At a Glance
- Tasks: Lead risk management and compliance for Salesforce, ensuring data protection and security.
- Company: Join AVEVA, a global leader in industrial software with a collaborative culture.
- Benefits: Enjoy flexible benefits, 28 days annual leave, and professional development opportunities.
- Why this job: Make a real impact by safeguarding critical assets and driving compliance in a dynamic environment.
- Qualifications: 5+ years in risk and compliance, with strong Salesforce knowledge and relevant certifications.
- Other info: Hybrid working model with excellent career growth and a supportive team atmosphere.
The predicted salary is between 36000 - 60000 Β£ per year.
AVEVA is creating software trusted by over 90% of leading industrial companies.
Location: London or Cambridge
Employment Type: full-time
We are seeking a highly experienced Global Risk & Compliance Lead to oversee risk management, security, and compliance for our Sales Enablement platforms, primarily focused on Salesforce. This role is responsible for ensuring that Salesforce solutions meet global regulatory requirements, align with enterprise risk frameworks, and maintain the highest standards of data protection, security, and governance. Reporting to the Sales Enablement Domain Director with a dotted line to the Head of IT GRC, this position collaborates closely with Sales Enablement teams to document control designs, organize evidence collection, manage dependencies (e.g., JML feeds from HR, access reviews by Business Owners), and strengthen Role-Based Access Control (RBAC) structures. The key objective is to ensure compliance with Sarbanes-Oxley (SOX) requirements, implement controls from the Crown Jewel Security Playbook (e.g., risk assessments, access reviews, patching, backups), and satisfy the Crown Jewel Security Policy by protecting critical assets through governance, identification, protection, detection, response, and recovery measures.
The ideal candidate will bring deep expertise in compliance, risk management, and Salesforce governance, with the ability to work with globally distributed teams and collaborate across business, legal, and technology functions.
Responsibilities- Governance & Risk Management Define and maintain global compliance and risk frameworks for Salesforce implementation and operations.
- Documenting control designs for Sales Enablement processes, ensuring alignment with Crown Jewel Playbook controls (e.g., critical stakeholder inventory, supply chain risk management, risk assessments, data inventory, user access reviews).
- Project managing dependencies on other teams, such as timely Joiner-Mover-Leaver (JML) feeds from HR, and access reviews by Business Owners.
- Conduct risk assessments to identify, evaluate, and mitigate risks related to Salesforce data, processes, and integrations.
- Develop controls to ensure compliance with internal policies and external regulations.
- Regulatory & Compliance Oversight Ensure Salesforce configuration and operations comply with global and regional regulations (e.g., GDPR, SOX).
- Tightening RBAC structures by reviewing and documenting roles, permissions, and access controls, ensuring least privilege and periodic reviews.
- Security & Controls Collaborate with IT Security to design and enforce secure Salesforce configurations (SSO, MFA, RBAC, encryption).
- Ensure proper segregation of duties and implement internal controls within Salesforce.
- Oversee third-party application and integration risk assessments.
- Preparing for and responding to cybersecurity incidents within Sales Enablement scope, driving internal innovation to define best practices for securing the domain.
- Mitigating cybersecurity risks generated by Sales Enablement activities, ensuring policies are applied and critical assets (Crown Jewels) are protected.
- Audit & Monitoring Define audit-ready processes and provide evidence of compliance for internal and external audits.
- Establish monitoring, logging, and reporting mechanisms for ongoing compliance validation.
- Ensuring SOX compliance by gathering timely evidence of control operation and proactively preparing audit responses.
- Measuring compliance with IT policies, setting KPIs, and initiating activities to close gaps, preparing submissions for audits and the Executive Risk Committee.
- Implement continuous improvement to address findings from audits and risk reviews.
- Stakeholder Management & Enablement Act as a key liaison between compliance, security, business, and Salesforce program leadership.
- Provide guidance and training to Salesforce admins, developers, and business stakeholders on compliance best practices.
- Acting as the Digital Risk representative for the Domain interacting with other relevant GRC teams as required.
- Keep up-to-date with Salesforce releases, platform changes, and emerging technologies to ensure our performance strategy remains cutting-edge.
- Ideal Skills ISACA (or equivalent) qualification: Certified Information Systems Auditor (CISA), or Certified Information System Manager (CISM), or Certified Governance of Enterprise IT (CGEIT).
- 5+ years of experience in risk, compliance, or governance roles, with at least 3 years focused on Salesforce or large-scale SaaS implementations.
- Strong knowledge of global data protection regulations (GDPR) and industry compliance frameworks (SOX, ISO 27001).
- Salesforce certifications (e.g., Salesforce Administrator, Security & Privacy Specialist).
- Proven track record in implementing risk and compliance programs across multiple geographies.
- Experience with Salesforce security and compliance features, including Shield, encryption, access controls, and audit logging.
- Experience estimating costs of remediation activities/projects, split by one-off vs recurring costs.
- Proficiency in documenting risk and control mappings for review by external auditors, with appreciation of impacts on financial statements.
- Ability to document and coach others on business process and system mapping, including RBAC structures.
- MS Office, especially MS Outlook, Excel, PowerPoint, and SharePoint; analytics skills an advantage.
- Knowledge of Crown Jewel Playbook controls (e.g., patching, MFA, data encryption, incident response) and Policy directives (e.g., govern, protect, detect).
- Excellent communication, stakeholder management, and leadership skills.
- Desired skills Experience leading compliance efforts in multi-cloud Salesforce environments (Sales Cloud, Service Cloud, Marketing Cloud, etc.).
Our global team of 300+ IT professionals is responsible for the systems and platforms that keep AVEVA running. By empowering our colleagues and ensuring the smooth operation of the company, we help keep the business healthy and productivity high. We also provide key support for the transformation and modernisation efforts globally. We pride ourselves on a collaborative, inclusive and authentic culture that provides a framework allowing for autonomy, whilst always being available for support and guidance. We respect the differences that each team member brings and seek to include those perspectives in our solutions for our business functions. The energy and sense of purpose is evident when talking to team members, you will feel part of something special from the first day you join.
UK Benefits include: Flexible benefits fund, emergency leave days, adoption leave, 28 days annual leave (plus bank holidays), pension, life cover, private medical insurance, parental leave, education assistance program. Itβs possible weβre hiring for this position in multiple countries, in which case the above benefits apply to the primary location. Specific benefits vary by country, but our packages are similarly comprehensive.
By default, employees are expected to be in their local AVEVA office three days a week, but some positions are fully office-based. Roles supporting particular customers or markets are sometimes remote.
AVEVA is a global leader in industrial software with more than 6,500 employees in over 40 countries. Our cutting-edge solutions are used by thousands of enterprises to deliver the essentials of life β such as energy, infrastructure, chemicals, and minerals β safely, efficiently, and more sustainably. We are committed to embedding sustainability and inclusion into our operations, our culture, and our.
Salesforce Risk & Compliance Specialist employer: AVEVA Denmark
Contact Detail:
AVEVA Denmark Recruiting Team
StudySmarter Expert Advice π€«
We think this is how you could land Salesforce Risk & Compliance Specialist
β¨Tip Number 1
Network like a pro! Reach out to folks in your industry on LinkedIn or at events. A friendly chat can lead to opportunities that arenβt even advertised yet.
β¨Tip Number 2
Prepare for interviews by researching the company and its culture. Tailor your answers to show how your skills align with their needs, especially around compliance and risk management.
β¨Tip Number 3
Practice makes perfect! Do mock interviews with friends or use online platforms. The more comfortable you are speaking about your experience, the better you'll perform.
β¨Tip Number 4
Donβt forget to apply through our website! Itβs the best way to ensure your application gets seen by the right people. Plus, it shows youβre genuinely interested in joining our team.
We think you need these skills to ace Salesforce Risk & Compliance Specialist
Some tips for your application π«‘
Tailor Your CV: Make sure your CV is tailored to the Salesforce Risk & Compliance Specialist role. Highlight your experience with risk management, compliance frameworks, and Salesforce governance. We want to see how your skills align with what we're looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about this role and how your background makes you the perfect fit. Don't forget to mention any relevant certifications or experiences that relate to the job description.
Showcase Your Achievements: When detailing your work experience, focus on specific achievements rather than just duties. Use metrics where possible to demonstrate your impact in previous roles, especially in compliance and risk management areas. We love numbers that tell a story!
Apply Through Our Website: We encourage you to apply through our website for the best chance of getting noticed. Itβs super easy, and you'll be able to keep track of your application status. Plus, we love seeing applications come directly from our site!
How to prepare for a job interview at AVEVA Denmark
β¨Know Your Salesforce Inside Out
Make sure youβre well-versed in Salesforce governance and compliance features. Brush up on your knowledge of RBAC, encryption, and audit logging. Being able to discuss these topics confidently will show that youβre not just familiar with the platform but also understand its security implications.
β¨Understand Regulatory Requirements
Familiarise yourself with global data protection regulations like GDPR and SOX. Be prepared to discuss how these regulations impact Salesforce operations. Showing that you can navigate these complexities will demonstrate your expertise in risk management and compliance.
β¨Prepare for Scenario-Based Questions
Expect questions that ask you to solve hypothetical compliance issues or risk assessments. Think through potential scenarios related to Salesforce and be ready to explain your thought process. This will highlight your problem-solving skills and practical knowledge.
β¨Showcase Your Stakeholder Management Skills
Since this role involves liaising with various teams, be ready to share examples of how you've successfully managed stakeholder relationships in the past. Highlight your communication skills and ability to collaborate across different functions, as this is crucial for the position.