Senior Security GRC Analyst
Core
Cloud compliance subject matter expert supporting internal and external audits, partnering with engineering to translate regulatory mandates into actionable controls, and automating evidence collection.
Role type
Senior Security GRC Analyst (Cloud Compliance)
Builds
Actionable compliance controls, audit evidence, and process playbooks for Salesforce's global compliance posture.
Domain
Enterprise Technology & Infrastructure / Cloud Security / Regulatory Compliance
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
IT audit, internal controls, cloud security frameworks, regulatory standards interpretation, risk assessment, stakeholder management, documentation, process automation
Preferred skills
CSP Safety experience, compliance tooling, control testing automation, hyperscaler environment knowledge (AWS), Korean language proficiency
Technologies
ISO 27001, SOC 1/2, HIPAA, PCI, HITRUST, SOX, FedRAMP, AWS
Responsibilities
Lead walkthroughs with external assessors for ISO 27001 and SOC audits; Partner with engineering to translate compliance frameworks into actionable controls; Identify opportunities to automate evidence collection and streamline compliance operations; Collaborate with cross-functional partners to operationalize audit recommendations; Document detailed process playbooks for continuous improvement; Provide leadership reporting on progress and residual risk.
Seniority
Senior, hands-on IC
