Senior GRC Policy Operations Lead

salesforce.com, inc.

Seattle (WA)

On-site

USD 117,000 - 177,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Medical
Dental
Vision
Mental health support
Parental leave
Life and disability insurance
401(k)
Employee stock purchasing program

Job summary

Salesforce is hiring an Analyst for Security Governance to own the standards and policy program lifecycle, including intake, drafting, review, publication, and retirement. You will partner with Security Architecture, ProdSec, Trust, Privacy, and Legal to craft clear standards with precise requirements.

The role sits at the intersection of Security, Compliance, and Engineering, demanding strong writing, stakeholder management, and the ability to manage multiple parallel workstreams without

Qualifications

  • 3+ years in security governance, GRC, technical writing, program management, or compliance operations at a software/product tech company.
  • U.S. Citizenship or Permanent Residency. We are unable to provide visa sponsorship for this role.
  • Direct security-domain experience (AppSec, cloud security, IAM, vulnerability management, or GRC-adjacent) - deep enough to read controls, understand risk, and challenge a requester's draft.
  • Proven ability to write clear standards/policies non-security readers can act on.
  • Working knowledge of a major security/privacy framework (SOC 2, ISO 27001, NIST CSF, FedRAMP, PCI, HIPAA, EU AI Act, or equivalent).
  • Comfort running cross-functional review cycles with senior stakeholders.
  • Experience with Git; familiarity with OSCAL and Markdown.
  • Experience with a GRC platform (Salesforce eGRC, ServiceNow GRC, Archer, OneTrust, LogicGate, or similar).
  • Excellent written and verbal English communication.
  • Ability to work independently across many parallel workstreams.
  • Highest level of ethics, independence, and professionalism.

Responsibilities

  • Prioritize: Triage intake for new/updated standards, policies, and control documents - assign owners and set realistic timelines.
  • Build: Partner with SMEs to draft and finalize standards in plain, unambiguous language with crisp technical requirements.
  • Facilitate: Own the review/approval cycle end-to-end - schedule CAB reviews, prep read-aheads, capture decisions, track action items.
  • Manage: Publish approved standards to the eGRC platform and retire superseded documents.
  • Operate: Keep the standards register traceable from external obligations (SOC 2, ISO 27001, FedRAMP, EU AI Act, NIST CSF) to internal SFSS controls.
  • Maintain: Run content reviews so every standard has an owner, current review date, and clear ownership map.
  • Monitor: Build dashboards on standards health - coverage, freshness, exception load, adoption signals.
  • Improve: Support onboarding of new standards driven by high-priority initiatives.
  • Announce: Coordinate stakeholder comms - changelogs, engineering briefings, Slack updates.
  • Partner: Work with the Exception Management team so every standard has a paired exception path with defined approvers and evidence expectations.
  • Optimize: Improve the operating model - templates, workflows, checklists, eGRC config - to reduce cycle time without sacrificing quality.
  • Advance: Responsibly use AI/GenAI tooling to accelerate drafting, redlining, and summarization, with human-at-the-helm review.

Skills

Security governance
GRC
Technical writing
Program management
Compliance operations
English communication

Tools

Git
OSCAL
Markdown
Salesforce eGRC
OneTrust

Job description

Salesforce is hiring an Analyst for Security Governance to own the standards and policy program lifecycle, including intake, drafting, review, publication, and retirement. You will partner with Security Architecture, ProdSec, Trust, Privacy, and Legal to craft clear standards with precise requirements.

The role sits at the intersection of Security, Compliance, and Engineering, demanding strong writing, stakeholder management, and the ability to manage multiple parallel workstreams without

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior GRC & Policy Operations Lead
Senior GRC & Policy Operations Lead

Salesforce • San Francisco (CA)

On-site
USD 117,000 - 177,000
Senior GRC Policy Operations Lead
Senior GRC Policy Operations Lead

Salesforce, Inc. • Virginia (MN), Northern (KY)

Hybrid
USD 117,000 - 177,000
Accommodations available
Senior GRC Policy Operations Analyst
Senior GRC Policy Operations Analyst

100 Salesforce, Inc. • Washington

On-site
USD 117,000 - 177,000
Senior GRC Policy Operations Lead
Senior GRC Policy Operations Lead

salesforce.com, inc. • Herndon (VA)

On-site
USD 117,000 - 177,000
Time off programs
Medical
Dental
+6
Senior Policy & GRC Operations Analyst
Senior Policy & GRC Operations Analyst

salesforce.com, inc. • San Francisco (CA)

On-site
USD 117,000 - 177,000
Senior Security GRC Analyst — Federal Compliance
Senior Security GRC Analyst — Federal Compliance

salesforce.com, inc. • Washington

On-site
USD 117,000 - 177,000
Senior GRC Analyst — Common Controls & AI Governance
Senior GRC Analyst — Common Controls & AI Governance

Salesforce • San Francisco (CA)

On-site
USD 117,000 - 177,000
Senior Security GRC Analyst - Federal Cloud Compliance
Senior Security GRC Analyst - Federal Cloud Compliance

salesforce.com, inc. • McLean (VA)

On-site
USD 117,000 - 177,000
Senior GRC & Security Compliance Lead (Remote)
Senior GRC & Security Compliance Lead (Remote)

Shift Technology • Boston (MA)

Hybrid
USD 120,000 - 150,000
Flexible remote and hybrid options
Generous PTO and paid holidays
Mental health benefits
+2
Senior GRC Analyst for Common Controls Framework
Senior GRC Analyst for Common Controls Framework

salesforce.com, inc. • San Francisco (CA)

On-site
USD 117,000 - 177,000