At a Glance
- Tasks: Lead global risk and compliance for Salesforce, ensuring data protection and regulatory adherence.
- Company: Join AVEVA, a global leader in industrial software with a collaborative culture.
- Benefits: Enjoy flexible benefits, 28 days annual leave, private medical insurance, and education assistance.
- Why this job: Make a real impact on compliance and security in a cutting-edge tech environment.
- Qualifications: 5+ years in risk and compliance, with strong Salesforce knowledge and relevant certifications.
- Other info: Hybrid working model with excellent career growth opportunities in a diverse team.
The predicted salary is between 48000 - 72000 Β£ per year.
We are seeking a highly experienced Global Risk & Compliance Lead to oversee risk management, security, and compliance for our Sales Enablement platforms, primarily focused on Salesforce. This role is responsible for ensuring that Salesforce solutions meet global regulatory requirements, align with enterprise risk frameworks, and maintain the highest standards of data protection, security, and governance. Reporting to the Sales Enablement Domain Director with a dotted line to the Head of IT GRC, this position collaborates closely with Sales Enablement teams to document control designs, organize evidence collection, manage dependencies (e.g., JML feeds from HR, access reviews by Business Owners), and strengthen Role-Based Access Control (RBAC) structures. The key objective is to ensure compliance with Sarbanes-Oxley (SOX) requirements, implement controls from the Crown Jewel Security Playbook (e.g., risk assessments, access reviews, patching, backups), and satisfy the Crown Jewel Security Policy by protecting critical assets through governance, identification, protection, detection, response, and recovery measures. The ideal candidate will bring deep expertise in compliance, risk management, and Salesforce governance, with the ability to work with globally distributed teams and collaborate across business, legal, and technology functions.
Responsibilities
- Define and maintain global compliance and risk frameworks for Salesforce implementation and operations.
- Document control designs for Sales Enablement processes, ensuring alignment with Crown Jewel Playbook controls (e.g., critical stakeholder inventory, supply chain risk management, risk assessments, data inventory, user access reviews).
- Project manage dependencies on other teams, such as timely Joiner-Mover-Leaver (JML) feeds from HR and access reviews by Business Owners.
- Conduct risk assessments to identify, evaluate, and mitigate risks related to Salesforce data, processes, and integrations.
- Develop controls to ensure compliance with internal policies and external regulations.
- Ensure Salesforce configuration and operations comply with global and regional regulations (e.g., GDPR, SOX).
- Tighten RBAC structures by reviewing and documenting roles, permissions, and access controls, ensuring least privilege and periodic reviews.
- Collaborate with IT Security to design and enforce secure Salesforce configurations (SSO, MFA, RBAC, encryption).
- Ensure proper segregation of duties and implement internal controls within Salesforce.
- Oversee third-party application and integration risk assessments.
- Prepare for and respond to cybersecurity incidents within Sales Enablement scope, driving internal innovation to define best practices for securing the domain.
- Mitigate cybersecurity risks generated by Sales Enablement activities, ensuring policies are applied and critical assets (Crown Jewels) are protected.
- Define audit-ready processes and provide evidence of compliance for internal and external audits.
- Establish monitoring, logging, and reporting mechanisms for ongoing compliance validation.
- Ensure SOX compliance by gathering timely evidence of control operation and proactively preparing audit responses.
- Measure compliance with IT policies, set KPIs, and initiate activities to close gaps, preparing submissions for audits and the Executive Risk Committee.
- Implement continuous improvement to address findings from audits and risk reviews.
- Act as a key liaison between compliance, security, business, and Salesforce program leadership.
- Provide guidance and training to Salesforce admins, developers, and business stakeholders on compliance best practices.
- Act as the Digital Risk representative for the domain interacting with other relevant GRC teams as required.
- Keep up-to-date with Salesforce releases, platform changes, and emerging technologies to ensure our performance strategy remains cutting-edge.
Skills & Qualifications
- ISACA (or equivalent) qualification: Certified Information Systems Auditor (CISA), Certified Information System Manager (CISM), or Certified Governance of Enterprise IT (CGEIT).
- 5+ years of experience in risk, compliance, or governance roles, with at least 3 years focused on Salesforce or large-scale SaaS implementations.
- Strong knowledge of global data protection regulations (GDPR) and industry compliance frameworks (SOX, ISO 27001).
- Salesforce certifications (e.g., Salesforce Administrator, Security & Privacy Specialist).
- Proven track record in implementing risk and compliance programs across multiple geographies.
- Experience with Salesforce security and compliance features, including Shield, encryption, access controls, and audit logging.
- Experience estimating costs of remediation activities/projects, split by one-off vs recurring costs.
- Proficiency in documenting risk and control mappings for review by external auditors, with appreciation of impacts on financial statements.
- Ability to document and coach others on business process and system mapping, including RBAC structures.
- MS Office, especially MS Outlook, Excel, PowerPoint, and SharePoint; analytics skills an advantage.
- Knowledge of Crown Jewel Playbook controls (e.g., patching, MFA, data encryption, incident response) and Policy directives (e.g., govern, protect, detect).
- Excellent communication, stakeholder management, and leadership skills.
Desired Skills
- Experience leading compliance efforts in multi-cloud Salesforce environments (Sales Cloud, Service Cloud, Marketing Cloud, etc.).
UK Benefits
- Flexible benefits fund
- Emergency leave days
- Adoption leave
- 28 days annual leave (plus bank holidays)
- Pension
- Life cover
- Private medical insurance
- Parental leave
- Education assistance program
It's possible weβre hiring for this position in multiple countries, in which case the above benefits apply to the primary location. Specific benefits vary by country, but our packages are similarly comprehensive.
Hybrid working
By default, employees are expected to be in their local AVEVA office three days a week, but some positions are fully office-based. Roles supporting particular customers or markets are sometimes remote.
Hiring process
Interested? Great! Get started by submitting your cover letter and CV through our application portal. AVEVA is committed to recruiting and retaining people with disabilities. Please let us know in advance if you need reasonable support during your application process.
About AVEVA
AVEVA is a global leader in industrial software with more than 6,500 employees in over 40 countries. Our cutting-edge solutions are used by thousands of enterprises to deliver the essentials of life β such as energy, infrastructure, chemicals, and minerals β safely, efficiently, and more sustainably. We are committed to embedding sustainability and inclusion into our operations, our culture, and our core business strategy.
Background checks
AVEVA requires all successful applicants to undergo and pass a drug screening and comprehensive background check before they start employment. Background checks will be conducted in accordance with local laws and may, subject to those laws, include proof of educational attainment, employment history verification, proof of work authorization, criminal records, identity verification, credit check. Certain positions dealing with sensitive and/or third-party personal data may involve additional background check criteria.
Equal Opportunity Employer
AVEVA is an Equal Opportunity Employer. We are committed to being an exemplary employer with an inclusive culture, developing a workplace environment where all our employees are treated with dignity and respect. We value diversity and the expertise that people from different backgrounds bring to our business. AVEVA provides reasonable accommodation to applicants with disabilities where appropriate. If you need reasonable accommodation for any part of the application and hiring process, please notify your recruiter. Determinations on requests for reasonable accommodation will be made on a caseβbyβcase basis.
Salesforce Global Risk & Compliance Lead in London employer: AVEVA
Contact Detail:
AVEVA Recruiting Team
StudySmarter Expert Advice π€«
We think this is how you could land Salesforce Global Risk & Compliance Lead in London
β¨Tip Number 1
Network like a pro! Reach out to folks in your industry on LinkedIn or at events. A friendly chat can lead to opportunities that arenβt even advertised yet.
β¨Tip Number 2
Prepare for interviews by researching the company and its culture. Tailor your answers to show how your experience aligns with their values and needs, especially around compliance and risk management.
β¨Tip Number 3
Practice makes perfect! Do mock interviews with friends or use online platforms. The more comfortable you are speaking about your skills and experiences, the better you'll perform.
β¨Tip Number 4
Donβt forget to apply through our website! Itβs the best way to ensure your application gets seen by the right people. Plus, it shows youβre genuinely interested in joining our team.
We think you need these skills to ace Salesforce Global Risk & Compliance Lead in London
Some tips for your application π«‘
Tailor Your Cover Letter: Make sure to customise your cover letter for the Salesforce Global Risk & Compliance Lead role. Highlight your relevant experience in risk management and compliance, especially with Salesforce, to show us youβre the perfect fit!
Showcase Your Skills: In your CV, donβt just list your qualificationsβdemonstrate how your skills align with the job description. Mention specific projects or achievements that relate to governance, risk assessments, and compliance frameworks.
Be Clear and Concise: When writing your application, keep it clear and to the point. Use bullet points where possible to make it easy for us to see your key achievements and qualifications at a glance.
Apply Through Our Website: We encourage you to apply directly through our website. Itβs the best way to ensure your application gets into the right hands and shows us youβre serious about joining our team!
How to prepare for a job interview at AVEVA
β¨Know Your Salesforce Inside Out
Make sure you have a solid understanding of Salesforce and its compliance features. Brush up on your knowledge of RBAC, encryption, and audit logging. Being able to discuss these elements confidently will show that you're not just familiar with the platform but also understand how to secure it.
β¨Master the Compliance Landscape
Familiarise yourself with global data protection regulations like GDPR and SOX. Be prepared to discuss how these regulations impact Salesforce operations. Showing that you can navigate the compliance landscape will demonstrate your readiness for the role.
β¨Prepare Real-World Examples
Think of specific instances where you've successfully managed risk or compliance in previous roles. Use the STAR method (Situation, Task, Action, Result) to structure your answers. This will help you articulate your experience clearly and effectively during the interview.
β¨Engage with Stakeholders
Since this role involves liaising with various teams, be ready to discuss how you've collaborated with different stakeholders in the past. Highlight your communication skills and ability to build relationships, as these are crucial for success in this position.