Loading this job…
Loading this job…
MailerMen is hiring a Senior Salesforce Business Analyst to lead the end-to-end business analysis for a large-scale access and security transformation on an enterprise Salesforce platform. The work decides who inside a large organisation can see and do what in Salesforce, how that access is granted and how it is kept under control as the business changes. A central deliverable is a streamlined Role-Based Access Control (RBAC) model, meaning access is granted according to the job role a person performs rather than assembled person by person, which is what makes a large permission estate possible to understand, audit and maintain. You will sit between business stakeholders and technical architects, and you will be expected to speak both languages.
The first phase is an honest picture of the current state. You will oversee the extraction, mapping and audit of the legacy Salesforce security assets already in place, including Profiles, Permission Sets, Permission Set Groups, Roles, Queues, Licenses and the integration and system users that applications sign in as. From that inventory you will identify the operational risks: over-privileged access, orphaned accounts left behind by leavers and closed projects, license bloat, and Segregation of Duties (SoD) violations. Segregation of Duties is the principle that no one person should control every step of a sensitive process, so that the person who creates a record cannot also be the person who approves it without anyone else seeing it. Your output here is practical rather than theoretical: risk remediation matrices and impact analyses that someone can act on.
You will then design the target state. That means RBAC and ABAC architectures, where ABAC is attribute-based access control, granting access from attributes such as business unit, region or record type instead of a fixed role, built with Permission Set Groups, Muting Permission Sets, Restriction Rules and Public Groups to cut technical debt and enforce current governance standards. You will also define the access boundaries for newer platform capabilities, including Agentforce and Agentic AI features, which are AI agents that plan and carry out multi-step tasks on their own, alongside Einstein features and automated Flows, so that automation runs inside strictly defined security guardrails rather than inheriting more access than it needs. Running through all of it is discovery and documentation work: persona workshops across global business units, least-privilege access models, executive-ready reports, user stories, traceability matrices and change management material that secures buy-in from business and IT leadership. Salesforce certifications in Business Analysis, Administration or Advanced Administration, and Identity and Access Management Architecture, are preferred rather than required, and PMI-PBA or CBAP is a bonus.
This is a full-time role, worked on a hybrid basis, partly from the office in the location named on this listing and partly remotely. No fixed salary figure is published for this role: compensation is benchmarked to market standards for the role and will be discussed during the selection process. The role calls for 8–10 years of total experience, including 5+ years on Salesforce enterprise implementations. Apply through MailerMen with your updated resume and a summary of your relevant experience.
MailerMen runs a verified job board covering startup and product roles across twelve markets, and takes on interns across engineering, data, design and marketing to build it.