Security GRC Senior Analyst

Own Company
Own Company

IT

Hyderabad, Telangana, India

Posted on Jun 17, 2026

Description

Overview of the Role

Salesforce is seeking a Senior Security GRC Analyst to support strategic Technology Transformation Initiatives (TTI) and compliance programs within Global Compliance & Certification (GCC). This role partners with Security, Engineering, Compliance, Risk, Audit, and Business teams to drive technology and compliance transformation initiatives, strengthen governance and compliance programs, and ensure secure implementation. The ideal candidate will assess emerging technologies, identify compliance and security risks, and drive remediation efforts to enhance compliance maturity, and secure innovation.

You will work closely with the Technology Transformation Initiatives (TTI) team to assess emerging technologies and strategic programs for compliance and security impacts, provide governance oversight, identify control gaps and regulatory risks, and drive remediation efforts that strengthen compliance maturity and secure innovation.

Key Responsibilities

  • Drive strategic technology transformation programs that modernize security and compliance capabilities, strengthen governance frameworks, and improve operational effectiveness.

  • Partner with Security, Engineering, Product, Risk, Audit, and Compliance stakeholders to ensure regulatory, security, privacy, and control requirements are effectively incorporated into technology strategy, transformation initiatives, and enterprise-wide programs.

  • Drive the implementation and continuous evolution of compliance programs across key regulatory and industry frameworks, including SOC 1, SOC 2, ISO 27001, PCI DSS, NIST, FedRAMP, and internal control frameworks, ensuring sustained audit readiness and control effectiveness.

  • Provide governance oversight for strategic technology initiatives, including Identity and Access Management (IAM), Agentic workflows, and other enterprise security programs, ensuring alignment with regulatory and organizational requirements.

  • Serve as a trusted advisor to Product and engineering teams by providing strategic guidance on security, governance practices, and compliance implications of emerging technologies.

  • Lead and coordinate internal and external audit engagements, including audit planning, control testing, evidence reviews, auditor engagement, issue management, and executive reporting to support successful audit outcomes and compliance.

  • Drive continuous improvement of compliance operating models, governance processes, control frameworks, and oversight mechanisms through cross-functional collaboration, data-driven insights, and technology-enabled transformation initiatives.

Required Qualifications

  • 5+ years of experience in GRC, Information Security, Cybersecurity, Risk Advisory, Compliance Consulting, or related security and compliance functions.

  • Experience with Agentic frameworks, workflow automation and LLMs including Claude, is a plus.

  • Strong understanding of security governance, control frameworks, risk management principles, Identity and Access Management (IAM), and compliance requirements.

  • Strong knowledge of security and compliance frameworks including SOC 1, SOC 2, ISO 27001, PCI DSS, NIST, and cloud security standards.

  • Experience working with cloud platforms such as AWS and GCP, including an understanding of cloud security, governance, compliance requirements, and shared responsibility models.

  • Strong analytical and problem-solving skills with the ability to navigate complex security, compliance, and technology challenges.

  • Ability to influence cross-functional teams and drive initiatives across large organizations.

  • Experience working with security, engineering, and business stakeholders.

Preferred Qualifications

  • Experience with enterprise GRC platforms such as ServiceNow GRC, Archer, AuditBoard, Vanta, or similar tools.

  • Experience supporting Identity and Access Management (IAM) programs and platforms.

  • Knowledge of continuous controls monitoring and compliance automation concepts.

  • Experience with AI technologies, agentic workflows, workflow automation, and Large Language Models (LLMs), such as Claude

  • Professional certifications such as CISSP, CISA, CCSP, or equivalent.

  • Experience with cloud platforms (AWS, GCP, Salesforce Hyperforce) and their compliance/security features.