Security Grc Senior Analyst

Salesforce Salesforce · Enterprise · Hyderabad, India

Salesforce is looking for a Senior Security GRC Analyst to support technology transformation initiatives and compliance programs. This role involves partnering with various teams to drive technology and compliance transformation, strengthen governance, and ensure secure implementation of emerging technologies. The analyst will assess risks, drive remediation, and ensure alignment with regulatory and security requirements.

What you'd actually do

  1. Drive strategic technology transformation programs that modernize security and compliance capabilities, strengthen governance frameworks, and improve operational effectiveness.
  2. Partner with Security, Engineering, Product, Risk, Audit, and Compliance stakeholders to ensure regulatory, security, privacy, and control requirements are effectively incorporated into technology strategy, transformation initiatives, and enterprise-wide programs.
  3. Drive the implementation and continuous evolution of compliance programs across key regulatory and industry frameworks, including SOC 1, SOC 2, ISO 27001, PCI DSS, NIST, FedRAMP, and internal control frameworks, ensuring sustained audit readiness and control effectiveness.
  4. Provide governance oversight for strategic technology initiatives, including Identity and Access Management (IAM), Agentic workflows, and other enterprise security programs, ensuring alignment with regulatory and organizational requirements.
  5. Serve as a trusted advisor to Product and engineering teams by providing strategic guidance on security, governance practices, and compliance implications of emerging technologies.

Skills

Required

  • 5+ years of experience in GRC, Information Security, Cybersecurity, Risk Advisory, Compliance Consulting, or related security and compliance functions.
  • Strong understanding of security governance, control frameworks, risk management principles, Identity and Access Management (IAM), and compliance requirements.
  • Strong knowledge of security and compliance frameworks including SOC 1, SOC 2, ISO 27001, PCI DSS, NIST, and cloud security standards.
  • Experience working with cloud platforms such as AWS and GCP, including an understanding of cloud security, governance, compliance requirements, and shared responsibility models.
  • Strong analytical and problem-solving skills with the ability to navigate complex security, compliance, and technology challenges.
  • Ability to influence cross-functional teams and drive initiatives across large organizations.
  • Experience working with security, engineering, and business stakeholders.

Nice to have

  • Experience with Agentic frameworks, workflow automation and LLMs including Claude, is a plus.
  • Experience with enterprise GRC platforms such as ServiceNow GRC, Archer, AuditBoard, Vanta, or similar tools.
  • Experience supporting Identity and Access Management (IAM) programs and platforms.
  • Knowledge of continuous controls monitoring and compliance automation concepts.
  • Experience with AI technologies, agentic workflows, workflow automation, and Large Language Models (LLMs), such as Claude
  • Professional certifications such as CISSP, CISA, CCSP, or equivalent.
  • Experience with cloud platforms (AWS, GCP, Salesforce Hyperforce) and their compliance/security features.

What the JD emphasized

  • Agentic workflows
  • LLMs
  • SOC 1
  • SOC 2
  • ISO 27001
  • PCI DSS
  • NIST
  • FedRAMP