Sr. GRC Analyst, Policy Operations

Salesforce•Herndon, VA
•$117,200 - $194,200•Remote

About The Position

The Security Governance team is the operational backbone of Salesforce's security Assurance program. We own the lifecycle of the Salesforce Security Standards (SFSS) — translating regulatory obligations, customer commitments, and threat intelligence into clear, enforceable requirements for engineering, IT, and product teams. We're hiring an Analyst to run day-to-day operations of the standards and policy program: intake, drafting support, cross-functional review, publication, and retirement. This role sits at the intersection of Security, Compliance, and Engineering — a strong fit for someone skilled at policy development, authorship, and managing complex stakeholders without losing quality or momentum.

Requirements

  • 3+ years in security governance, GRC, technical writing, program management, or compliance operations at a software/product tech company.
  • U.S. Citizenship or Permanent Residency. We are unable to provide visa sponsorship for this role.
  • Direct security-domain experience (AppSec, cloud security, IAM, vulnerability management, or GRC-adjacent) — deep enough to read controls, understand risk, and challenge a requester's draft.
  • Proven ability to write clear standards/policies non-security readers can act on.
  • Working knowledge of a major security/privacy framework (SOC 2, ISO 27001, NIST CSF, FedRAMP, PCI, HIPAA, EU AI Act, or equivalent).
  • Comfort running cross-functional review cycles with senior stakeholders.
  • Experience with Git; familiarity with OSCAL and Markdown.
  • Experience with a GRC platform (Salesforce eGRC, ServiceNow GRC, Archer, OneTrust, LogicGate, or similar).
  • Excellent written and verbal English communication.
  • Ability to work independently across many parallel workstreams.
  • Highest level of ethics, independence, and professionalism.

Nice To Haves

  • Experience at a cloud/SaaS/platform company under multiple concurrent audit regimes.
  • Familiarity with the Salesforce platform, trust model, or AppExchange/partner ecosystem.
  • Exposure to AI/ML governance (model risk, third-party LLM/MCP supply chain, Responsible AI, agentic system controls).
  • Hands-on Salesforce reporting, SOQL, or admin-level config experience.
  • Certifications: CISA, CISM, CRISC, ISO 27001 Lead Implementer, or equivalent.
  • Experience with M&A security due diligence or acquisition integration.
  • Comfort adopting new AI/GenAI tools responsibly (builder / Customer-Zero mindset).

Responsibilities

  • Prioritize: Triage intake for new/updated standards, policies, and control documents — assign owners and set realistic timelines.
  • Build: Partner with SMEs (Security Architecture, ProdSec, Trust, Privacy, Legal) to draft and finalize standards in plain, unambiguous language with crisp technical requirements.
  • Facilitate: Own the review/approval cycle end-to-end — schedule CAB reviews, prep read-aheads, capture decisions, track action items.
  • Manage: Publish approved standards to the eGRC platform and retire superseded documents.
  • Operate: Keep the standards register traceable from external obligations (SOC 2, ISO 27001, FedRAMP, EU AI Act, NIST CSF) to internal SFSS controls.
  • Maintain: Run content reviews so every standard has an owner, current review date, and clear ownership map — flag drift, drive re-attestations.
  • Monitor: Build dashboards on standards health — coverage, freshness, exception load, adoption signals.
  • Improve: Support onboarding of new standards driven by high-priority initiatives.
  • Announce: Coordinate stakeholder comms — changelogs, engineering briefings, Slack updates.
  • Partner: Work with the Exception Management team so every standard has a paired exception path with defined approvers and evidence expectations.
  • Optimize: Improve the operating model — templates, workflows, checklists, eGRC config — to reduce cycle time without sacrificing quality.
  • Advance: Responsibly use AI/GenAI tooling to accelerate drafting, redlining, and summarization, with human-at-the-helm review.

Benefits

  • time off programs
  • medical
  • dental
  • vision
  • mental health support
  • paid parental leave
  • life and disability insurance
  • 401(k)
  • employee stock purchasing program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service