a trusted advisor to executives and business leaders, ensuring regulatory compliance while fostering a culture of risk awareness. My expertise spans IT SOX 404, SOC 1 & SOC 2, ISO 27001, PCI DSS, GDPR, FedRAMP, HIPAA, and leading cybersecurity frameworks (NIST CSF, NIST 800-53, ISO 27001, CIS, COBIT). Whether securing cloud environments (AWS, Azure) or optimizing on-premises infrastructures, I bring a data-driven, automation-focused approach to enhancing efficiency and risk visibility.Key Achievements & Expertise:Compliance Program Transformation – Spearheaded IT risk and compliance initiatives for Fortune 500 companies, reducing audit execution and remediation timelines through process enhancements, control rationalization, and automation.Enterprise Risk Management – Partnered with C-suite executives to align IT risk management with business strategies, reducing enterprise risk exposure and strengthening security frameworks.Governance & Policy Development – Designed and implemented scalable IT risk frameworks (NIST CSF, ISO 27001, SOC 2), leading to a 15% reduction in audit findings year-over-year.Technology & Automation – Led the deployment of GRC tools (ServiceNow, AuditBoard) to streamline workflows, achieving a 30% reduction in hours spent on IT audits.Data-Driven Insights – Built executive dashboards using Tableau and Power BI, delivering actionable intelligence that improved risk visibility and decision-making.Core CompetenciesIT Audit | Third-Party Risk Management | Enterprise Risk Management | Cybersecurity | Cloud Security | Governance, Risk, and Compliance (GRC)| Vulnerability Management | Business Continuity Planning | Compliance Audits | Policy Development | Internal/External Audits | Regulatory Compliance | Legal Coordination | Security Systems | Threat Management | Vendor Management | Business Risk | Continuous Improvement | Incident Response | Data Security
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.