Salesforce ITCompliance Auditor
Quick Overview
Job Description
Role: Salesforce ITCompliance Auditor - (Commerce Cloud | Marketing Cloud | Order Management)
Location : Bridgewater, NJ Hybrid onsite 3 days/week
Duration: Long term contract
About the Role
We are seeking a highly experienced Salesforce ITCompliance Auditor with a strong technical foundation across Salesforce Commerce Cloud (SFCC), Salesforce Marketing Cloud (SFMC), and Salesforce Order Management (OMS). This role sits at the intersection of IT audit, risk management, and hands-on Salesforce platform knowledge - ideal for a professional who can not only design and execute IT General Controls (ITGC) testing but also speak fluently to the underlying technical architecture of the Salesforce ecosystem being audited.
The ideal candidate will bring deep expertise in SOX/ITframeworks, access and change management controls, and system configuration reviews, combined with practical, technical familiarity with how Commerce Cloud, Marketing Cloud, and Order Management operate, integrate, and are governed.
Key Responsibilities
IT& Compliance
Plan, design, and execute IT General Controls (ITGC) testing across Salesforce platforms in accordance with SOX, internal audit, and enterprise risk frameworks.
Assess and test controls related to access management, change management, program development, and IT operations (ITOC) within SFCC, SFMC, and Order Management environments.
Evaluate user access provisioning, de-provisioning, role-based access control (RBAC), segregation of duties (SoD), and privileged access within Salesforce orgs.
Review change management processes for platform releases, configuration changes, and custom code deployments (Apex, integrations, workflows).
Identify control gaps, deficiencies, and risks; document findings with clear root-cause analysis and remediation recommendations.
Partner with internal and external auditors (Big 4 / statutory auditors) during audit cycles, walkthroughs, and control testing.
Maintain audit documentation, control matrices, RCMs (Risk Control Matrices), and testing workpapers in line with audit standards.
Technical & Platform Expertise
Apply hands-on understanding of Salesforce Commerce Cloud architecture (storefronts, cartridges, integrations, order flows) to assess technical and business process risks.
Leverage working knowledge of Salesforce Marketing Cloud (Journey Builder, Automation Studio, Contact Builder, data extensions) to evaluate data governance and access controls.
Understand Salesforce Order Management processes (order lifecycle, fulfillment, payments, returns) to assess transactional and financial control points.
Review integration points between Salesforce clouds and upstream/downstream systems (ERP, payment gateways, third-party platforms) for control coverage.
Assess data security, encryption, and platform configuration settings relevant to compliance and audit requirements.
Stakeholder & Process Management
Act as a bridge between IT, business, and audit teams - translating technical Salesforce configurations into audit-ready language.
Present audit findings and control assessments to senior stakeholders, IT leadership, and audit committees.
Drive remediation tracking and follow-up testing to ensure timely closure of identified issues.
Contribute to continuous improvement of ITframeworks, testing methodologies, and audit efficiency (including automation opportunities).
Required Qualifications
12+ years of overall experience in IT Audit, ITSOX compliance, or IT Risk & Controls, of which:
o 6+ years in IT/ SOX compliance and IT Risk & Controls (access management, change management, ITOC testing, audit methodology).
o 6+ years in a technical, hands-on capacity with Salesforce platforms.
Strong, demonstrable technical background in Salesforce Commerce Cloud, Salesforce Marketing Cloud, and Salesforce Order Management.
Solid understanding of SOX 404, COSO framework, COBIT, and IT General Controls testing methodologies.
Proven experience in access management, change management, and IT operations control testing.
Experience working with internal/external auditors and managing audit lifecycles end-to-end.
Strong documentation skills - RCMs, control narratives, workpapers, and audit reports.
Excellent stakeholder management and communication skills, with the ability to explain technical risk in business terms.
Bachelor's degree in Information Systems, Computer Science, Accounting, Finance, or related field.
Preferred Qualifications
Professional certifications such as CISA, CISSP, CRISC, or equivalent.
Salesforce certifications (e.g., Salesforce Administrator, Commerce Cloud Digital Developer, Marketing Cloud Administrator) are a strong plus.
Prior experience in a Big 4 / consulting firm audit environment.
Experience with GRC tools (e.g., AuditBoard, ServiceNow GRC, Archer).
Familiarity with data privacy regulations (GDPR, CCPA) as they apply to Marketing Cloud data handling.
What We Offer
Opportunity to work at the intersection of technology and compliance in a high-visibility role.
Exposure to enterprise-scale Salesforce implementations across Commerce, Marketing, and Order Management clouds.
Collaborative, onsite work environment with direct access to leadership and cross-functional teams.
Regards,
Jagannath Gaddam
Skills
Similar jobs
CSSP Auditor with Security Clearance
TekSynap · Fort Belvoir, United States
4 hours ago$120k - $170k/yrSenior FIAR_FISCAM Auditor
Decisionpoint Corporation · United States
5 hours ago2nd Shift Quality Control Auditor
CHEP · Jacksonville, United States
12 hours agoIT Internal Audit Manager
SpaceX · Hawthorne, United States
18 hours ago$140k - $220k/yrInpatient Coding Compliance Auditor (Remote)
Memorial Hermann Health System · Bellaire, United States
YesterdayInpatient Coding Compliance Auditor (Remote)
Memorial Hermann Health System · Houston, United States
Yesterday