Senior Policy & GRC Operations Analyst

salesforce.com, inc.

San Francisco (CA)

On-site

USD 117,000 - 177,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Salesforce is seeking an Analyst for the Security Governance team in the United States. You will own intake, drafting, and end-to-end review of security standards and policies, collaborating with Security Architecture, ProdSec, Trust, Privacy, and Legal.

You’ll publish to the eGRC platform and ensure ongoing control health and ownership maps. You’ll coordinate CAB reviews, drive attestations, and advance AI-enabled drafting while maintaining high standards of clarity and compliance across

Qualifications

  • 3+ years in security governance, GRC, technical writing, program management, or compliance operations at a software/product tech company.
  • U.S. Citizenship or Permanent Residency. We are unable to provide visa sponsorship for this role.
  • Direct security-domain experience (AppSec, cloud security, IAM, vulnerability management, or GRC-adjacent).
  • Proven ability to write clear standards/policies non-security readers can act on.
  • Working knowledge of a major security/privacy framework (SOC 2, ISO 27001, NIST CSF, FedRAMP, PCI, HIPAA, EU AI Act, or equivalent).
  • Comfort running cross-functional review cycles with senior stakeholders.
  • Experience with Git; familiarity with OSCAL and Markdown.
  • Experience with a GRC platform (Salesforce eGRC, ServiceNow GRC, Archer, OneTrust, LogicGate, or similar).
  • Excellent written and verbal English communication.
  • Ability to work independently across many parallel workstreams.
  • Highest level of ethics, independence, and professionalism.

Responsibilities

  • Prioritize intake for new/updated standards, policies, and control documents; assign owners and timelines.
  • Build standards with SMEs to draft clear, plain-language requirements.
  • Facilitate end-to-end review cycles; schedule CAB reviews and capture decisions.
  • Publish approved standards to the eGRC platform and retire superseded documents.
  • Maintain traceability from external obligations to SFSS controls; update ownership maps.
  • Run content reviews to ensure current owner, review date, and clear accountability.
  • Monitor standards health with dashboards on coverage, freshness, and adoption.
  • Support onboarding of new standards driven by high-priority initiatives.
  • Coordinate stakeholder communications via changelogs and engineering briefings.
  • Partner with Exception Management for paired exception paths and evidence.
  • Optimize operating model with templates, workflows, and configs to reduce cycle time.
  • Advance AI/GenAI tooling with human review to accelerate drafting and redlining.

Skills

Security governance
GRC
Technical writing
Policy development
Program management
Stakeholder management
OSCAL
Git
Markdown
SOC 2
ISO 27001
NIST CSF
FedRAMP
AI governance

Tools

Git
OSCAL
Markdown
Salesforce eGRC
ServiceNow GRC
Archer
OneTrust
LogicGate

Job description

Salesforce is seeking an Analyst for the Security Governance team in the United States. You will own intake, drafting, and end-to-end review of security standards and policies, collaborating with Security Architecture, ProdSec, Trust, Privacy, and Legal.

You’ll publish to the eGRC platform and ensure ongoing control health and ownership maps. You’ll coordinate CAB reviews, drive attestations, and advance AI-enabled drafting while maintaining high standards of clarity and compliance across

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior GRC Policy Operations Lead
Senior GRC Policy Operations Lead

Salesforce, Inc. • Virginia (MN), Northern (KY)

Hybrid
USD 117,000 - 177,000
Accommodations available
Senior GRC & Policy Operations Lead
Senior GRC & Policy Operations Lead

Salesforce • San Francisco (CA)

On-site
USD 117,000 - 177,000
Senior GRC Policy Operations Analyst
Senior GRC Policy Operations Analyst

100 Salesforce, Inc. • Washington

On-site
USD 117,000 - 177,000
Senior GRC Policy Operations Lead
Senior GRC Policy Operations Lead

salesforce.com, inc. • Seattle (WA)

On-site
USD 117,000 - 177,000
Medical
Dental
Vision
+5
Senior GRC Policy Operations Lead
Senior GRC Policy Operations Lead

salesforce.com, inc. • Herndon (VA)

On-site
USD 117,000 - 177,000
Time off programs
Medical
Dental
+6
Senior Security GRC Analyst — Federal Compliance
Senior Security GRC Analyst — Federal Compliance

salesforce.com, inc. • Washington

On-site
USD 117,000 - 177,000
Senior Security GRC Analyst - Federal Cloud Compliance
Senior Security GRC Analyst - Federal Cloud Compliance

salesforce.com, inc. • McLean (VA)

On-site
USD 117,000 - 177,000
Senior GRC Analyst — Common Controls & AI Governance
Senior GRC Analyst — Common Controls & AI Governance

Salesforce • San Francisco (CA)

On-site
USD 117,000 - 177,000
Strategic GRC & Common Controls Analyst (CCF)
Strategic GRC & Common Controls Analyst (CCF)

salesforce.com, inc. • Herndon (VA)

On-site
USD 117,000 - 177,000
Senior Security GRC Analyst – Government Cloud
Senior Security GRC Analyst – Government Cloud

salesforce.com, inc. • Herndon (VA)

On-site
USD 117,000 - 177,000