Director, Technology Risk & Controls (compliance Engineering)

Salesforce Salesforce · Enterprise · New York, NY +5

Salesforce is looking for a Director, Technology Risk and Controls to lead their compliance automation team. This role involves architecting and implementing an end-to-end agentic ecosystem for compliance lifecycle management, transitioning from manual processes to automated solutions. The goal is to institutionalize engineering-driven compliance, focusing on automated control execution, audit facilitation, and continuous reporting. The role requires technical leadership, team building, and proficiency in programming languages like Python, Apex, or Java, along with experience in GRC and meeting standards like SOX, PCI, and SOC2.

What you'd actually do

  1. Define and lead the vision to systematically automate manual compliance workstreams, engineering scalable processes that align with enterprise risk priorities.
  2. Recruit and lead a specialized team of compliance engineers, establishing technical standards and an engineering culture required to modernize controls within the DET environment.
  3. Architect an end-to-end agentic ecosystem to autonomously manage the compliance lifecycle, transitioning from manual evidence collection to automated, "push-button" execution.
  4. Direct the design and delivery of automated workflows and real-time dashboards (Tableau) to provide leadership with data-driven visibility into control health.
  5. Partner with SOX teams and external auditors to ensure engineering solutions meet rigorous standards, driving formal audit reliance on automated evidence.

Skills

Required

  • Apex and/or Java, SQL, SOQL, and Python
  • SOX, PCI, and SOC2 standards
  • design enterprise-level automation tools and API integrations
  • evaluating security control effectiveness
  • translating complex data into technical requirements
  • delivering real-time dashboards
  • agentic frameworks to automate workflows
  • synthesize unstructured data across disparate systems

Nice to have

  • fine-tuning or prompting Large Language Models (LLMs)
  • Salesforce Certified Technical Architect (CTA)
  • CISSP
  • CISM
  • Salesforce platform architecture
  • Tableau dashboards

What the JD emphasized

  • SOX
  • PCI
  • SOC2