Senior GRC & Policy Operations Lead

Salesforce

San Francisco (CA)

On-site

USD 117,000 - 177,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Salesforce is seeking an Analyst to join the Security Governance team. You will own the standards lifecycle, from intake and drafting to review, publication, and retirement, ensuring alignment with external obligations and internal controls.

The role requires strong policy writing, governance experience, and the ability to manage multiple stakeholders across engineering, security, and legal. A solid understanding of major frameworks and experience with GRC platforms is essential.

Qualifications

  • 3+ years in security governance, GRC, technical writing, program management, or compliance operations at a software/product tech company.
  • U.S. Citizenship or Permanent Residency. We are unable to provide visa sponsorship for this role.
  • Direct security-domain experience (AppSec, cloud security, IAM, vulnerability management, or GRC-adjacent).
  • Proven ability to write clear standards/policies non-security readers can act on.
  • Working knowledge of SOC 2, ISO 27001, NIST CSF, FedRAMP, PCI, HIPAA, EU AI Act, or equivalent.
  • Experience with Git; familiarity with OSCAL and Markdown.
  • Experience with a GRC platform (Salesforce eGRC, ServiceNow GRC, Archer, OneTrust, LogicGate, or similar).
  • Excellent written and verbal English communication.
  • Ability to work independently across many parallel workstreams.
  • Highest level of ethics, independence, and professionalism.

Responsibilities

  • Triage intake for new/updated standards, policies, and control documents; assign owners and timelines.
  • Draft and finalize standards with SMEs to ensure clear, actionable requirements.
  • Own the review/approval cycle end-to-end; schedule CAB reviews and track decisions.
  • Publish approved standards to the eGRC platform and retire superseded documents.
  • Maintain standards traceability to external obligations (SOC 2, ISO 27001, FedRAMP, EU AI Act, NIST CSF).
  • Run content reviews to ensure owner and current review dates exist; flag drift.
  • Build dashboards on standards health: coverage, freshness, adoption signals.

Skills

Security governance
GRC
Technical writing
Program management
Compliance operations
English communication

Education

Bachelor's degree in a related field

Tools

Git
OSCAL
Markdown
Salesforce eGRC
ServiceNow GRC
Archer
OneTrust
LogicGate

Job description

Salesforce is seeking an Analyst to join the Security Governance team. You will own the standards lifecycle, from intake and drafting to review, publication, and retirement, ensuring alignment with external obligations and internal controls.

The role requires strong policy writing, governance experience, and the ability to manage multiple stakeholders across engineering, security, and legal. A solid understanding of major frameworks and experience with GRC platforms is essential.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior GRC Policy Operations Lead
Senior GRC Policy Operations Lead

salesforce.com, inc. • Seattle (WA)

On-site
USD 117,000 - 177,000
Medical
Dental
Vision
+5
Senior GRC Policy Operations Lead
Senior GRC Policy Operations Lead

Salesforce, Inc. • Virginia (MN), Northern (KY)

Hybrid
USD 117,000 - 177,000
Accommodations available
Senior GRC Policy Operations Analyst
Senior GRC Policy Operations Analyst

100 Salesforce, Inc. • Washington

On-site
USD 117,000 - 177,000
Senior GRC Policy Operations Lead
Senior GRC Policy Operations Lead

salesforce.com, inc. • Herndon (VA)

On-site
USD 117,000 - 177,000
Time off programs
Medical
Dental
+6
Senior Policy & GRC Operations Analyst
Senior Policy & GRC Operations Analyst

salesforce.com, inc. • San Francisco (CA)

On-site
USD 117,000 - 177,000
Senior GRC Analyst — Common Controls & AI Governance
Senior GRC Analyst — Common Controls & AI Governance

Salesforce • San Francisco (CA)

On-site
USD 117,000 - 177,000
Senior GRC Analyst for Common Controls Framework
Senior GRC Analyst for Common Controls Framework

salesforce.com, inc. • San Francisco (CA)

On-site
USD 117,000 - 177,000
Senior GRC Analyst, Common Controls — Hybrid
Senior GRC Analyst, Common Controls — Hybrid

Salesforce, Inc. • Virginia (MN), Northern (KY)

Hybrid
USD 117,000 - 177,000
Senior Security GRC Analyst — Federal Compliance
Senior Security GRC Analyst — Federal Compliance

salesforce.com, inc. • Washington

On-site
USD 117,000 - 177,000
Strategic GRC & Common Controls Analyst (CCF)
Strategic GRC & Common Controls Analyst (CCF)

salesforce.com, inc. • Herndon (VA)

On-site
USD 117,000 - 177,000