Sr. GRC Analyst, Policy Operations

Own Company

San Francisco (CA)

On-site

USD 120,000 - 180,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Time off
Medical coverage
Dental
Vision
Mental health support
Parental leave
Life insurance
Disability insurance
401(k)
ESPP

Job summary

Salesforce is seeking an Analyst to run day-to-day operations of the Security Standards and policy program, coordinating intake, drafting support, reviews, publication, and retirement. You will work across Security, Compliance, and Engineering to translate obligations into clear, actionable requirements while maintaining high-quality stakeholder engagement.

In this role you will enable governance across frameworks like SOC 2, ISO 27001, and NIST CSF,Partner with Security Architecture, ProdSec,

Qualifications

  • 3+ years in security governance, GRC, technical writing, program management, or compliance operations at a software/product tech company.
  • U.S. Citizenship or Permanent Residency. We are unable to provide visa sponsorship for this role.
  • Direct security-domain experience (AppSec, cloud security, IAM, vulnerability management, or GRC-adjacent).
  • Proven ability to write clear standards/policies non-security readers can act on.
  • Working knowledge of a major security/privacy framework (SOC 2, ISO 27001, NIST CSF, FedRAMP, PCI, HIPAA, EU AI Act, or equivalent).
  • Comfort running cross-functional review cycles with senior stakeholders.
  • Experience with Git; familiarity with OSCAL and Markdown.
  • Experience with a GRC platform (Salesforce eGRC, ServiceNow GRC, Archer, OneTrust, LogicGate, or similar).
  • Excellent written and verbal English communication.
  • Ability to work independently across many parallel workstreams.
  • Highest level of ethics, independence, and professionalism.

Responsibilities

  • Prioritize intake for new/updated standards, policies, and control documents — assign owners and set realistic timelines.
  • Build standards in plain, unambiguous language with crisp technical requirements in collaboration with SMEs.
  • Facilitate the review/approval cycle end-to-end — schedule CAB reviews, prep read-aheads, capture decisions, track actions.
  • Manage: Publish approved standards to the eGRC platform and retire superseded documents.
  • Operate: Keep standards register traceable to external obligations (SOC 2, ISO 27001, etc.).
  • Maintain: Run content reviews so every standard has an owner, current review date, and ownership map.
  • Monitor: Build dashboards on standards health — coverage, freshness, adoption signals.
  • Improve: Support onboarding of new standards driven by high-priority initiatives.
  • Announce: Coordinate stakeholder communications — changelogs, engineering briefings, Slack updates.
  • Partner: Work with Exception Management to define paired exception paths.
  • Optimize: Improve templates, workflows, and config to reduce cycle time without sacrificing quality.
  • Advance: Use AI/GenAI tooling to accelerate drafting, redlining, and summarization with human review.

Skills

Security governance
GRC
Technical writing
Program management
Compliance operations
Git
OSCAL
Markdown
GRC platform
English communication

Education

Bachelor's degree

Tools

Git
OSCAL
Markdown

Job description

Description
About Salesforce

Salesforce is the #1 AI CRM, where humans with agents drive customer success together. We're looking for Trailblazers passionate about bettering business and the world through AI, driving innovation, and living our core values.

Agentforce is the future of AI, and you are the future of Salesforce.

About the team

The Security Governance team is the operational backbone of Salesforce's security Assurance program. We own the lifecycle of the Salesforce Security Standards (SFSS) — translating regulatory obligations, customer commitments, and threat intelligence into clear, enforceable requirements for engineering, IT, and product teams.

We're hiring an Analyst to run day-to-day operations of the standards and policy program: intake, drafting support, cross-functional review, publication, and retirement. This role sits at the intersection of Security, Compliance, and Engineering — a strong fit for someone skilled at policy development, authorship, and managing complex stakeholders without losing quality or momentum.

What you'll be doing:
  • Prioritize: Triage intake for new/updated standards, policies, and control documents — assign owners and set realistic timelines.
  • Build: Partner with SMEs (Security Architecture, ProdSec, Trust, Privacy, Legal) to draft and finalize standards in plain, unambiguous language with crisp technical requirements.
  • Facilitate: Own the review/approval cycle end-to-end — schedule CAB reviews, prep read‑aheads, capture decisions, track action items.
  • Manage: Publish approved standards to the eGRC platform and retire superseded documents.
  • Operate: Keep the standards register traceable from external obligations (SOC 2, ISO 27001, FedRAMP, EU AI Act, NIST CSF) to internal SFSS controls.
  • Maintain: Run content reviews so every standard has an owner, current review date, and clear ownership map — flag drift, drive re‑attestations.
  • Monitor: Build dashboards on standards health — coverage, freshness, exception load, adoption signals.
  • Improve: Support onboarding of new standards driven by high-priority initiatives.
  • Announce: Coordinate stakeholder comms — changelogs, engineering briefings, Slack updates.
  • Partner: Work with the Exception Management team so every standard has a paired exception path with defined approvers and evidence expectations.
  • Optimize: Improve the operating model — templates, workflows, checklists, eGRC config — to reduce cycle time without sacrificing quality.
  • Advance: Responsibly use AI/GenAI tooling to accelerate drafting, redlining, and summarization, with human‑at‑the‑helm review.
What you should have:
  • 3+ years in security governance, GRC, technical writing, program management, or compliance operations at a software/product tech company.
  • U.S. Citizenship or Permanent Residency. We are unable to provide visa sponsorship for this role.
  • Direct security-domain experience (AppSec, cloud security, IAM, vulnerability management, or GRC-adjacent) — deep enough to read controls, understand risk, and challenge a requester's draft.
  • Proven ability to write clear standards/policies non-security readers can act on.
  • Working knowledge of a major security/privacy framework (SOC 2, ISO 27001, NIST CSF, FedRAMP, PCI, HIPAA, EU AI Act, or equivalent).
  • Comfort running cross-functional review cycles with senior stakeholders.
  • Experience with Git; familiarity with OSCAL and Markdown.
  • Experience with a GRC platform (Salesforce eGRC, ServiceNow GRC, Archer, OneTrust, LogicGate, or similar).
  • Excellent written and verbal English communication.
  • Ability to work independently across many parallel workstreams.
  • Highest level of ethics, independence, and professionalism.
Nice to have:
  • Experience at a cloud/SaaS/platform company under multiple concurrent audit regimes.
  • Familiarity with the Salesforce platform, trust model, or AppExchange/partner ecosystem.
  • Exposure to AI/ML governance (model risk, third‑party LLM/MCP supply chain, Responsible AI, agentic system controls).
  • Hands‑on Salesforce reporting, SOQL, or admin‑level config experience.
  • Certifications: CISA, CISM, CRISC, ISO 27001 Lead Implementer, or equivalent.
  • Experience with M&A security due diligence or acquisition integration.
  • Comfort adopting new AI/GenAI tools responsibly (builder / Customer‑Zero mindset).

Pursuant to the San Francisco Fair Chance Ordinance and the Los Angeles Fair Chance Initiative for Hiring, Salesforce will consider for employment qualified applicants with arrest and conviction records.

In the United States, compensation offered will be determined by factors such as location, job level, job-related knowledge, skills, and experience. Certain roles may be eligible for incentive compensation, equity, and benefits.

Salesforce offers a variety of benefits to help you live well including:

  • time off programs
  • medical
  • dental
  • vision
  • mental health support
  • paid parental leave
  • life and disability insurance
  • 401(k)
  • an employee stock purchasing program

More details about company benefits can be found at the following link: https://www.salesforcebenefits.com.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr. GRC Analyst, Policy Operations
Sr. GRC Analyst, Policy Operations

salesforce.com, inc. • San Francisco (CA)

On-site
USD 117,000 - 177,000
Sr. GRC Analyst, Policy Operations
Sr. GRC Analyst, Policy Operations

salesforce.com, inc. • Seattle (WA)

On-site
USD 117,000 - 177,000
Medical
Dental
Vision
+5
Sr. GRC Analyst, Policy Operations
Sr. GRC Analyst, Policy Operations

salesforce.com, inc. • Herndon (VA)

On-site
USD 117,000 - 177,000
Time off programs
Medical
Dental
+6
Sr. GRC Analyst, Policy Operations
Sr. GRC Analyst, Policy Operations

Salesforce • San Francisco (CA)

On-site
USD 117,000 - 177,000
Sr. GRC Analyst, Common Control Framework
Sr. GRC Analyst, Common Control Framework

Own Company • San Francisco (CA)

On-site
USD 120,000 - 170,000
Health insurance
401(k) matching
Employee stock purchase program
+5
Sr. GRC Analyst, Policy Operations
Sr. GRC Analyst, Policy Operations

Salesforce, Inc. • Virginia (MN), Northern (KY)

Hybrid
USD 117,000 - 177,000
Accommodations available
Sr. GRC Analyst, Policy Operations
Sr. GRC Analyst, Policy Operations

100 Salesforce, Inc. • Washington

On-site
USD 117,000 - 177,000
Sr. GRC Analyst, Common Control Framework
Sr. GRC Analyst, Common Control Framework

salesforce.com, inc. • San Francisco (CA)

On-site
USD 117,000 - 177,000
Sr. GRC Analyst, Common Control Framework
Sr. GRC Analyst, Common Control Framework

salesforce.com, inc. • Herndon (VA)

On-site
USD 117,000 - 177,000
Sr. GRC Analyst, Common Control Framework
Sr. GRC Analyst, Common Control Framework

salesforce.com, inc. • Bellevue (WA)

On-site
USD 117,000 - 194,000