Senior GRC Policy Operations Lead

Own Company

San Francisco (CA)

On-site

USD 120,000 - 180,000

Full time

5 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Time off
Medical coverage
Dental
Vision
Mental health support
Parental leave
Life insurance
Disability insurance
401(k)
ESPP

Job summary

Salesforce is seeking an Analyst to run day-to-day operations of the Security Standards and policy program, coordinating intake, drafting support, reviews, publication, and retirement. You will work across Security, Compliance, and Engineering to translate obligations into clear, actionable requirements while maintaining high-quality stakeholder engagement.

In this role you will enable governance across frameworks like SOC 2, ISO 27001, and NIST CSF,Partner with Security Architecture, ProdSec,

Qualifications

  • 3+ years in security governance, GRC, technical writing, program management, or compliance operations at a software/product tech company.
  • U.S. Citizenship or Permanent Residency. We are unable to provide visa sponsorship for this role.
  • Direct security-domain experience (AppSec, cloud security, IAM, vulnerability management, or GRC-adjacent).
  • Proven ability to write clear standards/policies non-security readers can act on.
  • Working knowledge of a major security/privacy framework (SOC 2, ISO 27001, NIST CSF, FedRAMP, PCI, HIPAA, EU AI Act, or equivalent).
  • Comfort running cross-functional review cycles with senior stakeholders.
  • Experience with Git; familiarity with OSCAL and Markdown.
  • Experience with a GRC platform (Salesforce eGRC, ServiceNow GRC, Archer, OneTrust, LogicGate, or similar).
  • Excellent written and verbal English communication.
  • Ability to work independently across many parallel workstreams.
  • Highest level of ethics, independence, and professionalism.

Responsibilities

  • Prioritize intake for new/updated standards, policies, and control documents — assign owners and set realistic timelines.
  • Build standards in plain, unambiguous language with crisp technical requirements in collaboration with SMEs.
  • Facilitate the review/approval cycle end-to-end — schedule CAB reviews, prep read-aheads, capture decisions, track actions.
  • Manage: Publish approved standards to the eGRC platform and retire superseded documents.
  • Operate: Keep standards register traceable to external obligations (SOC 2, ISO 27001, etc.).
  • Maintain: Run content reviews so every standard has an owner, current review date, and ownership map.
  • Monitor: Build dashboards on standards health — coverage, freshness, adoption signals.
  • Improve: Support onboarding of new standards driven by high-priority initiatives.
  • Announce: Coordinate stakeholder communications — changelogs, engineering briefings, Slack updates.
  • Partner: Work with Exception Management to define paired exception paths.
  • Optimize: Improve templates, workflows, and config to reduce cycle time without sacrificing quality.
  • Advance: Use AI/GenAI tooling to accelerate drafting, redlining, and summarization with human review.

Skills

Security governance
GRC
Technical writing
Program management
Compliance operations
Git
OSCAL
Markdown
GRC platform
English communication

Education

Bachelor's degree

Tools

Git
OSCAL
Markdown

Job description

Salesforce is seeking an Analyst to run day-to-day operations of the Security Standards and policy program, coordinating intake, drafting support, reviews, publication, and retirement. You will work across Security, Compliance, and Engineering to translate obligations into clear, actionable requirements while maintaining high-quality stakeholder engagement.

In this role you will enable governance across frameworks like SOC 2, ISO 27001, and NIST CSF,Partner with Security Architecture, ProdSec,

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior GRC Policy Operations Lead
Senior GRC Policy Operations Lead

salesforce.com, inc. • Herndon (VA)

On-site
USD 117,000 - 177,000
Time off programs
Medical
Dental
+6
Senior GRC Policy Operations Lead
Senior GRC Policy Operations Lead

salesforce.com, inc. • Seattle (WA)

On-site
USD 117,000 - 177,000
Medical
Dental
Vision
+5
Senior GRC & Policy Operations Lead
Senior GRC & Policy Operations Lead

Salesforce • San Francisco (CA)

On-site
USD 117,000 - 177,000
Senior GRC Policy Operations Analyst
Senior GRC Policy Operations Analyst

100 Salesforce, Inc. • Washington

On-site
USD 117,000 - 177,000
Senior GRC Policy Operations Lead
Senior GRC Policy Operations Lead

Salesforce, Inc. • Virginia (MN), Northern (KY)

Hybrid
USD 117,000 - 177,000
Accommodations available
Senior Policy & GRC Operations Analyst
Senior Policy & GRC Operations Analyst

salesforce.com, inc. • San Francisco (CA)

On-site
USD 117,000 - 177,000
Senior GRC Analyst — Common Controls Lead
Senior GRC Analyst — Common Controls Lead

Own Company • San Francisco (CA)

On-site
USD 120,000 - 170,000
Health insurance
401(k) matching
Employee stock purchase program
+5
Senior GRC Analyst — Common Controls & AI Governance
Senior GRC Analyst — Common Controls & AI Governance

Salesforce • San Francisco (CA)

On-site
USD 117,000 - 177,000
Senior GRC Analyst for Common Controls Framework
Senior GRC Analyst for Common Controls Framework

salesforce.com, inc. • San Francisco (CA)

On-site
USD 117,000 - 177,000
Senior Security GRC Analyst — Federal Compliance
Senior Security GRC Analyst — Federal Compliance

salesforce.com, inc. • Washington

On-site
USD 117,000 - 177,000