Security GRC Analyst
SalesforceRole Overview
Salesforce is hiring a mid-level Security GRC Analyst. This is a full-time role in California - San Francisco. posted today. applications are still in the early window, before most candidates have applied. Full responsibilities, required qualifications, and the apply link are listed in the description below.
Resume Keywords to Include
Make sure these keywords appear in your resume to improve ATS scoring
Job description
To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.
Job Category
Enterprise Technology & InfrastructureJob Details
About Salesforce
Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn’t a buzzword — it’s a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all.
Ready to level-up your career at the company leading workforce transformation in the agentic era? You’re in the right place! Agentforce is the future of AI, and you are the future of Salesforce.
The Security GRC (Governance, Risk, and Compliance) Analyst role is part of our Security and Compliance team, sitting at the intersection of internal operations and external audit relationships. We are looking for a detail-oriented GRC Analyst to lead our Unified Audit program — keeping us compliant, audit-ready, and continuously improving across multiple frameworks.
As a key partner to control owners and external auditors alike, you will help ensure our compliance programs run smoothly and that our certifications stay strong.
- Lead the end-to-end Unified Audit program across SOC 2 (Service Organization Control 2), HIPAA (Health Insurance Portability and Accountability Act), ISO (International Organization for Standardization) 27001, and GxP (Good Practice) frameworks, coordinating schedules and minimizing duplication across certifications.
- Manage internal evidence collection by assigning tasks to control owners, tracking deadlines, validating submissions, and conducting pre-audit gap reviews.
- Serve as the primary liaison with external auditors — scheduling walkthroughs, responding to information requests, and coordinating responses to findings.
- Maintain compliance dashboards, standard operating procedures, and documentation repositories to support continuous monitoring and audit readiness.
- You have 2–4 years of experience in GRC, compliance, audit, or information security, with hands-on experience supporting or managing compliance audits.
- You have working knowledge of at least two of the following: SOC 2, HIPAA, ISO 27001, or GxP frameworks.
- You are proficient with GRC tools, audit management platforms, and documentation systems (Microsoft Office Suite or Google Workspace).
- You communicate clearly with both technical and non-technical stakeholders and thrive managing multiple concurrent deadlines.
- You hold one or more relevant certifications such as CISA (Certified Information Systems Auditor), CRISC (Certified in Risk and Information Systems Control), CISSP (Certified Information Systems Security Professional), or ISO 27001 Lead Auditor/Implementer.
- You have experience with unified or integrated audit programs, or a background in healthcare or life sciences.
- You have hands-on experience with GRC platforms such as Drata, Vanta, OneTrust, or ServiceNow GRC.
- You have worked directly with external audit firms in a compliance or security capacity.
Unleash Your Potential
When you join Salesforce, you’ll be limitless in all areas of your life. Our benefits and resources support you to find balance and be your best, and our AI agents accelerate your impact so you can do your best. Together, we’ll bring the power of Agentforce to organizations of all sizes and deliver amazing experiences that customers love. Apply today to not only shape the future — but to redefine what’s possible — for yourself, for AI, and the world.
Accommodations
If you need a reasonable accommodation during the application or the recruiting process, please submit a request via this Accommodations Request Form.
Please note that Salesforce uses artificial intelligence (AI) tools to help our recruiters assess and evaluate candidates’ resumes and qualifications throughout the recruiting process. Humans will always make any candidate selection and hiring decisions. Please see our Candidate Privacy Statement for more information about how we use your personal data and your rights, including with regard to use of AI tools and opt out options.
Posting Statement
Salesforce is an equal opportunity employer and maintains a policy of non-discrimination with all employees and applicants for employment. What does that mean exactly? It means that at Salesforce, we believe in equality for all. And we believe we can lead the path to equality in part by creating a workplace that’s inclusive, and free from discrimination. Know your rights: workplace discrimination is illegal. Any employee or potential employee will be assessed on the basis of merit, competence and qualifications – without regard to race, religion, color, national origin, sex, sexual orientation, gender expression or identity, transgender status, age, disability, veteran or marital status, political viewpoint, or other classifications protected by law. This policy applies to current and prospective employees, no matter where they are in their Salesforce employment journey. It also applies to recruiting, hiring, job assignment, compensation, promotion, benefits, training, assessment of job performance, discipline, termination, and everything in between. Recruiting, hiring, and promotion decisions at Salesforce are fair and based on merit. The same goes for compensation, benefits, promotions, transfers, reduction in workforce, recall, training, and education.
In the United States, compensation offered will be determined by factors such as location, job level, job-related knowledge, skills, and experience. Certain roles may be eligible for incentive compensation, equity, and benefits. Salesforce offers a variety of benefits to help you live well including: time off programs, medical, dental, vision, mental health support, paid parental leave, life and disability insurance, 401(k), and an employee stock purchasing program. More details about company benefits can be found at the following link: https://www.salesforcebenefits.com.Pursuant to the San Francisco Fair Chance Ordinance and the Los Angeles Fair Chance Initiative for Hiring, Salesforce will consider for employment qualified applicants with arrest and conviction records.At Salesforce, we believe in equitable compensation practices that reflect the dynamic nature of labor markets across various regions. The typical base salary range for this position is $96,300 - $145,200 annually. In select cities within the San Francisco and New York City metropolitan area, the base salary range for this role is $116,000 - $159,500 annually. The range represents base salary only, and does not include company bonus, incentive for sales roles, equity or benefits, as applicable.About Salesforce
Salesforce
salesforce.com
34 other open roles at Salesforce on TryApplyNow.
Frequently Asked Questions
How do I apply for the Security GRC Analyst position at Salesforce?
Use the Apply button above to submit your application directly to Salesforce. Most applications take less than 5 minutes if your resume and contact details are ready, and you'll be routed to the employer's official application system to finish.
Where is the Security GRC Analyst position at Salesforce located?
This position is based in California - San Francisco. Salesforce has not indicated remote or hybrid options for this role, so candidates should plan for on-site work.
What does a Security GRC Analyst at Salesforce earn?
Salesforce has not disclosed a salary range in this posting. Many employers share specifics later in the interview process; you can also ask during a recruiter screen if compensation transparency is important to you.
When was the Security GRC Analyst role at Salesforce posted?
This role was posted on July 22, 2026 (today). It's still listed as actively hiring; we re-confirm openings against the source system multiple times per day and remove closed roles.
More Jobs at Salesforce
View all →Senior Research Lead (Thought Leadership), Customer Insights
Salesforce
Systems Engineering Associate - GovCloud [ National Security]
Salesforce
Business Development Associate
Salesforce
Employee Success Shared Services Specialist
Salesforce
Human Centered Change Senior Manager- Public Sector
Salesforce
AI-powered job search
Get every job scored to your resume
Upload your resume and get jobs ranked, your resume tailored, and employee contacts found automatically.
Get started freeNo credit card to start