Senior GRC Analyst, Policy Operations

Salesforce

Confirmed live today High trust
Hybrid

Quick summary

Work type
Hybrid
Location
Seattle, WAHerndon, VASan Francisco, CA
Salary
$117,200–$176,700 / yr
Employment
Full-time
Posted
5 days ago
Freshness
Confirmed live today
Closes
Oct 30, 2026

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $144k
This role $147k
$100k most similar roles pay here $185k

This role pays more than 53% of similar roles. Most pay $117,000–$170,237 — the shaded band above. At the midpoint, this role pays about $147k versus about $144k for comparable roles.

Based on 240 similar postings.

Employer

About Salesforce

Salesforce is the world''s leading customer relationship management (CRM) platform, offering cloud-based software for sales, service, marketing, analytics, and application development. Industry: Enterprise Software & Cloud Computing

Salesforce currently has 163 open roles on FindRole.

Listed pay typically runs $148,500–$260,100 across 119 roles with salary data.

Most-posted roles

View all roles at Salesforce

At a glance

TL;DR · Senior GRC Analyst, Policy Operations

Sr. GRC Analyst, Policy Operations joins the Security Governance team to manage the lifecycle of Salesforce Security Standards. This role serves as the operational backbone of the security assurance program by translating regulatory obligations and threat intelligence into clear requirements for engineering and product teams. You will triage intake for new policies, partner with subject matter experts to draft technical documentation in plain language, and manage the end-to-end review and approval cycle. Key responsibilities include maintaining a traceable standards register against frameworks like SOC 2, ISO 27001, FedRAMP, and the EU AI Act. The role requires expertise in technical writing, program management, and GRC platforms such as ServiceNow or OneTrust. Candidates should possess skills in Git, OSCAL, and Markdown while utilizing GenAI tools to accelerate drafting and summarization within a complex security domain.

What you'll do

  • Triage intake for new or updated security standards, policies, and control documents while assigning owners and timelines.
  • Draft and finalize technical security standards in plain language by collaborating with internal subject matter experts.
  • Manage the end-to-end review and approval cycle, including scheduling CAB reviews and tracking action items.
  • Publish approved standards to the eGRC platform and retire outdated documentation.
  • Ensure all internal controls are traceable to external regulatory requirements like SOC 2, ISO 27001, and FedRAMP.
  • Perform regular content reviews to ensure every standard has a clear owner and current review date.
  • Build and monitor dashboards to track the health, coverage, and adoption of security standards.
  • Coordinate stakeholder communications including changelogs, engineering briefings, and internal updates.

What we're looking for

  • Must have 3+ years of experience in security governance, GRC, technical writing, program management, or compliance operations at a software/product tech company.
  • Must be a U.S. citizen or Permanent Resident.
  • Must possess direct security-domain experience such as AppSec, cloud security, IAM, vulnerability management, or GRC-adjacent fields.
  • Must have the ability to write clear standards and policies for non-security readers.
  • Must have working knowledge of a major security/privacy framework like SOC 2, ISO 27001, NIST CSF, FedRAMP, PCI, HIPAA, or EU AI Act.
  • Must be comfortable running cross-functional review cycles with senior stakeholders.
  • Experience with Git, OSCAL, Markdown, and GRC platforms is required.
  • CISA, CISM, CRISC, ISO 27001 Lead Implementer, or equivalent certifications are preferred.

More like this

Similar roles

Senior GRC Analyst, Common Control Framework

Salesforce

Bellevue, WA +2 5 days ago $117,200–$176,700
GRC SOC 2 ISO 27001 NIST CSF FedRAMP PCI HIPAA EU AI Act Salesforce ServiceNow OneTrust Archer LogicGate SOQL AI generative-AI Cloud Security IAM Vulnerability Management Technical Writing
3+ yrs exp Hybrid

Senior Security GRC Analyst

Salesforce

Remote (Herndon, VA) 33 days ago $117,200–$176,700
Information Security Cybersecurity FedRAMP DoD SRG AWS Azure GCP SaaS IaaS PaaS Compliance Engineering AI Scripting Incident Response Security Operations Agile
4+ yrs exp Remote

Governance Operations Analyst

Booz Allen Hamilton

McLean, VA 65 days ago
Data Governance Metadata Management Access Governance SQL Power BI Power Automate Databricks Immuta Microsoft 365 Jira Confluence Agile AI Automation Data Classification Data Protection Continuous Improvement
1+ yrs exp

Security GRC Analyst Program Manager

Stripe

Remote 5 days ago $190,400–$285,600
Security GRC NIST CSF Cloud Architecture Identity Management AppSec Data Protection Incident Response Audit Compliance Secure Development Stablecoins Crypto
8+ yrs exp Remote

Senior DCO Analyst

Leidos

Odenton, MD 10 days ago $107,900–$195,050
SIEM ArcSight Splunk Elastic Incident Response Cyber Kill Chain UAT Security+ CEH(P) GCED GDSA GSEC PenTest+ Cloud+
8+ yrs exp

Senior DFIR Analyst

SentinelOne

20 days ago $108,000–$130,000
DFIR EDR XDR SIEM Python AWS Azure GCP Windows Linux macOS X-Ways Forensics Axiom FTK Malware Analysis Reverse Engineering Threat Hunting SaaS Cybersecurity
4+ yrs exp