Security GRC Senior Analyst
SalesforceAbout the role
To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.
Job Category
Enterprise Technology & InfrastructureJob Details
About Salesforce
We’re Salesforce, the Customer Company, inspiring the future of business with AI+ Data +CRM. Leading with our core values, we help companies across every industry blaze new trails and connect with customers in a whole new way. And, we empower you to be a Trailblazer, too — driving your performance and career growth, charting new paths, and improving the state of the world. If you believe in business as the greatest platform for change and in companies doing well and doing good – you’ve come to the right place.
About Salesforce
We’re Salesforce, the Customer Company, inspiring the future of business with AI+ Data +CRM+Trust. Leading with our core values, we help companies across every industry blaze new trails and connect with customers in a whole new way. And, we empower you to be a Trailblazer, too — driving your performance and career growth, charting new paths, and improving the state of the world. If you believe in business as the greatest platform for change and in companies doing well and doing good – you’ve come to the right place!
About Our Team
The Salesforce Security Controls Management program is anchored in the principles of Transparency, Inclusiveness, Accountability and Equality. We build, operate, and continuously improve a best in class, organizationally integrated and business value driven, security controls management program commensurate with the most secure enterprise cloud!
In this individual contributor role, you bring security domain subject matter expertise, GRC background, operational background, influencing capabilities, and Product Manager know-how. You must have the ability to ramp up quickly to support the Security Controls Management program, and become a trusted advisor to Security and GRC leadership. You create and maintain relationships with business and technical experts throughout the company who provide expertise in security requirements and solutions design.
This role has high visibility throughout the entire organization, with growth potential and career path opportunities across technical and leadership roles.
Impact - Responsibilities:
Assist in the building and maintenance of the security Common Controls Framework (CCF) and other activities in the security controls life-cycle management process covering all Salesforce business units, products, and services
Drive adoption and awareness of the CCF and eGRC platform with stakeholders across the organization, to include security teams, GRC, engineering teams, legal, etc.
Lead controls data within the eGRC platform based upon feedback from partners, framework updates, new framework adoption, or changes in the state of controls
Assist the product owner in defining clear lines of responsibility between various Salesforce organizations including the first, second and third lines of defense
Plan, implement, and operate controls management program capabilities including the security Common Controls Framework (CCF) which maps all of Salesforce’s external obligations to internal standards and control activities
Build and ensure ongoing program oversight
Responsible for assuring process effectiveness, measurement and optimization
Create and maintain security controls management standards, frameworks, processes, procedures, and other program documentation
Prepare reports and presentations for multiple audiences with varying business objectives including senior executives and the Board of Directors
Support Governance, Risk & Compliance (GRC) tools implementation and utilization
Coordinate with other teams and departments inside Security and across the greater organization
Provide controls management subject matter expertise for members of the Security organization
Continuously identify improvement opportunities and provide feedback to senior team members and management
Minimum Qualifications:
BA or BS in Computer Science or any related subject area, or 6+ years of experience
6+ years of related security governance, risk and compliance experience or equivalent security experience
Experience working in or exposure to large-scale/global organizations
In depth understanding of security GRC the component programs
Knowledge of multiple regulatory compliance frameworks (NIST CSF & 800-53, ISO27001, SOC, HITRUST, HIPAA, FedRamp, PCI, GDPR, etc.)
Required Qualifications:
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s