Senior GRC Analyst for Common Controls Framework

salesforce.com, inc.

San Francisco (CA)

On-site

USD 117,000 - 177,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Salesforce is seeking an Analyst to support the Common Controls Framework (CCF) program. You will work on security governance, GRC, and operational/product-management tasks, becoming a trusted advisor to security and compliance stakeholders.

You'll map controls to frameworks, maintain control documentation, and drive efficiency and automation across certification programs while collaborating with Eng, Legal, Privacy, and Product teams. Strong English communication and independence are essential.

Qualifications

  • 3+ years in security governance, GRC, or compliance operations at a tech company.
  • Direct security-domain experience to read controls, understand risk, and challenge a draft.
  • Ability to write clear, concise standards, policies, or procedures for non-security readers.
  • Working knowledge of major security/privacy frameworks (SOC 2, ISO 27001, NIST CSF, FedRAMP, PCI, HIPAA, EU AI Act).
  • Comfort running cross-functional review cycles with senior stakeholders (Engineering, Legal, Privacy, Product).
  • Strong attention to detail - versioning, traceability, review dates, approver signatures.
  • Experience with a GRC platform (Salesforce eGRC, ServiceNow GRC, Archer, OneTrust, LogicGate).
  • Excellent written and verbal English communication.
  • Ability to work independently across many parallel workstreams.
  • Highest level of ethics, independence, and professionalism.

Responsibilities

  • Support the design, maintenance, and evolution of the CCF and its implementation across all Salesforce compliance certification programs.
  • Map common controls to applicable frameworks, standards, and certification requirements, identifying reuse opportunities across programs.
  • Maintain and update controls throughout their lifecycle - descriptions, mappings, applicability, implementation guidance.
  • Support certification programs by analyzing requirements, identifying control coverage, and streamlining assessment processes and timelines.
  • Partner cross-functionally to support CCF adoption and implementation.
  • Research emerging regulations, standards, and certification requirements for potential impact on the CCF.
  • Analyze controls and framework requirements for opportunities to standardize, reuse, and increase efficiency.
  • Support efforts to reduce compliance burden by improving CCF processes, controls, and implementation strategies.
  • Support identification and implementation of compliance automation opportunities.
  • Develop and maintain reporting, metrics, and analyses on CCF adoption, control coverage, and certification readiness.
  • Identify and track control gaps and inconsistencies, escalating to senior team members as needed.
  • Maintain accurate, current CCF documentation and supporting materials.
  • Stay informed on regulatory, standards, and compliance trends, and share relevant updates with the team.
  • As experience grows, take ownership of defined controls, mappings, or workstreams and drive their maintenance and improvement.
  • Use AI and generative-AI tooling responsibly to enhance CCF processes, stakeholder engagement, and data management.

Skills

Security governance
Security domain
Technical writing
Security framework knowledge
Cross-functional collaboration
Attention to detail
GRC platform experience
English communication
Independent work
Ethics and professionalism

Tools

Salesforce eGRC
ServiceNow GRC
Archer
OneTrust
LogicGate

Job description

Salesforce is seeking an Analyst to support the Common Controls Framework (CCF) program. You will work on security governance, GRC, and operational/product-management tasks, becoming a trusted advisor to security and compliance stakeholders.

You'll map controls to frameworks, maintain control documentation, and drive efficiency and automation across certification programs while collaborating with Eng, Legal, Privacy, and Product teams. Strong English communication and independence are essential.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior GRC Analyst: Common Controls & Frameworks
Senior GRC Analyst: Common Controls & Frameworks

salesforce.com, inc. • Bellevue (WA)

On-site
USD 117,000 - 194,000
Senior GRC Analyst — Common Controls & AI Governance
Senior GRC Analyst — Common Controls & AI Governance

Salesforce • San Francisco (CA)

On-site
USD 117,000 - 177,000
Senior GRC Analyst, Common Controls — Hybrid
Senior GRC Analyst, Common Controls — Hybrid

Salesforce, Inc. • Virginia (MN), Northern (KY)

Hybrid
USD 117,000 - 177,000
Strategic GRC & Common Controls Analyst (CCF)
Strategic GRC & Common Controls Analyst (CCF)

salesforce.com, inc. • Herndon (VA)

On-site
USD 117,000 - 177,000
Senior GRC & Policy Operations Lead
Senior GRC & Policy Operations Lead

Salesforce • San Francisco (CA)

On-site
USD 117,000 - 177,000
Senior GRC Policy Operations Analyst
Senior GRC Policy Operations Analyst

100 Salesforce, Inc. • Washington

On-site
USD 117,000 - 177,000
Senior GRC Policy Operations Lead
Senior GRC Policy Operations Lead

Salesforce, Inc. • Virginia (MN), Northern (KY)

Hybrid
USD 117,000 - 177,000
Accommodations available
Senior Policy & GRC Operations Analyst
Senior Policy & GRC Operations Analyst

salesforce.com, inc. • San Francisco (CA)

On-site
USD 117,000 - 177,000
Senior GRC Policy Operations Lead
Senior GRC Policy Operations Lead

salesforce.com, inc. • Seattle (WA)

On-site
USD 117,000 - 177,000
Medical
Dental
Vision
+5
Senior GRC Policy Operations Lead
Senior GRC Policy Operations Lead

salesforce.com, inc. • Herndon (VA)

On-site
USD 117,000 - 177,000
Time off programs
Medical
Dental
+6