Security GRC Manager
Listed on 2026-01-14
-
IT/Tech
Cybersecurity, Data Security, Information Security, IT Business Analyst
Join to apply for the Security GRC Manager role at Salesforce
Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn’t a buzzword — it’s a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all.
The Global Compliance and Certification (GCC) team is responsible for enterprise wide compliance processes, ensuring Salesforce leadership has the information needed to make strategic risk‑based decisions. You will report directly to the Sr. Manager on our APEX team, a division within the Product Security Organization, and will play a pivotal role in driving and overseeing cloud security compliance that supports Salesforce’s products.
We’re seeking an experienced and driven Security GRC Manager to lead and mature our compliance programs. In this role, you’ll be responsible for managing audits, regulatory requirements, and internal control frameworks that support our security posture and ensure adherence to global standards.
What You Will Be Doing- You’ll work cross‑functionally with stakeholders in Security, Legal, IT, and Engineering to embed compliance into operational workflows and support certifications and attestations such as ISO 27001, SOC 2, PCI DSS, ISMAP, IRAP and others.
- Work on compliance initiatives and assessments across various frameworks (e.g. SOC 2, ISO 27001, PCI, ISMAP, IRAP).
- Manage and improve internal control environments, ensuring continuous alignment with applicable regulations and industry best practices.
- Act as a senior liaison for external auditors, assessors, and internal stakeholders during audits and assessments.
- Oversee the implementation and monitoring of corrective actions and risk mitigation efforts.
- Develop and maintain compliance documentation, policies, and procedures.
- Provide compliance training and awareness to relevant business units.
- Track compliance metrics, drive remediation efforts, and communicate risks and progress to senior leadership.
- 6–8 years of relevant experience in information security compliance, risk management, or audit.
- Deep knowledge of security standards and regulatory frameworks (e.g. ISO 27001, SOC 2, HIPAA, PCI, ISMAP, IRAP).
- Experience managing compliance audits and interacting with external assessors or regulators.
- Strong understanding of IT and security controls, particularly in cloud environments.
- Good communication and stakeholder management skills.
- Ability to translate regulatory requirements into actionable technical and process‑oriented controls.
- Relevant certifications (e.g. CISA, CISSP, CRISC, ISO Lead Auditor).
- Prior experience working with GRC tools and automation platforms.
- Strategic mindset with the technical ability to translate compliance goals into engineering solutions.
- Passion for global compliance and finding the path of least resistance to get there.
- Ability to operate autonomously and drive innovation in regulated environments.
- Strong solutioning mindset, being able to break down complex problems with simple solutions that are communicated in a clear and concise manner.
Unleash Your Potential. When you join Salesforce, you’ll be limitless in all areas of your life. Our benefits and resources support you to find balance and be your best, and our AI agents accelerate your impact so you can do your best. Together, we’ll bring the power of Agentforce to organizations of all sizes and deliver amazing experiences that customers love.
Apply today to not only shape the future — but to redefine what’s possible — for yourself, for AI, and the world.
Accommodations:
If you require assistance due to a disability applying for open positions please submit a request via this Accommodations Request Form.
Salesforce is an equal opportunity employer and maintains a policy of non‑discrimination with all employees and applicants for employment. It means that at Salesforce, we believe in equality for all and can lead the path to…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).