← Back to job listings
SA
Security GRC Analyst
Salesforce · San Francisco, United States
About The Role
Join our Security and Compliance team as a Security GRC Analyst. In this role, you will lead our Unified Audit program, ensuring compliance across multiple frameworks including SOC 2, HIPAA, ISO 27001, and GxP. You will manage internal evidence collection, serve as the primary liaison with external auditors, and maintain compliance dashboards and documentation repositories. This position requires 2-4 years of experience in GRC, compliance, audit, or information security, and proficiency with GRC tools and audit management platforms.
- Lead the end-to-end Unified Audit program across multiple compliance frameworks, coordinating schedules and minimizing duplication.
- Manage internal evidence collection by assigning tasks to control owners, tracking deadlines, validating submissions, and conducting pre-audit gap reviews.
- Serve as the primary liaison with external auditors, scheduling walkthroughs, responding to information requests, and coordinating responses to findings.
- You have working knowledge of at least two of the following: SOC 2, HIPAA, ISO 27001, or GxP frameworks
- You are proficient with GRC tools, audit management platforms, and documentation systems (Microsoft Office Suite or Google Workspace)
- You have 2–4 years of experience in GRC, compliance, audit, or information security, with hands-on experience supporting or managing compliance audits
- You communicate clearly with both technical and non-technical stakeholders and thrive managing multiple concurrent deadlines
- You have worked directly with external audit firms in a compliance or security capacity
- You have hands-on experience with GRC platforms such as Drata, Vanta, OneTrust, or ServiceNow GRC
- You have experience with unified or integrated audit programs, or a background in healthcare or life sciences
- You hold one or more relevant certifications such as CISA (Certified Information Systems Auditor), CRISC (Certified in Risk and Information Systems Control), CISSP (Certified Information Systems Security Professional), or ISO 27001 Lead Auditor/Implementer
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring