1

Cybersecurity Governance Risk Compliance Jobs in Utah

GRC Security Manager

West Valley City, UT ยท On-site

$150K - $165K/yr

We are looking for an experienced GRC Security Manager to lead cybersecurity governance, risk, and compliance efforts for a health-focused organization in West Valley City, Utah. This position will ...

... Cybersecurity, or a related field, or equivalent practical experience. * 5+ years of experience in Enterprise Risk Management (ERM), Operational Risk, Governance, Risk & Compliance (GRC), Information ...

next page

Showing results 1-20

Cybersecurity Governance Risk Compliance information

What is the difference between Cybersecurity Governance Risk Compliance vs Cybersecurity Analyst?

AspectCybersecurity Governance Risk ComplianceCybersecurity Analyst
CertificationsCISA, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentPolicy development, audits, compliance frameworksMonitoring security systems, incident response
Employer & Industry UsageOrganizations with compliance needs, regulatory bodiesIT security teams, cybersecurity firms

While Cybersecurity Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing risks, Cybersecurity Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential in a comprehensive cybersecurity strategy but differ in scope and daily responsibilities.

What are the key skills and qualifications needed to thrive as a cybersecurity governance, risk, and compliance (GRC) professional?

To thrive as a Cybersecurity GRC professional, you need a solid understanding of information security frameworks, risk management principles, and regulatory compliance, often supported by a degree in cybersecurity or related fields. Familiarity with tools like GRC platforms (e.g., Archer, ServiceNow), and certifications such as CISSP, CISM, or CRISC are highly valued. Strong analytical thinking, attention to detail, and effective communication skills help you interpret regulations and collaborate with stakeholders. These skills ensure organizations can manage cybersecurity risks proactively while meeting regulatory and industry standards.

What are some typical challenges faced by professionals in cybersecurity governance, risk, and compliance (GRC) roles?

Professionals in Cybersecurity GRC roles often navigate the challenge of keeping up with rapidly changing regulatory requirements while ensuring company policies align with both business objectives and security best practices. Balancing the need for robust security controls with operational efficiency, educating non-technical stakeholders about risk, and managing audits are common aspects of the job. Additionally, GRC professionals frequently collaborate with IT, legal, and business teams to ensure a cohesive approach to risk management and compliance. This dynamic environment requires strong communication skills, adaptability, and a commitment to continuous learning.

Is cybersecurity governance risk compliance a good career?

Cybersecurity Governance, Risk, and Compliance (GRC) is a growing field that offers opportunities in managing organizational security policies, risk assessments, and regulatory compliance. It requires knowledge of security frameworks, certifications like CISSP or CISM, and strong analytical skills. The role is in demand across various industries due to increasing cybersecurity threats and regulatory requirements.

Is cybersecurity governance risk compliance a good job?

Cybersecurity Governance, Risk, and Compliance (GRC) roles are in high demand due to increasing cybersecurity threats and regulatory requirements. These jobs typically require knowledge of security frameworks, risk management, and compliance standards, offering opportunities for career growth and specialization. They often involve collaboration across departments and may require certifications like CISSP or CISA.

What is cybersecurity governance, risk, and compliance (GRC)?

Cybersecurity Governance, Risk, and Compliance (GRC) refers to a framework used by organizations to align their IT and security strategies with business objectives, manage risks, and ensure compliance with laws and regulations. Governance involves setting policies and procedures, risk focuses on identifying and addressing threats, and compliance ensures adherence to required standards. Professionals in this field help organizations protect sensitive data, avoid regulatory penalties, and build trust with stakeholders. GRC is essential for maintaining effective cybersecurity and demonstrating due diligence.

What are popular job titles related to Cybersecurity Governance Risk Compliance jobs in Utah?

For Cybersecurity Governance Risk Compliance jobs in Utah, the most frequently searched job titles are:

What job categories do people searching Cybersecurity Governance Risk Compliance jobs in Utah look for?

The top searched job categories for Cybersecurity Governance Risk Compliance jobs in Utah are:

What cities in Utah are hiring for Cybersecurity Governance Risk Compliance jobs?

Cities in Utah with the most Cybersecurity Governance Risk Compliance job openings:

Director, Governance, Risk & Compliance

MX Technologies, Inc.

Lehi, UT โ€ข On-site

Full-time

Posted 16 days ago


Job description

As we continue to grow our platform and expand our customer base, we're looking for an experienced Director of Governance, Risk & Compliance (GRC) to lead our enterprise Information Security Governance, Risk, Compliance, and Privacy programs. This leader will partner across Security, Engineering, Legal, Product, Sales, Customer Success, and Operations to ensure MX maintains industry-leading security and privacy standards while enabling the business to move quickly and responsibly.

Reporting directly to the VP & Chief Information Security Officer (CISO), you will lead the Compliance team and own the strategy, execution, and continuous improvement of MX's security governance, privacy, and regulatory compliance programs.

ย What You'll DoLead Governance, Risk & Compliance
  • Develop and execute MX's enterprise Governance, Risk & Compliance (GRC) strategy.
  • Build, mature, and continuously improve security, privacy, and risk management programs that align with business objectives and regulatory requirements.
  • Develop, maintain, and operationalize enterprise-wide security policies, standards, controls, and governance processes.
  • Establish scalable compliance frameworks that support continued company growth while reducing organizational risk.
Own Privacy & Regulatory Compliance
  • Lead the company's global privacy program across multiple jurisdictions.
  • Ensure compliance with applicable privacy regulations, including GDPR, CCPA, HIPAA, PIPEDA, UK Data Protection Act, and other emerging regulations.
  • Partner with Legal, Engineering, Product, and business stakeholders to perform Privacy Impact Assessments (PIAs) and advise on privacy requirements throughout the product lifecycle.
  • Develop governance frameworks for responsible data collection, storage, processing, retention, and sharing.
  • Oversee data mapping initiatives, vendor privacy reviews, and data governance practices.
Manage Audits & Customer Assurance
  • Own all internal and external security, privacy, and compliance audits.
  • Lead certification efforts including SOC 2, ISO 27001, PCI DSS, and other applicable frameworks.
  • Serve as the executive owner for customer security and privacy questionnaires.
  • Partner with Sales and Customer Success to support enterprise customer due diligence and security reviews.
Drive Risk Management
  • Continuously assess organizational security, compliance, and privacy risks.
  • Monitor effectiveness of security controls and recommend improvements where necessary.
  • Build reporting and metrics that provide executive leadership visibility into organizational risk posture.
  • Develop mitigation strategies and partner across engineering and operations to reduce risk.
Lead & Develop the Team
  • Lead, mentor, and grow a high-performing Compliance and Privacy team.
  • Foster a culture of accountability, operational excellence, and continuous improvement.
  • Develop scalable processes that improve efficiency while maintaining regulatory compliance.
Build Cross-Functional Partnerships
  • Partner closely with Security, Engineering, Legal, Product, Sales, Support, and Operations to embed security and privacy into business processes.
  • Influence stakeholders across the organization to balance business objectives with regulatory obligations.
  • Lead company-wide privacy and compliance awareness initiatives and employee training programs.
Basic Qualifications
  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Information Systems, Business, Legal Studies, or a related field.
  • 10+ years of experience leading Information Security Governance, Risk, Compliance, Privacy, or Security Operations programs.
  • Deep expertise with compliance frameworks
  • Experience implementing Governance, Risk & Compliance (GRC) platforms and common control frameworks.
Preferred Qualifications
  • Professional certifications such as: CIPP, CIPM, CIPT, CISM, CISA
  • Experience working within fintech or highly regulated industries.
  • Knowledge of Business Continuity Planning and Disaster Recovery.
  • Experience supporting multinational organizations with global regulatory requirements.
  • Familiarity with Web Application Firewalls (WAFs), Content Delivery Networks (CDNs), and modern cloud infrastructure.
ย