Security GRC Manager managing audits and compliance programs at Salesforce. Overseeing cloud security compliance and collaborating across departments for risk management.
Responsibilities
Manage and improve internal control environments, ensuring continuous alignment with applicable regulations and industry best practices.
Act as a senior liaison for external auditors, assessors, and internal stakeholders during audits and assessments.
Oversee the implementation and monitoring of corrective actions and risk mitigation efforts.
Develop and maintain compliance documentation, policies, and procedures.
Provide compliance training and awareness to relevant business units.
Track compliance metrics, drive remediation efforts, and communicate risks and progress to senior leadership.
Requirements
6–8 years of relevant experience in information security compliance, risk management, or audit.
Deep knowledge of security standards and regulatory frameworks (e.g., ISO 27001, SOC 2,HIPAA, PCI, ISMAP, IRAP, etc.).
Experience managing compliance audits and interacting with external assessors or regulators.
Strong understanding of IT and security controls, particularly in cloud environments.
Good communication and stakeholder management skills.
Ability to translate regulatory requirements into actionable technical and process-oriented controls.
Relevant certifications (e.g., CISA, CISSP, CRISC, ISO Lead Auditor) are nice to have.
Prior experience working with GRC tools and automation platforms is nice to have.
Strategic mindset with the technical ability to translate compliance goals into engineering solutions is nice to have.
Passion for global compliance and finding the path of least resistance to get there is nice to have.
Ability to operate autonomously and drive innovation in regulated environments is nice to have.
Strong solutioning mindset, being able to break down complex problems with simple solutions that are communicated in a clear and concise manner is nice to have.
Cloud Security Architect integrating cyber defense strategies across cloud platforms for Elevance Health. Lead collaboration with infrastructure and engineering teams to enhance security in cloud environments.
Senior Security Advisor designing advanced security solutions for Optiv’s clients. Driving sales and building relationships in a competitive cyber security landscape.
Personnel Security Specialist leading intake operations at PSI. Focused on case coordination, quality assurance, and team training for security suitability tasks.
Security Coordinator overseeing supervision and training of security personnel for BronxWorks' homeless services programs. Ensuring compliance, safety, and coordination with social services directors in Bronx area.
Part - Time Security Officer safeguarding personnel and property at Kaman Air Vehicles. Providing access control, monitoring systems, and responding to incidents in Bloomfield, CT.
Security Officer responsible for maintaining a safe environment for clients and employees. Enforcing policies and responding to emergencies at the client's site.
Senior Security Advisor enhancing security measures to align with corporate objectives at Desjardins. Leading development of strategic initiatives and overseeing best practices in security.
Controls Professional assessing internal control frameworks at Barclays, improving control effectiveness and managing risks to ensure compliance with regulations.
Senior Information Security Engineer at Wells Fargo investigating insider threats and strengthening cybersecurity measures. Conducting advanced investigations and collaborating with cyber teams to mitigate risks.