Senior Security GRC Analyst

Jobtailor

California (MO)

On-site

USD 120,000 - 170,000

Full time

5 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Jobtailor is seeking a cloud compliance expert to lead audits and risk remediation across large SaaS environments. You will work with engineering and product teams to translate regulatory requirements into concrete controls and evidence.

This role emphasizes automation of evidence collection and scalable compliance operations. The ideal candidate brings 4+ years in IT audit, strong ISO27001/SOC experience, and certifications such as CRISC/CISSP/CISM/CISA.

Qualifications

  • 4+ years of experience in IT audit or internal controls.
  • Experience managing global compliance assessments in complex environments, with focus on cloud and SaaS platforms.
  • Experience with ISO 27001, SOC, HIPAA, PCI, HITRUST, SOX, and FedRAMP.
  • Strong analytical and problem-solving skills.
  • Ability to assess risks, recommend solutions, and work independently.
  • Strong program and stakeholder management experience.
  • Cross-functional leadership experience.
  • Excellent organizational and documentation skills.
  • Experience in CSP Safety and ability to engage with Korean auditors preferred.
  • Experience with compliance tooling, control testing automation, or audit workflow platforms preferred.
  • Technical knowledge of hyperscaler environments such as AWS preferred.
  • Relevant certifications such as CRISC, CISSP, CISM, or CISA preferred.

Responsibilities

  • Serve as a cloud compliance subject matter expert.
  • Support internal and external audits, including leading walkthroughs with external assessors.
  • Ensure effective control implementation across Salesforce environments aligned with ISO 27001, SOC 1/2, and other regulatory frameworks.
  • Partner with engineering teams to translate compliance frameworks and regulatory mandates into actionable deliverables.
  • Ensure timely remediation and provide leadership reporting on progress and residual risk.
  • Identify opportunities to streamline and automate evidence collection.
  • Document detailed process playbooks.
  • Collaborate with cross-functional partners to operationalize audit recommendations.
  • Enhance Salesforce’s overall compliance posture.
  • Automate evidence collection and compliance operations to drive efficiency and continuous improvement.

Skills

Cloud compliance
Audit management
Cross-functional leadership
Regulatory compliance
Documentation skills

Education

CRISC
CISSP
CISM
CISA

Tools

Audit Workflow Platforms
Compliance Tooling
Salesforce
CSP Safety

Job description

  • Serve as a cloud compliance subject matter expert
  • Support internal and external audits, including leading walkthroughs with external assessors
  • Ensure effective control implementation across Salesforce environments aligned with ISO 27001, SOC 1/2, and other regulatory frameworks
  • Partner with engineering teams to translate compliance frameworks and regulatory mandates into actionable deliverables
  • Ensure timely remediation and provide leadership reporting on progress and residual risk
  • Identify opportunities to streamline and automate evidence collection
  • Document detailed process playbooks
  • Collaborate with cross-functional partners to operationalize audit recommendations
  • Enhance Salesforce’s overall compliance posture
  • Automate evidence collection and compliance operations to drive efficiency and continuous improvement
Requirements
  • 4+ years of experience in IT audit or internal controls
  • Experience managing global compliance assessments in complex environments, with a strong focus on cloud and SaaS platforms
  • Experience with ISO 27001, SOC, HIPAA, PCI, HITRUST, SOX, and FedRAMP
  • Strong analytical and problem-solving skills
  • Ability to assess risks, recommend solutions, and work independently
  • Strong program and stakeholder management experience
  • Cross-functional leadership experience
  • Excellent organizational and documentation skills
  • Experience in CSP Safety and ability to engage with Korean auditors preferred
  • Experience with compliance tooling, control testing automation, or audit workflow platforms preferred
  • Technical knowledge of hyperscaler environments such as AWS preferred
  • Relevant certifications such as CRISC, CISSP, CISM, or CISA preferred
Core Competencies

Demonstrates expertise in cloud compliance, particularly with ISO 27001, SOC, and other regulatory frameworks, while effectively managing audits and compliance assessments. Proven ability to collaborate with engineering teams to implement controls and enhance compliance operations.

Highest-signal resume keywords
  • Cloud Compliance Expertise
  • ISO 27001 Experience
  • Audit Management
  • Cross-Functional Leadership
  • Compliance Tooling Experience
Hard Skills
  • IT Audit
  • Internal Controls
  • Risk Assessment
  • Control Testing Automation
  • Evidence Collection Automation
  • Documentation Skills
  • Compliance Frameworks
  • Regulatory Compliance
  • SaaS Platforms
  • Hyperscaler Environments
Soft Skills
  • Analytical Skills
  • Problem-Solving Skills
  • Stakeholder Management
  • Organizational Skills
  • Independent Work
Certifications & Qualifications
  • CRISC
  • CISSP
  • CISM
  • CISA
Industry Keywords
  • SOC 1/2
  • HIPAA
  • PCI
  • HITRUST
  • SOX
  • FedRAMP
Tools & Technologies
  • Audit Workflow Platforms
  • Compliance Tooling
  • Salesforce
  • CSP Safety
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security GRC Analyst
Senior Security GRC Analyst

Salesforce • Washington

On-site
USD 120,000 - 170,000
Senior Cloud GRC Analyst - Salesforce Compliance & Audits
Senior Cloud GRC Analyst - Salesforce Compliance & Audits

Jobtailor • California (MO)

On-site
USD 120,000 - 170,000
Senior Security GRC Analyst
Senior Security GRC Analyst

Relha LLC • Bellevue (WA), Northern (KY)

Hybrid
USD 117,000 - 177,000
Senior Cloud Compliance & Audit Analyst
Senior Cloud Compliance & Audit Analyst

Relha LLC • Bellevue (WA), Northern (KY)

Hybrid
USD 117,000 - 177,000
Senior Cloud Compliance & Security GRC Analyst
Senior Cloud Compliance & Security GRC Analyst

Salesforce • Washington

On-site
USD 120,000 - 170,000
GRC Security Analyst — Unified Audit Lead
GRC Security Analyst — Unified Audit Lead

Salesforce • San Francisco (CA)

On-site
USD 96,000 - 146,000
Senior Security GRC Analyst
Senior Security GRC Analyst

Salesforce • San Francisco (CA)

On-site
USD 96,300 - 145,200
Manager, Security, Governance, Risk and Compliance
Manager, Security, Governance, Risk and Compliance

Jazz Pharmaceuticals • Northern (KY)

Hybrid
USD 120,000 - 180,000
Security Compliance Analyst
Security Compliance Analyst

Harbinger Motors • Garden Grove (CA)

On-site
USD 110,000 - 160,000
Stock options
Flexible PTO
Health coverage
+2
GRC Compliance Auditor
GRC Compliance Auditor

NorthMark Compute & Cloud • Dallas (TX)

On-site
USD 90,000 - 140,000