FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Senior GRC Analyst, Common Control Framework
Salesforce. Support the design, maintenance, and evolution of Salesforce’s Common Control Framework (CCF) across compliance certification programs .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in security governance and compliance frameworks, with a strong focus on Salesforce’s Common Control Framework. Proficient in analyzing control requirements, developing documentation, and implementing compliance strategies to enhance operational efficiency.
Highest-signal resume keywords
Security GovernanceCompliance FrameworksSalesforce eGRCTechnical WritingCross-Functional Collaboration
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Application SecurityCloud SecurityIAMVulnerability ManagementSOC 2ISO 27001NIST CSFFedRAMPSOQLSalesforce Reporting
Soft Skills
Attention to DetailExcellent CommunicationIndependenceProfessionalism
Tools & Technologies
Salesforce eGRCServiceNow GRCArcherOneTrustLogicGate
Certifications & Qualifications
CISACISMCRISCISO 27001 Lead Implementer
Industry Keywords
Compliance OperationsControl FrameworkRegulatory StandardsAudit RegimesAI/ML Governance
Tech Stack
Tools & technologiesCloudServiceNow
About the role
Key responsibilities & impact- Support the design, maintenance, and evolution of Salesforce’s Common Control Framework (CCF) across compliance certification programs
- Map common controls to applicable frameworks, standards, and certification requirements
- Identify control reuse opportunities across programs
- Maintain and update control descriptions, mappings, applicability, and implementation guidance throughout the control lifecycle
- Support certification programs by analyzing requirements, identifying control coverage, and streamlining assessment processes and timelines
- Partner cross-functionally to support CCF adoption and implementation
- Research emerging regulations, standards, and certification requirements for potential impact on the CCF
- Analyze controls and framework requirements to standardize, reuse, and increase efficiency
- Improve CCF processes, controls, and implementation strategies to reduce compliance burden
- Support identification and implementation of compliance automation opportunities
- Develop and maintain reporting, metrics, and analyses on CCF adoption, control coverage, and certification readiness
- Identify and track control gaps and inconsistencies, escalating to senior team members as needed
- Maintain accurate, current CCF documentation and supporting materials
- Stay informed on regulatory, standards, and compliance trends and share relevant updates with the team
- Take ownership of defined controls, mappings, or workstreams as experience grows
- Use AI and generative-AI tooling responsibly to enhance CCF processes, stakeholder engagement, and data management
Requirements
What you’ll need- 3+ years in security governance, GRC, technical writing, program management, or compliance operations at a tech company
- Direct security-domain experience in application security, cloud security, IAM, vulnerability management, or GRC-adjacent work
- Ability to read controls, understand the risk they manage, and challenge a draft
- Ability to write clear, concise standards, policies, or procedures for non-security readers
- Working knowledge of a major security/privacy framework such as SOC 2, ISO 27001, NIST CSF, FedRAMP, PCI, HIPAA, EU AI Act, or equivalent
- Experience running cross-functional review cycles with senior stakeholders in Engineering, Legal, Privacy, and Product
- Strong attention to detail, including versioning, traceability, review dates, and approver signatures
- Experience with a GRC platform such as Salesforce eGRC, ServiceNow GRC, Archer, OneTrust, LogicGate, or similar
- Excellent written and verbal English communication
- Ability to work independently across many parallel workstreams
- Highest level of ethics, independence, and professionalism
- Prior experience at a cloud, SaaS, or platform company under multiple concurrent audit regimes (nice to have)
- Familiarity with the Salesforce platform, trust model, or AppExchange/partner ecosystem (nice to have)
- Exposure to AI/ML governance (nice to have)
- Hands-on experience with Salesforce reporting, SOQL, or admin-level custom object configuration (nice to have)
- CISA, CISM, CRISC, ISO 27001 Lead Implementer, or equivalent certification (nice to have)
- Experience supporting M&A security due diligence or acquisition integration (nice to have)
- Comfort adopting new AI/GenAI tools responsibly (nice to have)
Benefits
Comp & perks- Time off programs
- Medical insurance
- Dental insurance
- Vision insurance
- Mental health support
- Paid parental leave
- Life insurance
- Disability insurance
- 401(k)
- Employee stock purchasing program
- Incentive compensation may be available for eligible roles
- Equity may be available for eligible roles
- AI agents to accelerate impact
- Reasonable accommodation during the application or recruiting process