Sr. GRC Analyst, Policy Operations

Salesforce•Seattle, WA

About The Position

Salesforce is seeking a Sr. GRC Analyst for its Policy Operations team. This role is crucial for the operational backbone of Salesforce's security assurance program. The analyst will manage the lifecycle of Salesforce Security Standards (SFSS), translating regulatory obligations, customer commitments, and threat intelligence into actionable requirements for engineering, IT, and product teams. The position involves running day-to-day operations of the standards and policy program, including intake, drafting support, cross-functional review, publication, and retirement. This role requires a blend of security, compliance, and engineering expertise, with a focus on policy development, authorship, and stakeholder management.

Requirements

  • 3+ years in security governance, GRC, technical writing, program management, or compliance operations at a software/product tech company.
  • U.S. Citizenship or Permanent Residency (visa sponsorship is not provided).
  • Direct security-domain experience (AppSec, cloud security, IAM, vulnerability management, or GRC-adjacent) sufficient to read controls, understand risk, and challenge drafts.
  • Proven ability to write clear standards/policies that non-security readers can act on.
  • Working knowledge of a major security/privacy framework (SOC 2, ISO 27001, NIST CSF, FedRAMP, PCI, HIPAA, EU AI Act, or equivalent).
  • Comfort running cross-functional review cycles with senior stakeholders.
  • Experience with Git; familiarity with OSCAL and Markdown.
  • Experience with a GRC platform (Salesforce eGRC, ServiceNow GRC, Archer, OneTrust, LogicGate, or similar).
  • Excellent written and verbal English communication.
  • Ability to work independently across many parallel workstreams.
  • Highest level of ethics, independence, and professionalism.

Nice To Haves

  • Experience at a cloud/SaaS/platform company under multiple concurrent audit regimes.
  • Familiarity with the Salesforce platform, trust model, or AppExchange/partner ecosystem.
  • Exposure to AI/ML governance (model risk, third-party LLM/MCP supply chain, Responsible AI, agentic system controls).
  • Hands-on Salesforce reporting, SOQL, or admin-level config experience.
  • Certifications: CISA, CISM, CRISC, ISO 27001 Lead Implementer, or equivalent.
  • Experience with M&A security due diligence or acquisition integration.
  • Comfort adopting new AI/GenAI tools responsibly (builder / Customer-Zero mindset).

Responsibilities

  • Triage intake for new/updated standards, policies, and control documents, assigning owners and setting timelines.
  • Partner with SMEs (Security Architecture, ProdSec, Trust, Privacy, Legal) to draft and finalize standards in clear, unambiguous language with crisp technical requirements.
  • Own the review/approval cycle end-to-end, including scheduling CAB reviews, preparing read-aheads, capturing decisions, and tracking action items.
  • Publish approved standards to the eGRC platform and retire superseded documents.
  • Maintain the standards register, ensuring traceability from external obligations (SOC 2, ISO 27001, FedRAMP, EU AI Act, NIST CSF) to internal SFSS controls.
  • Run content reviews to ensure every standard has an owner, current review date, and clear ownership map, flagging drift and driving re-attestations.
  • Build dashboards on standards health, including coverage, freshness, exception load, and adoption signals.
  • Support the onboarding of new standards driven by high-priority initiatives.
  • Coordinate stakeholder communications, including changelogs, engineering briefings, and Slack updates.
  • Partner with the Exception Management team to ensure every standard has a paired exception path with defined approvers and evidence expectations.
  • Optimize the operating model, including templates, workflows, checklists, and eGRC configuration, to reduce cycle time without sacrificing quality.
  • Responsibly use AI/GenAI tooling to accelerate drafting, redlining, and summarization, with human-at-the-helm review.

Benefits

  • Time off programs
  • Medical, dental, vision
  • Mental health support
  • Paid parental leave
  • Life and disability insurance
  • 401(k)
  • Employee stock purchasing program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service