Senior Security GRC Analyst
Listed on 2026-08-12
-
Security
Information Security & Data Protection, Cybersecurity
About Salesforce
Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn’t a buzzword - it’s a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all.
Ready to level-up your career at the company leading workforce transformation in the agentic era? You’re in the right place! Agentforce is the future of AI, and you are the future of Salesforce.
Location:
San Francisco, CA
The Senior Security GRC Analyst role is part of our Assurance team, sitting at the intersection of internal operations and external audit relationships. This role leads our IDMC Unified Audit program, keeping the company compliant, audit-ready, and continuously improving across multiple frameworks. As a key partner to control owners and external auditors alike, you will help ensure compliance programs run smoothly and certifications stay strong.
WhatYou'll Actually Be Doing
- Lead the end-to-end IDMC Unified Audit program across SOC (Service Organization Control) 1/2/3, HIPAA (Health Insurance Portability and Accountability Act), ISO (International Organization for Standardization) 27001, and GxP (Good Practice) frameworks, coordinating schedules and minimizing duplication across certifications.
- Own the audit strategy and roadmap, setting priorities and timelines across frameworks and presenting program status and risk areas to leadership.
- Manage internal evidence collection by assigning tasks to control owners, tracking deadlines, validating submissions, and conducting pre-audit gap reviews.
- Serve as the primary liaison with external auditors, scheduling walkthroughs, responding to information requests, and coordinating responses to findings.
- You have 3+ years of experience in GRC (Governance, Risk, and Compliance), compliance, audit, or information security, with hands‑on experience supporting or managing compliance audits.
- You have working knowledge of at least two of the following: SOC, HIPAA, ISO 27001, or GxP frameworks.
- You are proficient with GRC tools, audit management platforms, and documentation systems, such as Microsoft Office Suite or Google Workspace.
- You communicate clearly with both technical and non-technical stakeholders, thrive managing multiple concurrent deadlines, and are comfortable guiding less experienced team members.
- You hold one or more relevant certifications, such as CISA (Certified Information Systems Auditor), CRISC (Certified in Risk and Information Systems Control), CISSP (Certified Information Systems Security Professional), or ISO 27001 Lead Auditor/Implementer.
- You have experience with unified or integrated audit programs, or audit programs spanning multiple frameworks.
- You have hands‑on experience with JIRA.
- You have worked directly with external audit firms in a compliance or security capacity.
- You mentor and educate teams on audit methodology, evidence review, and stakeholder communication, and help build repeatable processes as the audit program scales.
When you join Salesforce, you’ll be limitless in all areas of your life. Our benefits and resources support you to find balance and be your best, and our AI agents accelerate your impact so you can do your best. Together, we’ll bring the power of Agentforce to organizations of all sizes and deliver amazing experiences that customers love.
AccommodationsIf you need a reasonable accommodation during the application or the recruiting process, please submit a request via this Accommodations Request Form. Please note that Salesforce uses artificial intelligence (AI) tools to help our recruiters assess and evaluate candidates’ resumes and qualifications throughout the recruiting process. Humans will always make any candidate selection and hiring decisions. Please see our Candidate Privacy Statement for more information about how we use your personal data and your rights, including with regard to use of AI…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).