×
Register Here to Apply for Jobs or Post Jobs. X

Sr. GRC Analyst, Policy Operations

Job in Yakima, Yakima County, Washington, 98903, USA
Listing for: 100 Salesforce, Inc.
Full Time position
Listed on 2026-10-03
Job specializations:
  • IT/Tech
    Information Security & Data Protection, Cybersecurity
Salary/Wage Range or Industry Benchmark: 117000 - 177000 USD Yearly USD 117000.00 177000.00 YEAR
Job Description & How to Apply Below
About Salesforce

Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn't a buzzword - it's a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all.

Ready to level-up your career at the company leading workforce transformation in the agentic era? You're in the right place! Agentforce is the future of AI, and you are the future of Salesforce.

About Salesforce

Salesforce is the #1 AI CRM, where humans with agents drive customer success together. We're looking for Trailblazers passionate about bettering business and the world through AI, driving innovation, and living our core values. Agentforce is the future of AI, and you are the future of Salesforce.

About the team

The Security Governance team is the operational backbone of Salesforce's security Assurance program. We own the lifecycle of the Salesforce Security Standards (SFSS) - translating regulatory obligations, customer commitments, and threat intelligence into clear, enforceable requirements for engineering, IT, and product teams. We're hiring an Analyst to run day-to-day operations of the standards and policy program: intake, drafting support, cross-functional review, publication, and retirement.

This role sits at the intersection of Security, Compliance, and Engineering - a strong fit for someone skilled at policy development, authorship, and managing complex stakeholders without losing quality or momentum.

What you'll be doing:
  • Prioritize:
    Triage intake for new/updated standards, policies, and control documents - assign owners and set realistic timelines.
  • Build:
    Partner with SMEs (Security Architecture, Prod Sec, Trust, Privacy, Legal) to draft and finalize standards in plain, unambiguous language with crisp technical requirements.
  • Facilitate:
    Own the review/approval cycle end-to-end - schedule CAB reviews, prep read-aheads, capture decisions, track action items.
  • Manage:
    Publish approved standards to the eGRC platform and retire superseded documents.
  • Operate:
    Keep the standards register traceable from external obligations (SOC 2, ISO 27001, FedRAMP, EU AI Act, NIST CSF) to internal SFSS controls.
  • Maintain:
    Run content reviews so every standard has an owner, current review date, and clear ownership map - flag drift, drive re-attestations.
  • Monitor:
    Build dashboards on standards health - coverage, freshness, exception load, adoption signals.
  • Improve:
    Support onboarding of new standards driven by high-priority initiatives.
  • Announce:
    Coordinate stakeholder comms - change logs, engineering briefings, Slack updates.
  • Partner:
    Work with the Exception Management team so every standard has a paired exception path with defined approvers and evidence expectations.
  • Optimize:
    Improve the operating model - templates, workflows, checklists, eGRC config - to reduce cycle time without sacrificing quality.
  • Advance:
    Responsibly use AI/GenAI tooling to accelerate drafting, redlining, and summarization, with human-at-the-helm review.
What you should have:
  • 3+ years in security governance, GRC, technical writing, program management, or compliance operations at a software/product tech company.
  • U.S. Citizenship or Permanent Residency.
  • We are unable to provide visa sponsorship for this role.
  • Direct security-domain experience (App Sec, cloud security, IAM, vulnerability management, or GRC-adjacent) - deep enough to read controls, understand risk, and challenge a requester's draft.
  • Proven ability to write clear standards/policies non-security readers can act on.
  • Working knowledge of a major security/privacy framework (SOC 2, ISO 27001, NIST CSF, FedRAMP, PCI, HIPAA, EU AI Act, or equivalent).
  • Comfort running cross-functional review cycles with senior stakeholders.
  • Experience with Git; familiarity with OSCAL and Markdown.
  • Experience with a GRC platform (Salesforce eGRC, Service Now GRC, Archer, One Trust, Logic Gate, or similar).
  • Excellent written and verbal English communication.
  • Ability to work independently across many parallel work streams.
  • Highest level of ethics, independence, and professionalism.
Nice to have:
  • Experience at a cloud/SaaS/platform company under multiple concurrent audit regimes.
  • Familiarity with the Salesforce platform, trust model, or App Exchange/partner ecosystem.
  • Exposure to AI/ML governance (model risk, third-party…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary