> Markdown version of [/jobs/ext/2297982-enterprise-security-senior-analyst-security-partner](https://www.wearedevelopers.com/jobs/ext/2297982-enterprise-security-senior-analyst-security-partner). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Enterprise Security Senior Analyst, Security Partner - **Company:** Salesforce.com, Inc. - **Location:** San Francisco, CA, United States - **Experience:** Expert - **Salary:** $117,200.0 - $176,700.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Microsoft Visio, Tableau (Software), Tools for Reporting - **Published:** August 29, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88177864/1 ## About the Role * You have 3+ years of experience in consulting or a large corporate environment with a complex IT environment * You have strong understanding of security internal control methodologies and terminology (e.g., COSO, Cybersecurity Framework (CSF)) * You can identify and articulate key security risks and develop controls to mitigate them * You have experience implementing and testing security controls based on the NIST SP 800-53 standard Even Better If... * You've designed and implemented internal controls in response to identified risks * You're experienced with data and reporting tools such as Tableau or Visio * You hold a CISSP, CISA, PMP, or CISM certification ## Description Enterprise Security is looking for a Senior Analyst to support our Business Information Security Officers (BISOs) in their day-to-day work with Enterprise business unit customers. BISOs drive measurable security improvements and own the health of the relationship between their business units and Enterprise Security. As a Senior Analyst, you work alongside BISOs to keep those engagements running smoothly - tracking risks and commitments, coordinating deliverables, and preparing materials for stakeholder reviews. This role suits someone building on a solid cybersecurity foundation while working alongside experienced security professionals. You won't make independent architectural or risk-acceptance calls - those sit with the BISOs you support. You will make their work visible, actionable, and well-documented, and own the operational rhythm that keeps the team credible with its business unit customers. What You'll Actually Be Doing * Maintain an accurate, prioritized risk register for assigned business units, including intake of new findings and status updates * Track risk buy-down commitments - owners, dates, status - and flag slippage to the responsible BISO * Prepare recurring stakeholder materials (status decks, dashboards, executive read-outs) under BISO direction * Coordinate meetings between BISOs, business unit customers, and specialist teams; capture actions and drive follow-up ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Times of (climate) crisis - How and why sustainable software is a must!](https://www.wearedevelopers.com/videos/988-times-of-climate-crisis-how-and-why-sustainable-software-is-a-must) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions)