Security Grc Lead

Salesforce Salesforce · Enterprise · San Francisco, CA

Salesforce is seeking a Public Sector GRC Lead with experience in FedRAMP, NIST 800-53, and other public sector security and compliance frameworks to support their global public sector compliance program. The role involves maintaining current authorizations, onboarding new cloud products, and identifying future compliance targets. Responsibilities include managing auditor relationships, maintaining security documentation, driving continuous monitoring, providing subject matter expertise, conducting internal assessments, and leading audit planning. The ideal candidate has 3-5+ years of FedRAMP experience, project/program management experience, and broad knowledge of various security and compliance frameworks.

What you'd actually do

  1. Manage the relationships with our external auditors (including our 3PAO), sponsoring agencies, and FedRAMP PMO.
  2. Maintain the System Security Plan (SSP), Plan of Action & Milestones (POA&M), and the overall authorization package.
  3. Collaborate with a cross-functional team operating the FedRAMP controls, working to build strong relationships and internal processes that lead to shared positive outcomes
  4. Drive Continuous Monitoring efforts as part of FedRAMP and other standards.
  5. Provide subject-matter expertise on all public sector requirements (including FedRAMP) with R&D, sales & marketing, and customers.

Skills

Required

  • FedRAMP
  • NIST 800-53
  • public sector security and compliance frameworks
  • Information System Security Officer (ISSO)
  • System Owners
  • third-party auditors
  • System Security Plan (SSP)
  • Plan of Action & Milestones (POA&M)
  • Continuous Monitoring
  • internal assessments
  • audit training
  • risk/gap findings documentation
  • external audits
  • cloud products migration
  • project and program management
  • cross functional teams
  • R&D
  • commercial legal
  • sales
  • product/enterprise teams
  • privacy legal
  • SOX
  • SOC2
  • ISO 27001
  • PCI DSS
  • HIPAA
  • UK Cyber Essentials
  • IRAP
  • security posture risk reduction
  • internal security and business groups
  • compliance with Informatica's policies
  • internal and external regulatory requirements
  • government regulations
  • security best practices
  • status and metrics report generation
  • DevSecOps
  • U.S. citizen (U.S. born or naturalized) who does not hold dual citizenship and agrees to complete a U.S. federal government Minimum Background Investigation (MBI) for a Moderate Public Trust position

Nice to have

  • CISSP
  • CRISC
  • CISA
  • CISM
  • GIAC

What the JD emphasized

  • U.S. citizen (U.S. born or naturalized) who does not hold dual citizenship and agrees to complete a U.S. federal government Minimum Background Investigation (MBI) for a Moderate Public Trust position
  • FedRAMP
  • public sector security and compliance frameworks