Salesforce logo

Sr. GRC Analyst, Common Control Framework

Salesforce

San Francisco, CA, USAJobPosted 3 days agoStill listed 2 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
No compensation found
Location
San Francisco, CA, USA
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Job overview

Salesforce seeks a Sr. GRC Analyst to support day-to-day operations of the Common Controls Framework, designing, maintaining, and evolving controls across compliance programs while partnering with cross‑functional stakeholders and leveraging AI tools to improve processes and reporting.

Skills & qualifications

RequiredNice to have

Skills

Technical WritingProgram ManagementApplication SecurityVulnerability ManagementISO/IEC 27001FedRAMPCloud SecurityIAMGRC PlatformSalesforce eGRCServiceNow GRCArcherOneTrustLogicGateAI/GenAI ToolsSOQLReportingSOC 2ISO 27001NIST CSFPCIHIPAAEU AI ActCISACISMCRISCISO 27001 Lead ImplementerWritten CommunicationVerbal CommunicationAttention to DetailIndependenceProfessional Ethics

Qualifications

3+ Years Security Governance Experience

Benefits

Medical Insurance
Dental Insurance
Vision Insurance
Parental Leave
401(k) Match
Paid Time Off

Full job description

Description About Salesforce Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action, tech meets trust, and innovation is a way of life. We're looking for Trailblazers passionate about bettering business and the world through AI. Agentforce is the future of AI, and you are the future of Salesforce.

About the team Salesforce's Common Controls Framework (CCF) program is the foundation of our security governance and compliance program, anchored in Trust, Transparency, and Accountability. We build, operate, and continuously improve a best-in-class, organizationally integrated, business-value-driven security controls management program.

We're hiring an Analyst to support day-to-day CCF operations. In this individual contributor role, you'll bring security, GRC, and operational/product-management expertise, quickly adapting to the program and becoming a trusted advisor to security and compliance stakeholders across the business.

What you'll be doing:

  • Support the design, maintenance, and evolution of the CCF and its implementation across all Salesforce compliance certification programs
  • Map common controls to applicable frameworks, standards, and certification requirements, identifying reuse opportunities across programs
  • Maintain and update controls throughout their lifecycle — descriptions, mappings, applicability, implementation guidance
  • Support certification programs by analyzing requirements, identifying control coverage, and streamlining assessment processes and timelines
  • Partner cross-functionally to support CCF adoption and implementation
  • Research emerging regulations, standards, and certification requirements for potential impact on the CCF
  • Analyze controls and framework requirements for opportunities to standardize, reuse, and increase efficiency
  • Support efforts to reduce compliance burden by improving CCF processes, controls, and implementation strategies
  • Support identification and implementation of compliance automation opportunities
  • Develop and maintain reporting, metrics, and analyses on CCF adoption, control coverage, and certification readiness
  • Identify and track control gaps and inconsistencies, escalating to senior team members as needed
  • Maintain accurate, current CCF documentation and supporting materials
  • Stay informed on regulatory, standards, and compliance trends, and share relevant updates with the team
  • As experience grows, take ownership of defined controls, mappings, or workstreams and drive their maintenance and improvement
  • Use AI and generative-AI tooling responsibly to enhance CCF processes, stakeholder engagement, and data management

What you should have:

  • 3+ years in security governance, GRC, technical writing, program management, or compliance operations at a tech company
  • Direct security-domain experience (application security, cloud security, IAM, vulnerability management, or GRC-adjacent) — deep enough to read controls, understand the risk they manage, and challenge a draft
  • Demonstrated ability to write clear, concise standards, policies, or procedures non-security readers can act on
  • Working knowledge of a major security/privacy framework (SOC 2, ISO 27001, NIST CSF, FedRAMP, PCI, HIPAA, EU AI Act, or equivalent)
  • Comfort running cross-functional review cycles with senior stakeholders (Engineering, Legal, Privacy, Product)
  • Strong attention to detail — versioning, traceability, review dates, approver signatures
  • Experience with a GRC platform (Salesforce eGRC, ServiceNow GRC, Archer, OneTrust, LogicGate, or similar)
  • Excellent written and verbal English communication
  • Ability to work independently across many parallel workstreams
  • Highest level of ethics, independence, and professionalism

Nice to have:

  • Prior experience at a cloud, SaaS, or platform company under multiple concurrent audit regimes
  • Familiarity with the Salesforce platform, trust model, or AppExchange/partner ecosystem
  • Exposure to AI/ML governance (model risk, third-party LLM/MCP supply chain, Responsible AI, agentic system controls)
  • Hands-on experience with Salesforce reporting, SOQL, or admin-level custom object configuration
  • CISA, CISM, CRISC, ISO 27001 Lead Implementer, or equivalent certification
  • Experience supporting M&A security due diligence or acquisition integration
  • Comfort adopting new AI/GenAI tools responsibly ("builder"/Customer-Zero mindset)

Pursuant to the San Francisco Fair Chance Ordinance and the Los Angeles Fair Chance Initiative for Hiring, Salesforce will consider for employment qualified applicants with arrest and conviction records. In the United States, compensation offered will be determined by factors such as location, job level, job-related knowledge, skills, and experience. Certain roles may be eligible for incentive compensation, equity, and benefits. Salesforce offers a variety of benefits to help you live well including: time off programs, medical, dental, vision, mental health support, paid parental leave, life and disability insurance, 401(k), and an employee stock purchasing program. More details about company benefits can be found at the following link: https://www.salesforcebenefits.com.

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.