At a Glance
- Tasks: Oversee risk management and compliance for Salesforce, ensuring data protection and security.
- Company: Join AVEVA, a leader in industrial software trusted by top companies.
- Benefits: Enjoy flexible benefits, 28 days annual leave, and a supportive work culture.
- Why this job: Make a real impact on global compliance and security in a dynamic tech environment.
- Qualifications: 5+ years in risk and compliance, with Salesforce expertise and relevant certifications.
- Other info: Collaborative culture with excellent career growth opportunities and a focus on innovation.
The predicted salary is between 36000 - 60000 £ per year.
AVEVA is creating software trusted by over 90% of leading industrial companies.
We are seeking a highly experienced Salesforce Risk & Compliance Specialist to oversee risk management, security, and compliance for our Sales Enablement platforms, primarily focused on Salesforce. This role is responsible for ensuring that Salesforce solutions meet global regulatory requirements, align with enterprise risk frameworks, and maintain the highest standards of data protection, security, and governance. Reporting to the Sales Enablement Domain Director with a dotted line to the Head of IT GRC, this position collaborates closely with Sales Enablement teams to document control designs, organize evidence collection, manage dependencies (e.g., JML feeds from HR, access reviews by Business Owners), and strengthen Role-Based Access Control (RBAC) structures. The key objective is to ensure compliance with Sarbanes-Oxley (SOX) requirements, implement controls from the Crown Jewel Security Playbook (e.g., risk assessments, access reviews, patching, backups), and satisfy the Crown Jewel Security Policy by protecting critical assets through governance, identification, protection, detection, response, and recovery measures.
The ideal candidate will bring deep expertise in compliance, risk management, and Salesforce governance, with the ability to work with globally distributed teams and collaborate across business, legal, and technology functions.
Responsibilities
- Governance & Risk Management
- Define and maintain global compliance and risk frameworks for Salesforce implementation and operations.
- Document control designs for Sales Enablement processes, ensuring alignment with Crown Jewel Playbook controls (e.g., critical stakeholder inventory, supply chain risk management, risk assessments, data inventory, user access reviews).
- Project managing dependencies on other teams, such as timely Joiner-Mover-Leaver (JML) feeds from HR, and access reviews by Business Owners.
- Conduct risk assessments to identify, evaluate, and mitigate risks related to Salesforce data, processes, and integrations.
- Develop controls to ensure compliance with internal policies and external regulations.
- Regulatory & Compliance Oversight
- Ensure Salesforce configuration and operations comply with global and regional regulations (e.g., GDPR, SOX).
- Tightening RBAC structures by reviewing and documenting roles, permissions, and access controls, ensuring least privilege and periodic reviews.
- Security & Controls
- Collaborate with IT Security to design and enforce secure Salesforce configurations (SSO, MFA, RBAC, encryption).
- Ensure proper segregation of duties and implement internal controls within Salesforce.
- Oversee third-party application and integration risk assessments.
- Preparing for and responding to cybersecurity incidents within Sales Enablement scope, driving internal innovation to define best practices for securing the domain.
- Mitigating cybersecurity risks generated by Sales Enablement activities, ensuring policies are applied and critical assets (Crown Jewels) are protected.
- Audit & Monitoring
- Define audit-ready processes and provide evidence of compliance for internal and external audits.
- Establish monitoring, logging, and reporting mechanisms for ongoing compliance validation.
- Ensuring SOX compliance by gathering timely evidence of control operation and proactively preparing audit responses.
- Measuring compliance with IT policies, setting KPIs, and initiating activities to close gaps, preparing submissions for audits and the Executive Risk Committee.
- Implement continuous improvement to address findings from audits and risk reviews.
- Stakeholder Management & Enablement
- Act as a key liaison between compliance, security, business, and Salesforce program leadership.
- Provide guidance and training to Salesforce admins, developers, and business stakeholders on compliance best practices.
- Acting as the Digital Risk representative for the Domain interacting with other relevant GRC teams as required.
- Keep up-to-date with Salesforce releases, platform changes, and emerging technologies to ensure our performance strategy remains cutting-edge.
Skills & Qualifications
- ISACA (or equivalent) qualification: Certified Information Systems Auditor (CISA), or Certified Information System Manager (CISM), or Certified Governance of Enterprise IT (CGEIT).
- 5+ years of experience in risk, compliance, or governance roles, with at least 3 years focused on Salesforce or large-scale SaaS implementations.
- Strong knowledge of global data protection regulations (GDPR) and industry compliance frameworks (SOX, ISO 27001).
- Salesforce certifications (e.g., Salesforce Administrator, Security & Privacy Specialist).
- Proven track record in implementing risk and compliance programs across multiple geographies.
- Experience with Salesforce security and compliance features, including Shield, encryption, access controls, and audit logging.
- Experience estimating costs of remediation activities/projects, split by one-off vs recurring costs.
- Proficiency in documenting risk and control mappings for review by external auditors, with appreciation of impacts on financial statements.
- Ability to document and coach others on business process and system mapping, including RBAC structures.
- MS Office, especially MS Outlook, Excel, PowerPoint, and SharePoint; analytics skills an advantage.
- Knowledge of Crown Jewel Playbook controls (e.g., patching, MFA, data encryption, incident response) and Policy directives (e.g., govern, protect, detect).
- Excellent communication, stakeholder management, and leadership skills.
Desired skills
- Experience leading compliance efforts in multi-cloud Salesforce environments (Sales Cloud, Service Cloud, Marketing Cloud, etc.).
Our global team of 300+ IT professionals is responsible for the systems and platforms that keep AVEVA running. By empowering our colleagues and ensuring the smooth operation of the company, we help keep the business healthy and productivity high. We also provide key support for the transformation and modernisation efforts globally. We pride ourselves on a collaborative, inclusive and authentic culture that provides a framework allowing for autonomy, whilst always being available for support and guidance. We respect the differences that each team member brings and seek to include those perspectives in our solutions for our business functions. The energy and sense of purpose is evident when talking to team members, you will feel part of something special from the first day you join.
Find out more: Benefits include: Flexible benefits fund, emergency leave days, adoption leave, 28 days annual leave.
Salesforce Risk & Compliance Specialist in London employer: AVEVA
Contact Detail:
AVEVA Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Salesforce Risk & Compliance Specialist in London
✨Tip Number 1
Network like a pro! Reach out to people in your industry on LinkedIn or at events. A friendly chat can lead to opportunities that aren’t even advertised yet.
✨Tip Number 2
Prepare for interviews by researching the company and its culture. Tailor your answers to show how your skills align with their needs, especially around compliance and risk management.
✨Tip Number 3
Practice makes perfect! Do mock interviews with friends or use online platforms. The more comfortable you are speaking about your experience, the better you'll perform.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets noticed. Plus, we love seeing candidates who take that extra step.
We think you need these skills to ace Salesforce Risk & Compliance Specialist in London
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Salesforce Risk & Compliance Specialist role. Highlight your experience with compliance frameworks, risk management, and Salesforce governance. We want to see how your skills align with what we're looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about this role and how your background makes you the perfect fit. Don’t forget to mention any relevant certifications or experiences that relate directly to the job description.
Showcase Your Achievements: When detailing your past roles, focus on specific achievements rather than just responsibilities. Use metrics where possible to demonstrate your impact, especially in areas like compliance and risk management. We love numbers that tell a story!
Apply Through Our Website: We encourage you to apply through our website for the best chance of getting noticed. It’s super easy, and you’ll be able to keep track of your application status. Plus, we love seeing applications come directly from our site!
How to prepare for a job interview at AVEVA
✨Know Your Salesforce Inside Out
Make sure you brush up on your Salesforce knowledge, especially around compliance and risk management features. Familiarise yourself with tools like Shield, encryption, and access controls, as well as the Crown Jewel Playbook controls. This will show that you're not just a candidate, but someone who truly understands the platform.
✨Prepare for Regulatory Questions
Given the focus on global regulations like GDPR and SOX, be ready to discuss how you've navigated these in past roles. Think of specific examples where you've implemented compliance measures or conducted risk assessments. This will demonstrate your hands-on experience and understanding of the regulatory landscape.
✨Showcase Your Stakeholder Management Skills
This role requires collaboration across various teams, so be prepared to share examples of how you've successfully managed stakeholders in previous positions. Highlight your communication skills and any training or guidance you've provided to others, as this will illustrate your ability to lead and influence.
✨Demonstrate Continuous Improvement Mindset
Talk about how you've implemented changes based on audit findings or risk reviews in the past. Employers love candidates who are proactive about continuous improvement, so come armed with examples of how you've closed gaps and enhanced compliance processes in your previous roles.