Security GRC Lead

SalesforceSan Francisco, CA

About The Position

Salesforce is looking for a Public Sector GRC Lead to join their team with experience in FedRAMP, NIST 800-53 and other public sector security and compliance frameworks. The Principal Public Sector Lead will play an important role in supporting Informatica's global public sector compliance program, including FedRAMP / Tx-RAMP, and CMMC to support Informatica's rapidly growing cloud services in public sector. As the Public Sector GRC Lead, you will maintain the current level of authorization for cloud products by working with government sponsors and third-party auditors, collaborating closely with Engineering & Product teams to safely onboard new cloud products, and assisting Sales and Marketing teams to identify future public sector compliances. In this role, you will represent Informatica as the Information System Security Officer ("ISSO") and coordinate with System Owners and third-party auditors.

Requirements

  • 3-5+ years, FedRAMP industry experience.
  • Project/Program management experience for 3+ years at a software company.
  • Experience working with Government Cloud environments such as AWS, Azure, GCP (SaaS, IaaS, PaaS etc)
  • Relevant experience in corporate security management and security governance framework control assessment
  • Broad experience with SOX, SOC2, ISO 27001, PCI DSS, HIPAA, and public sector certifications such as FedRAMP, UK Cyber Essentials, IRAP.
  • Identify opportunities to reduce risk of the Informatica's security posture and escalate issues to management and where required.
  • Experience with internal security and business groups to ensure compliance with Informatica's policies, internal and external regulatory requirements, government regulations and security best practices.
  • Experience creating and generating status and metrics report that can provide meaningful context to guide informed decisions
  • Experience working closely with R&D, Product, DevSecOps, and other technical teams.

Nice To Haves

  • Desired certifications & Trainings: CISSP, CRISC, CISA, CISM, or related GIAC

Responsibilities

  • Manage the relationships with external auditors (including our 3PAO), sponsoring agencies, and FedRAMP PMO.
  • Maintain the System Security Plan (SSP), Plan of Action & Milestones (POA&M), and the overall authorization package.
  • Collaborate with a cross-functional team operating the FedRAMP controls, working to build strong relationships and internal processes that lead to shared positive outcomes
  • Drive Continuous Monitoring efforts as part of FedRAMP and other standards.
  • Provide subject-matter expertise on all public sector requirements (including FedRAMP) with R&D, sales & marketing, and customers.
  • Conduct internal assessments to prepare partners for external audits, including creating and providing audit training and support.
  • Ensure any risk/gap findings are documented and addressed with appropriate action following FedRAMP regulatory standards
  • Lead the planning, scheduling and preliminary analysis for all annual 3PAO external audits.
  • Work with product managers to migrate their cloud products onto the FedRAMP environment.
  • Direct project and program management efforts working with cross functional teams, to drive to outcomes and iterative improvements.
  • Work closely with other team leads and task owners including R&D, commercial legal, sales, product/enterprise teams, and privacy legal.
  • Other responsibilities, as assigned.

Benefits

  • time off programs
  • medical
  • dental
  • vision
  • mental health support
  • paid parental leave
  • life and disability insurance
  • 401(k)
  • employee stock purchasing program

Stand Out From the Crowd

Upload your resume and get instant feedback on how well it matches this job.

Upload and Match Resume

What This Job Offers

Job Type

Full-time

Career Level

Senior

Education Level

No Education Listed

Number of Employees

5,001-10,000 employees

© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service