Description
About Our Team
The Global Compliance and Certification (GCC) team is responsible for enterprise wide compliance processes, ensuring Salesforce leadership has the information needed to make strategic risk-based decisions. You will report directly to a Manager on our APEX team, a division within the Product Security Organization, and will play a pivotal role in driving and overseeing cloud security compliance that support Salesforce’s products.
About the Role
We’re seeking an experienced and driven Sr. Risk & Compliance Specialist to lead and mature our compliance programs. In this role, you’ll be responsible for managing audits, regulatory requirements, and internal control frameworks that support our security posture and ensure adherence to global standards.
What you will be doing:
You’ll work cross-functionally with stakeholders in Security, Legal, IT, and Engineering to embed compliance into operational workflows and support certifications and attestations such as ISO 27001, SOC 2, PCI DSS, ISMAP, IRAP and others.
Work on compliance initiatives and assessments across various frameworks (e.g.SOC 2, ISO 27001, PCI, ISMAP, IRAP, etc.).
Manage and improve internal control environments, ensuring continuous alignment with applicable regulations and industry best practices.
Act as a senior liaison for external auditors, assessors, and internal stakeholders during audits and assessments.
Oversee the implementation and monitoring of corrective actions and risk mitigation efforts.
Develop and maintain compliance documentation, policies, and procedures.
Provide compliance training and awareness to relevant business units.
Track compliance metrics, drive remediation efforts, and communicate risks and progress to senior leadership.
What you should have:
6–8 years of relevant experience in information security compliance, risk management, or audit.
Deep knowledge of security standards and regulatory frameworks (e.g., ISO 27001, SOC 2,HIPAA, PCI, ISMAP, IRAP, etc.).
Experience managing compliance audits and interacting with external assessors or regulators.
Strong understanding of IT and security controls, particularly in cloud environments.
Good communication and stakeholder management skills.
Ability to translate regulatory requirements into actionable technical and process-oriented controls.
Nice to have:
Relevant certifications (e.g., CISA, CISSP, CRISC, ISO Lead Auditor).
Prior experience working with GRC tools and automation platforms.
Strategic mindset with the technical ability to translate compliance goals into engineering solutions.
Passion for global compliance and finding the path of least resistance to get there.
Ability to operate autonomously and drive innovation in regulated environments.
Strong solutioning mindset, being able to break down complex problems with simple solutions that are communicated in a clear and concise manner.
For roles in San Francisco and Los Angeles: Pursuant to the San Francisco Fair Chance Ordinance and the Los Angeles Fair Chance Initiative for Hiring, Salesforce will consider for employment qualified applicants with arrest and conviction records.