SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Security GRC Analyst

Salesforce - San Francisco, CA, United States - Hybrid

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salesforce's Global Compliance and Certification (GCC) team is seeking a Senior Security GRC Analyst to drive enterprise-wide compliance and risk management. You'll serve as a cloud compliance subject matter expert, supporting internal and external audits including leading walkthroughs with external assessors. Your responsibilities include ensuring effective control implementation across Salesforce environments aligned with ISO 27001, SOC 1/2, and other regulatory frameworks. You'll partner closely with engineering teams to translate complex compliance frameworks and regulatory mandates into clear, actionable deliverables, ensuring timely remediation and leadership reporting on progress and residual risk. A key part of this role involves identifying opportunities to streamline and automate evidence collection, documenting detailed process playbooks, and driving operational efficiency and continuous improvement. You'll collaborate with cross-functional partners to operationalize audit recommendations and enhance overall compliance posture. The role requires deep expertise in cloud security frameworks, audit execution at scale, and the ability to work independently in a fast-paced regulatory environment. Required qualifications include 4+ years of IT audit or internal controls experience managing global compliance assessments in complex environments with strong focus on cloud and SaaS platforms. You must have prior experience with compliance and regulatory standards across industries and geographies, including ISO 27001, SOC, HIPAA, PCI, HITRUST, SOX, and FedRAMP. Strong analytical and problem-solving skills, program and stakeholder management experience, and excellent organizational and documentation skills are essential. Preferred qualifications include experience with CSP Safety and Korean auditors, compliance tooling and control testing automation, technical knowledge of hyperscaler environments like AWS, and relevant certifications such as CRISC, CISSP, CISM, or CISA.

Similar roles