06 Sep
|
Omniskope
|
India
CRM Compliance Analyst (Salesforce Audit & ITGC)
Company: Omniskope
Function: Salesforce Delivery / Governance & Compliance
Experience: 3–7 years
Employment Type: Full time
About the Role
Omniskope is looking for a CRM Compliance Analyst to own the build-out and execution of a Salesforce compliance and audit program. This is a hands-on role at the intersection of Salesforce administration and IT governance/audit — you'll take generic ITGC and ISO 27001 policy requirements and turn them into documented, evidenced, and continuously operating controls inside Salesforce, starting with Identity & Access Management and Change Management.
If you enjoy untangling "what does this compliance requirement actually mean in our system?" and turning it into a clean, repeatable process — this role is built for you.
What You'll Do
- Stand up and operate priority ITGC controls for Identity & Access Management and Change Management within Salesforce.
- Extract user, permission, and system-admin data from Salesforce to build audit-ready evidence packages (data extracts, screenshots, sign-offs)
- Write and maintain clear process documentation and control narratives tailored to the actual Salesforce and Azure DevOps environment — not just a copy of a generic template
- Use Azure DevOps (ADO) as the change-tracking system of record to evidence that changes follow the approved release path
- Run the reviewer sign-off loop — requesting, tracking, and filing manager/reviewer approvals for controls like privileged-access revalidation
- Track each control's required cadence (monthly, quarterly, semi-annual) and ensure no evidence cycle is ever missed
- Expand documented, evidenced controls across additional Salesforce clouds as audit scope grows
- Look for opportunities to reduce manual, repetitive evidence-gathering through scripting or AI-assisted extraction as the process matures
- Act as a direct, hands-on point of contact with stakeholders — explaining compliance status and trade-offs without an intermediary
Must-Have:
- Hands-on experience with Salesforce administration — profiles, permission sets, permission set groups, role hierarchy
- Understanding of Salesforce release/deployment flow (dev → test → approval → production) well enough to document and evidence controlled change management
- Familiarity with IT General Controls (ITGC) structure — change management, user access, IT security — and the ability to translate a generic control statement into a specific, provable system requirement
- Strong process documentation and technical writing skills
- Comfortable working directly with stakeholders as the primary point of contact, without an intermediary
- Organized, detail-oriented, and comfortable owning a recurring, cadence-driven deliverable (not a one-time project)
Good-to-Have:
- Working knowledge of ISO 27001 domains (user access control, change management, disaster recovery)
- Exposure to GDPR or other data-privacy compliance considerations
- Experience with Azure DevOps (ADO) or similar change-tracking/ALM tooling
- Prior experience in a consulting, professional services, or shared-services environment
- Interest in using AI/automation to streamline repetitive compliance and evidence-gathering work
📌 CRM Compliance Analyst (India)
🏢 Omniskope
📍 India