1

Cybersecurity Governance Risk Compliance Jobs in Utah

A Cybersecurity / GRC Engineer supports the execution and continuous improvement of an organization's governance, risk, and compliance (GRC) program. This role operates under the direction of GRC ...

Cybersecurity strategy and governance * Executive leadership and stakeholder management * Risk management and compliance oversight * Security operations and incident response * Cloud and emerging ...

New

next page

Showing results 1-20

Cybersecurity Governance Risk Compliance information

What is the difference between Cybersecurity Governance Risk Compliance vs Cybersecurity Analyst?

AspectCybersecurity Governance Risk ComplianceCybersecurity Analyst
CertificationsCISA, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentPolicy development, audits, compliance frameworksMonitoring security systems, incident response
Employer & Industry UsageOrganizations with compliance needs, regulatory bodiesIT security teams, cybersecurity firms

While Cybersecurity Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing risks, Cybersecurity Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential in a comprehensive cybersecurity strategy but differ in scope and daily responsibilities.

What are the key skills and qualifications needed to thrive as a Cybersecurity Governance, Risk, and Compliance (GRC) professional, and why are they important?

To thrive as a Cybersecurity GRC professional, you need a solid understanding of information security frameworks, risk management principles, and regulatory compliance, often supported by a degree in cybersecurity or related fields. Familiarity with tools like GRC platforms (e.g., Archer, ServiceNow), and certifications such as CISSP, CISM, or CRISC are highly valued. Strong analytical thinking, attention to detail, and effective communication skills help you interpret regulations and collaborate with stakeholders. These skills ensure organizations can manage cybersecurity risks proactively while meeting regulatory and industry standards.

What are some typical challenges faced by professionals in Cybersecurity Governance, Risk, and Compliance (GRC) roles?

Professionals in Cybersecurity GRC roles often navigate the challenge of keeping up with rapidly changing regulatory requirements while ensuring company policies align with both business objectives and security best practices. Balancing the need for robust security controls with operational efficiency, educating non-technical stakeholders about risk, and managing audits are common aspects of the job. Additionally, GRC professionals frequently collaborate with IT, legal, and business teams to ensure a cohesive approach to risk management and compliance. This dynamic environment requires strong communication skills, adaptability, and a commitment to continuous learning.

What is Cybersecurity Governance, Risk, and Compliance (GRC)?

Cybersecurity Governance, Risk, and Compliance (GRC) refers to a framework used by organizations to align their IT and security strategies with business objectives, manage risks, and ensure compliance with laws and regulations. Governance involves setting policies and procedures, risk focuses on identifying and addressing threats, and compliance ensures adherence to required standards. Professionals in this field help organizations protect sensitive data, avoid regulatory penalties, and build trust with stakeholders. GRC is essential for maintaining effective cybersecurity and demonstrating due diligence.
What are popular job titles related to Cybersecurity Governance Risk Compliance jobs in Utah? For Cybersecurity Governance Risk Compliance jobs in Utah, the most frequently searched job titles are:
What job categories do people searching Cybersecurity Governance Risk Compliance jobs in Utah look for? The top searched job categories for Cybersecurity Governance Risk Compliance jobs in Utah are:
What cities in Utah are hiring for Cybersecurity Governance Risk Compliance jobs? Cities in Utah with the most Cybersecurity Governance Risk Compliance job openings:

Cybersecurity Engineer

KēSTA I.T.

Draper, UT

$90K - $114K/yr

Full-time

Posted 12 days ago


Job description

Come build, innovate, disrupt, and thrive!


KēSTA I.T. is actively seeking a Cybersecurity Engineer for an immediate full-time opportunity with our industry leading client.


Are you on the lookout for a unique career opportunity that offers the chance to make a significant impact? If you're eager to contribute to a thriving and stable organization while maintaining your confidentiality, continue reading...


A Cybersecurity / GRC Engineer supports the execution and continuous improvement of an organization’s governance, risk, and compliance (GRC) program. This role operates under the direction of GRC leadership and is responsible for day-to-day risk, compliance, and audit activities to ensure cybersecurity practices align with regulatory, contractual, and business requirements.


This position plays a key role in operationalizing cybersecurity governance by conducting risk assessments, supporting audits, maintaining control frameworks, and partnering across IT and business teams to track and remediate findings. The ideal candidate is detail-oriented and analytical, with the ability to translate technical risks and controls into clear documentation and actionable insights.


Responsibilities

  • Conduct cybersecurity risk assessments for systems, applications, and business processes
  • Support third-party and vendor risk assessments, including due diligence reviews
  • Identify control gaps, document risks, and assist in developing remediation plans
  • Maintain and update the enterprise risk register, including risk scoring and tracking
  • Partner with control owners to validate mitigation efforts and assess risk status
  • Support internal and external audits by coordinating evidence collection and responses
  • Track audit findings and remediation activities, ensuring proper validation and closure
  • Assist with security questionnaires, RFP responses, and due diligence requests
  • Support compliance with regulatory and contractual requirements
  • Maintain and update cybersecurity policies, standards, and procedures
  • Map controls to industry frameworks such as NIST CSF, ISO 27001, and CIS
  • Support the development and maintenance of a unified control framework
  • Assist with control testing activities and documentation of effectiveness
  • Develop and maintain GRC metrics, dashboards, and reporting artifacts
  • Track key risk indicators (KRIs), audit trends, and remediation progress
  • Prepare reports and summaries for leadership and stakeholders
  • Maintain organized documentation and evidence repositories
  • Collaborate with cross-functional teams to drive risk awareness and remediation efforts
  • Support process improvements to enhance GRC efficiency and scalability
  • Assist in the implementation and optimization of GRC tools and automation
  • Stay current on evolving cybersecurity risks and compliance requirements
  • Perform additional related duties as needed


Requirements

  • Bachelor’s degree in Cybersecurity, Information Technology, Risk Management, or a related field
  • 3+ years of experience in cybersecurity, risk, compliance, or audit-related roles
  • Experience supporting audits, risk assessments, and compliance initiatives
  • Experience collaborating across IT and business teams
  • Working knowledge of cybersecurity frameworks such as NIST CSF, ISO 27001, and CIS


Preferred Qualifications:

  • Relevant certifications such as Security+, CISA, CRISC, or similar
  • Familiarity with GRC platforms (e.g., ServiceNow GRC, Archer, Drata, Vanta or similar tools)


Core Skills:

  • Strong analytical, documentation, and organizational capabilities
  • Ability to communicate technical concepts clearly to non-technical stakeholders
  • Attention to detail and ability to manage multiple priorities effectively



About KēSTA I.T.:


Our name says it all; KēSTA I.T. (Keys-to-I.T.) AND our people are our keys to our success!


KēSTA I.T. is a premier Utah-based technical staffing and consulting services firm. We specialize in temporary and permanent placement of Software, Hardware, Network, Cloud, CRM/ERP, Data, End-User support, Web and Executive / leadership-based positions on a full time and consulting basis. If you're interested in a role where top performance is rewarded, personal time is valued, and excellence is demanded at every level we want to talk to you today!


Where do you want to go? We've got the keys! ~ KēSTA I.T.


WWW.KeSTAIT.COM