Sr. GRC Analyst, Common Control Framework

Salesforce

San Francisco (CA)

On-site

USD 117,000 - 177,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Salesforce seeks an Analyst to support the Common Controls Framework (CCF) operations. You’ll apply security, GRC, and product-management expertise to advise security and compliance stakeholders across the business.

You’ll map controls to frameworks, update lifecycle documentation, and help streamline certification readiness while collaborating with Engineering, Legal, Privacy, and Product teams.

Qualifications

  • 3+ years in security governance, GRC, or compliance at a tech company.
  • Direct security-domain experience to read controls and assess risk.
  • Clear, concise standards or procedures for non-security readers.
  • Working knowledge of SOC 2, ISO 27001, NIST CSF, PCI, HIPAA or equivalent.
  • Comfort leading cross-functional reviews with senior stakeholders.
  • Experience with a GRC platform such as Salesforce eGRC / ServiceNow GRC.

Responsibilities

  • Support the design, maintenance, and evolution of the CCF program across Salesforce certifications.
  • Map controls to frameworks and requirements, identifying reuse opportunities.
  • Maintain controls lifecycle descriptions, mappings, applicability, and guidance.
  • Analyze requirements and streamline assessment timelines for certification.
  • Partner cross-functionally to drive CCF adoption and implementation.
  • Research regulations and standards affecting CCF and related programs.

Skills

Security governance
GRC
Technical writing
Program management
Compliance operations
SOQL

Tools

Salesforce eGRC
ServiceNow GRC
Archer
OneTrust
LogicGate

Job description

Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn’t a buzzword — it’s a way of life. The world of work as we know it is changing and we’re looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce’s core values at the heart of it all.

Ready to level-up your career at the company leading workforce transformation in the agentic era? You’re in the right place! Agentforce is the future of AI, and you are the future of Salesforce.

Enterprise Technology & Infrastructure

About the team

Salesforce's Common Controls Framework (CCF) program is the foundation of our security governance and compliance program, anchored in Trust, Transparency, and Accountability. We build, operate, and continuously improve a best-in-class, organizationally integrated, business-value-driven security controls management program.

We're hiring an Analyst to support day-to-day CCF operations. In this individual contributor role, you'll bring security, GRC, and operational/product-management expertise, quickly adapting to the program and becoming a trusted advisor to security and compliance stakeholders across the business.

What you'll be doing:
  • Support the design, maintenance, and evolution of the CCF and its implementation across all Salesforce compliance certification programs
  • Map common controls to applicable frameworks, standards, and certification requirements, identifying reuse opportunities across programs
  • Maintain and update controls throughout their lifecycle — descriptions, mappings, applicability, implementation guidanceSupport certification programs by analyzing requirements, identifying control coverage, and streamlining assessment processes and timelines
  • Partner cross-functionally to support CCF adoption and implementation
  • Research emerging regulations, standards, and certification requirements for potential impact on the CCF
  • Analyze controls and framework requirements for opportunities to standardize, reuse, and increase efficiency
  • Support efforts to reduce compliance burden by improving CCF processes, controls, and implementation strategies
  • Support identification and implementation of compliance automation opportunities
  • Develop and maintain reporting, metrics, and analyses on CCF adoption, control coverage, and certification readiness
  • Identify and track control gaps and inconsistencies, escalating to senior team members as needed
  • Maintain accurate, current CCF documentation and supporting materials
  • Stay informed on regulatory, standards, and compliance trends, and share relevant updates with the team
  • As experience grows, take ownership of defined controls, mappings, or workstreams and drive their maintenance and improvement
  • Use AI and generative-AI tooling responsibly to enhance CCF processes, stakeholder engagement, and data management
What you should have:
  • 3+ years in security governance, GRC, technical writing, program management, or compliance operations at a tech company
  • Direct security-domain experience (application security, cloud security, IAM, vulnerability management, or GRC-adjacent) — deep enough to read controls, understand the risk they manage, and challenge a draft
  • Demonstrated ability to write clear, concise standards, policies, or procedures non-security readers can act on
  • Working knowledge of a major security/privacy framework (SOC 2, ISO 27001, NIST CSF, FedRAMP, PCI, HIPAA, EU AI Act, or equivalent)
  • Comfort running cross-functional review cycles with senior stakeholders (Engineering, Legal, Privacy, Product)
  • Strong attention to detail — versioning, traceability, review dates, approver signatures
  • Experience with a GRC platform (Salesforce eGRC, ServiceNow GRC, Archer, OneTrust, LogicGate, or similar)
  • Excellent written and verbal English communication
  • Ability to work independently across many parallel workstreams
  • Highest level of ethics, independence, and professionalism
Nice to have:
  • Prior experience at a cloud, SaaS, or platform company under multiple concurrent audit regimes
  • Familiarity with the Salesforce platform, trust model, or AppExchange/partner ecosystem
  • Exposure to AI/ML governance (model risk, third‑party LLM/MCP supply chain, Responsible AI, agentic system controls)
  • Hands-on experience with Salesforce reporting, SOQL, or admin-level custom object configuration
  • CISA, CISM, CRISC, ISO 27001 Lead Implementer, or equivalent certification
  • Experience supporting M&A security due diligence or acquisition integration
  • Comfort adopting new AI/GenAI tools responsibly ("builder"/Customer-Zero mindset)
Unleash Your Potential

When you join Salesforce, you’ll be limitless in all areas of your life. Our benefits and resources support you to find balance and be your best, and our AI agents accelerate your impact so you can do your best. Together, we’ll bring the power of Agentforce to organizations of all sizes and deliver amazing experiences that customers love.

Accommodations

If you need a reasonable accommodation during the application or the recruiting process, please submit a request via this Accommodations Request Form.

Posting Statement

Salesforce is an equal opportunity employer and maintains a policy of non-discrimination with all employees and applicants for employment. What does that mean exactly? It means that at Salesforce, we believe in equality for all. And we believe we can lead the path to equality in part by creating a workplace that’s inclusive, and free from discrimination. Any employee or potential employee will be assessed on the basis of merit, competence and qualifications – without regard to race, religion, color, national origin, sex, sexual orientation, gender expression or identity, transgender status, age, disability, veteran or marital status, political viewpoint, or other classifications protected by law. This policy applies to current and prospective employees, no matter where they are in their Salesforce employment journey. It also applies to recruiting, hiring, job assignment, compensation, promotion, benefits, training, assessment of job performance, discipline, termination, and everything in between. Recruiting, hiring, and promotion decisions at Salesforce are fair and based on merit. The same goes for compensation, benefits, promotions, transfers, reduction in workforce, recall, training, and education.

In the United States, compensation offered will be determined by factors such as location, job level, job-related knowledge, skills, and experience. Certain roles may be eligible for incentive compensation, equity, and benefits. Salesforce offers a variety of benefits to help you live well including: time off programs, medical, dental, vision, mental health support, paid parental leave, life and disability insurance, 401(k), and an employee stock purchasing program. More details about company benefits can be found at the following link: https://www.salesforcebenefits.com. Pursuant to the San Francisco Fair Chance Ordinance and the Los Angeles Fair Chance Initiative for Hiring, Salesforce will consider for employment qualified applicants with arrest and conviction records. At Salesforce, we believe in equitable compensation practices that reflect the dynamic nature of labor markets across various regions. The typical base salary range for this position is $117,200 - $176,700 annually. In select cities within the San Francisco and New York City metropolitan area, the base salary range for this role is $141,200 - $194,200 annually. The range represents base salary only, and does

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr. GRC Analyst, Common Control Framework
Sr. GRC Analyst, Common Control Framework

salesforce.com, inc. • San Francisco (CA)

On-site
USD 117,000 - 177,000
Sr. GRC Analyst, Common Control Framework
Sr. GRC Analyst, Common Control Framework

salesforce.com, inc. • Herndon (VA)

On-site
USD 117,000 - 177,000
Sr. GRC Analyst, Common Control Framework
Sr. GRC Analyst, Common Control Framework

salesforce.com, inc. • Bellevue (WA)

On-site
USD 117,000 - 194,000
Sr. GRC Analyst, Policy Operations
Sr. GRC Analyst, Policy Operations

Salesforce • San Francisco (CA)

On-site
USD 117,000 - 177,000
Sr. GRC Analyst, Policy Operations
Sr. GRC Analyst, Policy Operations

salesforce.com, inc. • San Francisco (CA)

On-site
USD 117,000 - 177,000
Sr. GRC Analyst, Policy Operations
Sr. GRC Analyst, Policy Operations

salesforce.com, inc. • Seattle (WA)

On-site
USD 117,000 - 177,000
Medical
Dental
Vision
+5
Sr. GRC Analyst, Policy Operations
Sr. GRC Analyst, Policy Operations

salesforce.com, inc. • Herndon (VA)

On-site
USD 117,000 - 177,000
Time off programs
Medical
Dental
+6
Sr. GRC Analyst, Common Control Framework
Sr. GRC Analyst, Common Control Framework

Salesforce, Inc. • Virginia (MN), Northern (KY)

Hybrid
USD 117,000 - 177,000
Senior Security GRC Analyst
Senior Security GRC Analyst

Salesforce • Bellevue (WA)

On-site
USD 117,000 - 177,000
Sr. GRC Analyst, Policy Operations
Sr. GRC Analyst, Policy Operations

100 Salesforce, Inc. • Washington

On-site
USD 117,000 - 177,000