Senior Security GRC Analyst

Salesforce

Washington

On-site

USD 120,000 - 170,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Salesforce is seeking a seasoned cloud compliance professional to join the Global Compliance and Certification (GCC) team. You will partner with engineering to translate regulatory mandates into actionable controls and drive risk mitigation across Salesforce environments.

In this role, you will work with external auditors, translate frameworks into deliverables, and lead efforts to automate evidence collection and improve overall compliance posture in a fast-paced cloud-centric environment.

Qualifications

  • 4+ years of IT audit or internal controls experience.
  • Experience with compliance standards across industries and geographies (ISO 27001, SOC, HIPAA, PCI, HITRUST, SOX, FedRAMP).
  • Strong analytical and problem-solving skills with independent work style.

Responsibilities

  • Serve as cloud compliance SME, supporting audits and guiding control implementation across Salesforce environments for regulatory frameworks.
  • Translate complex mandates into actionable deliverables and provide leadership reporting on progress and residual risk.
  • Identify opportunities to automate evidence collection and document process playbooks to improve efficiency.
  • Collaborate with cross-functional partners to operationalize audit recommendations and enhance compliance posture.
  • Automate evidence collection and compliance operations to drive efficiency.

Skills

IT Audit
Internal Controls
Cloud/SaaS
ISO 27001
SOC
HIPAA
PCI
HITRUST
SOX
FedRAMP
Stakeholder Management
Analytical Thinking

Tools

Compliance tooling
Audit workflow platforms
AWS

Job description

Job Category

Enterprise Technology & Infrastructure

Job Details
About Salesforce

Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn't a buzzword - it's a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all.

Ready to level-up your career at the company leading workforce transformation in the agentic era? You're in the right place! Agentforce is the future of AI, and you are the future of Salesforce.

The Experience

The Global Compliance and Certification (GCC) team is responsible for enterprise-wide compliance processes, ensuring Salesforce leadership has the information needed to make strategic, risk-based decisions. The GCC team is a division within the Product Security Organization, and you'll play a pivotal role in partnering with engineering to translate complex mandates into actionable controls - driving continuous risk mitigation and adherence to Salesforce security frameworks.

We're looking for a compliance professional who is energized by the challenge of making complex regulatory requirements clear and actionable. In this role, you'll get to work across engineering, security, and external auditors to shape how Salesforce maintains its global compliance posture - gaining deep experience in cloud security frameworks and audit execution at scale.

What You'll Actually Be Doing
  • Serve as a cloud compliance subject matter expert, supporting internal and external audits - including leading walkthroughs with external assessors - by ensuring effective control implementation across Salesforce environments aligned with ISO 27001, Service Organization Controls (SOC) 1/2, and other regulatory frameworks.
  • Partner with engineering teams to translate complex compliance frameworks and regulatory mandates into clear, actionable deliverables, ensuring timely remediation and clear leadership reporting on progress and residual risk.
  • Identify opportunities to streamline and automate evidence collection, document detailed process playbooks, and drive operational efficiency and continuous improvement.
  • Collaborate with cross-functional partners to operationalize audit recommendations and enhance overall compliance posture.
  • Automate evidence collection and compliance operations to drive operational efficiency and continuous improvement.
You're Our Person If...
  • You have 4+ years of experience in IT audit or internal controls, managing global compliance assessments in complex environments with a strong focus on cloud and software-as-a-service (SaaS) platforms.
  • You have prior experience with compliance and regulatory standards across industries and geographies, including ISO 27001, SOC, Health Insurance Portability and Accountability Act (HIPAA), Payment Card Industry (PCI), Health Information Trust Alliance (HITRUST), Sarbanes-Oxley (SOX), and Federal Risk and Authorization Management Program (FedRAMP).
  • You bring strong analytical and problem-solving skills with the ability to assess risks, recommend solutions, and work independently in a fast-paced regulatory environment.
  • You have strong program and stakeholder management experience, including cross-functional leadership, with excellent organizational and documentation skills.
Even Better If...
  • You have experience in CSP Safety and are able to engage with Korean auditors.
  • You have experience with compliance tooling, control testing automation, or audit workflow platforms.
  • You have technical knowledge of hyperscaler environments such as Amazon Web Services (AWS).
  • You hold one or more relevant certifications such as Certified in Risk and Information Systems Control (CRISC), Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or Certified Information Systems Auditor (CISA).

Unleash Your Potential When you join Salesforce, you'll be limitless in all areas of your life. Our benefits and resources support you to find balance and be your best , and our AI agents accelerate your impact so you can do your best . Together, we'll bring the power of Agentforce to organizations of all sizes and deliver amazing experiences that customers love.

Accommodations

If you need a reasonable accommodation during the application or the recruiting process, please submit a request via this Accommodations Request Form.

Please note that Salesforce uses artificial intelligence (AI) tools to help our recruiters assess and evaluate candidates' resumes and qualifications throughout the

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security GRC Analyst
Senior Security GRC Analyst

Relha LLC • Bellevue (WA), Northern (KY)

Hybrid
USD 117,000 - 177,000
Senior Security GRC Analyst
Senior Security GRC Analyst

Salesforce • San Francisco (CA)

On-site
USD 96,300 - 145,200
Security Platform Engineer - MTS
Security Platform Engineer - MTS

Socket.dev • Bellevue (WA)

On-site
USD 117,000 - 177,000
Security GRC Senior Analyst
Security GRC Senior Analyst

Salesforce, Inc. • United States

On-site
USD 117,000 - 177,000
Security GRC Analyst
Security GRC Analyst

Salesforce, Inc. • San Francisco (CA)

On-site
USD 96,000 - 146,000
Security GRC Senior Analyst
Security GRC Senior Analyst

Relha LLC • Herndon (VA)

Hybrid
USD 149,000 - 224,000
Security GRC Senior Analyst
Security GRC Senior Analyst

Salesforce • Washington

On-site
USD 117,000 - 177,000
Manager, Office of the Chief Information Security Officer (OCISO)
Manager, Office of the Chief Information Security Officer (OCISO)

Salesforce, Inc. • New York (NY), Northern (KY)

Hybrid
USD 179,000 - 246,000
Product Vulnerability Engineer
Product Vulnerability Engineer

Salesforce, Inc. • Bellevue (WA), Northern (KY)

Hybrid
USD 117,000 - 177,000
Manager, Compliance - Public Sector Contracts
Manager, Compliance - Public Sector Contracts

salesforce.com, inc. • Washington

On-site
USD 117,000 - 178,000