Senior Security GRC Analyst

Airkit
Airkit

IT

San Francisco, CA, USA

Posted on Aug 8, 2026

Description

The Experience

Location: San Francisco, CA

The Senior Security GRC Analyst role is part of our Assurance team, sitting at the intersection of internal operations and external audit relationships. This role leads our IDMC Unified Audit program, keeping the company compliant, audit-ready, and continuously improving across multiple frameworks. As a key partner to control owners and external auditors alike, you will help ensure compliance programs run smoothly and certifications stay strong.

What You'll Actually Be Doing
  • Lead the end-to-end IDMC Unified Audit program across SOC (Service Organization Control) 1/2/3, HIPAA (Health Insurance Portability and Accountability Act), ISO (International Organization for Standardization) 27001, and GxP (Good Practice) frameworks, coordinating schedules and minimizing duplication across certifications.
  • Own the audit strategy and roadmap, setting priorities and timelines across frameworks and presenting program status and risk areas to leadership.
  • Manage internal evidence collection by assigning tasks to control owners, tracking deadlines, validating submissions, and conducting pre-audit gap reviews.
  • Serve as the primary liaison with external auditors, scheduling walkthroughs, responding to information requests, and coordinating responses to findings.


You're Our Person If...
  • You have 3+ years of experience in GRC (Governance, Risk, and Compliance), compliance, audit, or information security, with hands-on experience supporting or managing compliance audits.
  • You have working knowledge of at least two of the following: SOC, HIPAA, ISO 27001, or GxP frameworks.
  • You are proficient with GRC tools, audit management platforms, and documentation systems, such as Microsoft Office Suite or Google Workspace.
  • You communicate clearly with both technical and non-technical stakeholders, thrive managing multiple concurrent deadlines, and are comfortable guiding less experienced team members.


Even Better If...
  • You hold one or more relevant certifications, such as CISA (Certified Information Systems Auditor), CRISC (Certified in Risk and Information Systems Control), CISSP (Certified Information Systems Security Professional), or ISO 27001 Lead Auditor/Implementer.
  • You have experience with unified or integrated audit programs, or audit programs spanning multiple frameworks.
  • You have hands-on experience with JIRA.
  • You have worked directly with external audit firms in a compliance or security capacity.
  • You mentor and educate teams on audit methodology, evidence review, and stakeholder communication, and help build repeatable processes as the audit program scales.

Pursuant to the San Francisco Fair Chance Ordinance and the Los Angeles Fair Chance Initiative for Hiring, Salesforce will consider for employment qualified applicants with arrest and conviction records.

In the United States, compensation offered will be determined by factors such as location, job level, job-related knowledge, skills, and experience. Certain roles may be eligible for incentive compensation, equity, and benefits. Salesforce offers a variety of benefits to help you live well including: time off programs, medical, dental, vision, mental health support, paid parental leave, life and disability insurance, 401(k), and an employee stock purchasing program. More details about company benefits can be found at the following link: https://www.salesforcebenefits.com.