Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Salesforce

Senior GRC Analyst, Common Control Framework

Salesforce

. Support the design, maintenance, and evolution of Salesforce’s Common Control Framework (CCF) across compliance certification programs .

Posted 9/29/2026full-timeUnited StatesSenior💰 $117,200 - $176,700 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in security governance and compliance frameworks, with a strong focus on Salesforce’s Common Control Framework. Proficient in analyzing control requirements, developing documentation, and implementing compliance strategies to enhance operational efficiency.

Highest-signal resume keywords
Security GovernanceCompliance FrameworksSalesforce eGRCTechnical WritingCross-Functional Collaboration

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Application SecurityCloud SecurityIAMVulnerability ManagementSOC 2ISO 27001NIST CSFFedRAMPSOQLSalesforce Reporting
Soft Skills
Attention to DetailExcellent CommunicationIndependenceProfessionalism
Tools & Technologies
Salesforce eGRCServiceNow GRCArcherOneTrustLogicGate
Certifications & Qualifications
CISACISMCRISCISO 27001 Lead Implementer
Industry Keywords
Compliance OperationsControl FrameworkRegulatory StandardsAudit RegimesAI/ML Governance

Tech Stack

Tools & technologies
CloudServiceNow

About the role

Key responsibilities & impact
  • Support the design, maintenance, and evolution of Salesforce’s Common Control Framework (CCF) across compliance certification programs
  • Map common controls to applicable frameworks, standards, and certification requirements
  • Identify control reuse opportunities across programs
  • Maintain and update control descriptions, mappings, applicability, and implementation guidance throughout the control lifecycle
  • Support certification programs by analyzing requirements, identifying control coverage, and streamlining assessment processes and timelines
  • Partner cross-functionally to support CCF adoption and implementation
  • Research emerging regulations, standards, and certification requirements for potential impact on the CCF
  • Analyze controls and framework requirements to standardize, reuse, and increase efficiency
  • Improve CCF processes, controls, and implementation strategies to reduce compliance burden
  • Support identification and implementation of compliance automation opportunities
  • Develop and maintain reporting, metrics, and analyses on CCF adoption, control coverage, and certification readiness
  • Identify and track control gaps and inconsistencies, escalating to senior team members as needed
  • Maintain accurate, current CCF documentation and supporting materials
  • Stay informed on regulatory, standards, and compliance trends and share relevant updates with the team
  • Take ownership of defined controls, mappings, or workstreams as experience grows
  • Use AI and generative-AI tooling responsibly to enhance CCF processes, stakeholder engagement, and data management

Requirements

What you’ll need
  • 3+ years in security governance, GRC, technical writing, program management, or compliance operations at a tech company
  • Direct security-domain experience in application security, cloud security, IAM, vulnerability management, or GRC-adjacent work
  • Ability to read controls, understand the risk they manage, and challenge a draft
  • Ability to write clear, concise standards, policies, or procedures for non-security readers
  • Working knowledge of a major security/privacy framework such as SOC 2, ISO 27001, NIST CSF, FedRAMP, PCI, HIPAA, EU AI Act, or equivalent
  • Experience running cross-functional review cycles with senior stakeholders in Engineering, Legal, Privacy, and Product
  • Strong attention to detail, including versioning, traceability, review dates, and approver signatures
  • Experience with a GRC platform such as Salesforce eGRC, ServiceNow GRC, Archer, OneTrust, LogicGate, or similar
  • Excellent written and verbal English communication
  • Ability to work independently across many parallel workstreams
  • Highest level of ethics, independence, and professionalism
  • Prior experience at a cloud, SaaS, or platform company under multiple concurrent audit regimes (nice to have)
  • Familiarity with the Salesforce platform, trust model, or AppExchange/partner ecosystem (nice to have)
  • Exposure to AI/ML governance (nice to have)
  • Hands-on experience with Salesforce reporting, SOQL, or admin-level custom object configuration (nice to have)
  • CISA, CISM, CRISC, ISO 27001 Lead Implementer, or equivalent certification (nice to have)
  • Experience supporting M&A security due diligence or acquisition integration (nice to have)
  • Comfort adopting new AI/GenAI tools responsibly (nice to have)

Benefits

Comp & perks
  • Time off programs
  • Medical insurance
  • Dental insurance
  • Vision insurance
  • Mental health support
  • Paid parental leave
  • Life insurance
  • Disability insurance
  • 401(k)
  • Employee stock purchasing program
  • Incentive compensation may be available for eligible roles
  • Equity may be available for eligible roles
  • AI agents to accelerate impact
  • Reasonable accommodation during the application or recruiting process