Senior Security GRC Analyst

salesforce.com, inc.

San Francisco (CA)

On-site

USD 96,300 - 145,200

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, dental, and vision coverage
Paid parental leave
Employee stock-purchasing program

Job summary

Salesforce.com, inc. is seeking a detail-oriented Security GRC Analyst to join their Security and Compliance team. In this role, you will lead the Unified Audit program ensuring compliance across various frameworks like SOC 2 and HIPAA, while managing evidence collection and liaising with external auditors.

The ideal candidate will have 2–4 years of relevant experience in GRC, compliance, or information security, along with proficiency in GRC tools. Salesforce values innovation and is committed to driving success through a diverse and inclusive workplace.

Qualifications

  • 2–4 years of experience in GRC, compliance, audit, or information security.
  • Hands-on experience supporting or managing compliance audits.
  • Relevant certifications like CISA, CRISC, CISSP preferred.

Responsibilities

  • Lead Unified Audit program across multiple frameworks.
  • Manage internal evidence collection for audits.
  • Serve as primary liaison with external auditors.

Skills

GRC, compliance, audit, or information security experience
Knowledge of SOC 2, HIPAA, ISO 27001, GxP frameworks
Proficiency with GRC tools
Clear communication skills

Tools

Microsoft Office Suite
Google Workspace
GRC platforms like Drata, Vanta, OneTrust

Job description

Job Category

Enterprise Technology & Infrastructure

About Salesforce

Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn't a buzzword – it's a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all.

Experience

The Security GRC Analyst role is part of our Security and Compliance team, sitting at the intersection of internal operations and external audit relationships. We are looking for a detail-oriented GRC Analyst to lead our Unified Audit program – keeping us compliant, audit-ready, and continuously improving across multiple frameworks.

What You’ll Actually Be Doing
  • Lead end-to-end Unified Audit program across SOC 2, HIPAA, ISO 27001, and GxP frameworks, coordinating schedules and minimizing duplication.
  • Manage internal evidence collection by assigning tasks to control owners, tracking deadlines, validating submissions, and conducting pre-audit gap reviews.
  • Serve as primary liaison with external auditors – scheduling walkthroughs, responding to information requests, and coordinating responses to findings.
  • Maintain compliance dashboards, standard operating procedures, and documentation repositories to support continuous monitoring and audit readiness.
You're Our Person If...
  • 2–4 years of experience in GRC, compliance, audit, or information security, with hands‑on experience supporting or managing compliance audits.
  • Working knowledge of at least two of the following frameworks: SOC 2, HIPAA, ISO 27001, or GxP.
  • Proficiency with GRC tools, audit management platforms, and documentation systems (Microsoft Office Suite or Google Workspace).
  • Clear communication with both technical and non‑technical stakeholders and the ability to manage multiple concurrent deadlines.
Even Better If...
  • Relevant certifications such as CISA, CRISC, CISSP, or ISO 27001 Lead Auditor/Implementer.
  • Experience with unified or integrated audit programs, or a background in healthcare or life sciences.
  • Hands‑on experience with GRC platforms such as Drata, Vanta, OneTrust, or ServiceNow GRC.
  • Direct work with external audit firms in a compliance or security capacity.
Accommodations

If you need a reasonable accommodation during the application or the recruiting process, please submit a request via the Accommodations Request Form.

Posting Statement

Salesforce is an equal opportunity employer and maintains a policy of non‑discrimination with all employees and applicants for employment. Any employee or potential employee will be assessed on the basis of merit, competence, and qualifications – without regard to race, religion, color, national origin, sex, sexual orientation, gender expression or identity, transgender status, age, disability, veteran or marital status, political viewpoint, or other classifications protected by law. This policy applies to recruiting, hiring, and promotion decisions at Salesforce.

Compensation & Benefits

In the United States, compensation offered will be determined by factors such as location, job level, job‑related knowledge, skills, and experience. The typical base salary range for this position is $96,300 – $145,200 annually. In select cities within the San Francisco and New York City metropolitan area, the base salary range for this role is $116,000 – $159,500 annually. The range represents base salary only and does not include company bonus, incentive, equity, or other benefits. Salesforce offers a variety of benefits to help you live well, including time‑off programs, medical, dental, vision, mental health support, paid parental leave, life and disability insurance, 401(k), and an employee stock‑purchasing program. Pursuant to the San Francisco Fair Chance Ordinance and the Los Angeles Fair Chance Initiative for Hiring, Salesforce will consider qualified applicants with arrest and conviction records. Salesforce believes in equitable compensation practices that reflect the dynamic nature of labor markets across regions.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security GRC Analyst
Senior Security GRC Analyst

Salesforce • San Francisco (CA)

On-site
USD 96,300 - 145,200
Senior Security GRC Analyst
Senior Security GRC Analyst

Relha LLC • San Francisco (CA)

On-site
USD 117,000 - 177,000
Senior Security GRC Analyst
Senior Security GRC Analyst

100 Salesforce, Inc. • San Francisco (CA)

On-site
USD 117,000 - 177,000
Time off programs
Medical insurance
Dental insurance
+6
Security GRC Analyst
Security GRC Analyst

Salesforce, Inc. • San Francisco (CA)

On-site
USD 96,000 - 146,000
Product Compliance Engineering - Senior Analyst
Product Compliance Engineering - Senior Analyst

salesforce.com, inc. • Bellevue (WA)

On-site
USD 117,000 - 177,000
Comprehensive medical, dental, vision benefits
401(k) plan
Paid parental leave
+1
Security Platform Engineer - MTS
Security Platform Engineer - MTS

salesforce.com, inc. • Bellevue (WA)

On-site
USD 117,000 - 177,000
Security Platform Engineer - MTS
Security Platform Engineer - MTS

Socket.dev • Bellevue (WA)

On-site
USD 117,000 - 177,000
Security Platform Engineer - MTS
Security Platform Engineer - MTS

100 Salesforce, Inc. • Bellevue (WA)

On-site
USD 117,000 - 177,000
Time off programs
Medical insurance
Dental insurance
+6
Product Compliance Engineering - Senior Analyst
Product Compliance Engineering - Senior Analyst

Salesforce, Inc. • Bellevue (WA)

Hybrid
USD 117,000 - 177,000
Manager, Compliance - Public Sector Contracts
Manager, Compliance - Public Sector Contracts

salesforce.com, inc. • Washington

On-site
USD 117,000 - 178,000