Paul Goerke

Manager @EY

Coronado, CA, US
EMAILS
p••••••@confluent.io
MOBILE NUMBERS
+13•••••••29

Signup · Get unlimited contacts

WORK HISTORY

Oct 2017 — Present

Manager @EY

View department →

Salt Lake City, UT, US

EDUCATION

2006 — 2011

University of Utah - David Eccles School of Business

Bachelor of Science (BS), Computer and Information Systems, Finance

SKILLS

Sarbanes-Oxley ActBusiness IntelligenceInternal ControlsDue DiligenceItgcData AnalysisRisk ManagementMicrosoft OfficeIT AuditBusiness AnalysisFinancial Statement AnalysisTableauFinancial ReportingManagement ConsultingBusiness ProcessAnalyticsSegregation of DutiesBusiness Process ImprovementIT StrategyMicrosoft Sql ServerCisaMicrosoft ExcelUs GaapAnalysisCobitSarbanes-OxleyBusiness ValuationFinanceManagementGaapAuditingProcess ImprovementAccessCorporate FinanceValuationFinancial ServicesInformation SecurityLeadershipSharepointFinancial Modeling

ABOUT PAUL GOERKE

Navigating the ever-evolving landscape of IT risk and compliance requires more than just technical expertise, it demands strategic vision, cross-functional leadership, and a proactive approach to security. With 13+ years of experience in IT Governance, Risk, and Compliance (GRC), I help organizations strengthen security postures, streamline compliance initiatives, and align IT risk strategies with overarching business goals.Throughout my career, I’ve served as a trusted advisor to executives and business leaders, ensuring regulatory compliance while fostering a culture of risk awareness. My expertise spans IT SOX 404, SOC 1 & SOC 2, ISO 27001, PCI DSS, GDPR, FedRAMP, HIPAA, and leading cybersecurity frameworks (NIST CSF, NIST 800-53, ISO 27001, CIS, COBIT). Whether securing cloud environments (AWS, Azure) or optimizing on-premises infrastructures, I bring a data-driven, automation-focused approach to enhancing efficiency and risk visibility.Key Achievements & Expertise:Compliance Program Transformation – Spearheaded IT risk and compliance initiatives for Fortune 500 companies, reducing audit execution and remediation timelines through process enhancements, control rationalization, and automation.Enterprise Risk Management – Partnered with C-suite executives to align IT risk management with business strategies, reducing enterprise risk exposure and strengthening security frameworks.Governance & Policy Development – Designed and implemented scalable IT risk frameworks (NIST CSF, ISO 27001, SOC 2), leading to a 15% reduction in audit findings year-over-year.Technology & Automation – Led the deployment of GRC tools (ServiceNow, AuditBoard) to streamline workflows, achieving a 30% reduction in hours spent on IT audits.Data-Driven Insights – Built executive dashboards using Tableau and Power BI, delivering actionable intelligence that improved risk visibility and decision-making.Core CompetenciesIT Audit | Third-Party Risk Management | Enterprise Risk Management | Cybersecurity | Cloud Security | Governance, Risk, and Compliance (GRC)| Vulnerability Management | Business Continuity Planning | Compliance Audits | Policy Development | Internal/External Audits | Regulatory Compliance | Legal Coordination | Security Systems | Threat Management | Vendor Management | Business Risk | Continuous Improvement | Incident Response | Data Security

This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.