Senior GRC Analyst, Common Control Framework

Salesforce

Confirmed live today High trust
Hybrid

Quick summary

Work type
Hybrid
Location
Bellevue, WAHerndon, VASan Francisco, CA
Salary
$117,200–$176,700 / yr
Employment
Full-time
Posted
4 days ago
Freshness
Confirmed live today
Closes
Oct 30, 2026

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $160k
This role $147k
$108k most similar roles pay here $203k

This role pays less than 60% of similar roles. Most pay $129,500–$190,750 — the shaded band above. At the midpoint, this role pays about $147k versus about $160k for comparable roles.

Based on 240 similar postings.

Employer

About Salesforce

Salesforce is the world''s leading customer relationship management (CRM) platform, offering cloud-based software for sales, service, marketing, analytics, and application development. Industry: Enterprise Software & Cloud Computing

Salesforce currently has 150 open roles on FindRole.

Listed pay typically runs $148,500–$260,100 across 114 roles with salary data.

Most-posted roles

View all roles at Salesforce

At a glance

TL;DR · Senior GRC Analyst, Common Control Framework

Sr. GRC Analyst, Common Control Framework works within the Common Controls Framework team to support day-to-day operations of a security governance and compliance program. This individual contributor role involves designing, maintaining, and evolving common controls while mapping them to various frameworks, standards, and certification requirements like SOC 2, ISO 27001, NIST CSF, FedRAMP, PCI, HIPAA, or the EU AI Act. The analyst will manage control lifecycles, identify automation opportunities, track gaps, and develop reporting on compliance readiness. Key responsibilities include drafting clear technical documentation and collaborating with cross-functional teams in Engineering, Legal, and Product. Required skills include experience in GRC, program management, or compliance operations, along with proficiency in tools such as Salesforce eGRC, ServiceNow GRC, Archer, or OneTrust to manage the complexities of multi-audit regimes and security risk.

What you'll do

  • Map common controls to applicable frameworks, standards, and certification requirements to identify reuse opportunities.
  • Maintain and update control documentation including descriptions, mappings, applicability, and implementation guidance throughout their lifecycle.
  • Analyze certification requirements to determine control coverage and streamline assessment processes and timelines.
  • Research emerging regulations and standards to evaluate potential impacts on the Common Controls Framework.
  • Identify and implement compliance automation opportunities to reduce the overall burden on the organization.
  • Develop and maintain reporting, metrics, and analyses regarding CCF adoption and certification readiness.
  • Track control gaps and inconsistencies while escalating critical issues to senior team members.
  • Utilize AI and generative-AI tools to enhance CCF processes, data management, and stakeholder engagement.

What we're looking for

  • 3+ years of experience in security governance, GRC, technical writing, program management, or compliance operations at a tech company.
  • Direct security-domain experience in areas such as application security, cloud security, IAM, vulnerability management, or GRC-adjacent fields.
  • Ability to write clear, concise standards, policies, or procedures for non-security readers.
  • Working knowledge of a major security/privacy framework like SOC 2, ISO 27001, NIST CSF, FedRAMP, PCI, HIPAA, or the EU AI Act.
  • Experience with a GRC platform such as Salesforce eGRC, ServiceNow GRC, Archer, OneTrust, LogicGate, or similar.
  • Ability to run cross-functional review cycles with senior stakeholders in Engineering, Legal, Privacy, and Product.
  • Experience at a cloud, SaaS, or platform company under multiple concurrent audit regimes (preferred).
  • CISA, CISM, CRISC, ISO 27001 Lead Implementer, or equivalent certification (preferred).

More like this

Similar roles

Senior GRC Analyst, Policy Operations

Salesforce

Seattle, WA +2 4 days ago $117,200–$176,700
GRC SOC 2 ISO 27001 NIST CSF FedRAMP PCI HIPAA EU AI Act Salesforce eGRC Git OSCAL Markdown SOQL AI GenAI AppSec IAM Vulnerability Management
3+ yrs exp Hybrid

Senior Security GRC Analyst

Salesforce

Remote (Herndon, VA) 32 days ago $117,200–$176,700
Information Security Cybersecurity FedRAMP DoD SRG AWS Azure GCP SaaS IaaS PaaS Compliance Engineering AI Scripting Incident Response Security Operations Agile
4+ yrs exp Remote

Staff Security Strategist GRC

Uber

San Francisco, CA +1 10 days ago
ServiceNow eGRC Python SQL NIST CSF NIST 800-53 ISO 27001 NIST RMF SOC 2 CIS Agile Data Analytics Workflow Automation Risk Quantification AuditBoard Archer OpenPages SAP GRC
10+ yrs exp

Staff Security Strategist GRC

Uber

San Francisco, CA +1 10 days ago
ServiceNow eGRC Python SQL Agile NIST CSF NIST 800-53 ISO 27001 NIST RMF SOC 2 CIS Data Analytics Workflow Automation Risk Quantification AuditBoard Archer OpenPages SAP GRC
10+ yrs exp