1

Grc Engineer Jobs in Utah (NOW HIRING)

GRC Program Manager

Draper, UT

$120K - $146K/yr

  • PTO

Partner closely with engineering to translate framework and control requirements into clear ... Own our GRC tooling and automation, and drive continuous compliance rather than point-in-time ...

New

Senior Security GRC Lead

Salt Lake City, UT · On-site

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

Senior Security GRC Lead Austin | Chicago | New York City | Salt Lake City | San Francisco Gong ... Partner with Engineering, Infrastructure, and Product Security to embed controls at the ...

Find opportunities for automation and collaborate with GRC Engineering to improve control monitoring and evidence collection. * Contribute to critical initiatives that improve Tech GRC capabilities ...

The ideal candidate combines strong hands‑on security engineering expertise with a passion for ... Experience with GRC platforms, compliance automation, or risk management solutions. * Exposure to ...

You will focus on the execution of day-to-day GRC (Governance, Risk, and Compliance) operations ... Partner with Legal, Engineering, IT, Finance, and HR to ensure corporate security policies are ...

You will focus on the execution of day-to-day GRC (Governance, Risk, and Compliance) operations ... Partner with Legal, Engineering, IT, Finance, and HR to ensure corporate security policies are ...

next page

Showing results 1-20

Grc Engineer information

See Utah salary details

$54.2K

$101.6K

$184.8K

How much do grc engineer jobs pay per year?

As of Aug 17, 2026, the average yearly pay for grc engineer in Utah is $101,626.00, according to ZipRecruiter salary data. Most workers in this role earn between $73,300.00 and $120,600.00 per year, depending on experience, location, and employer.

What is a GRC engineer?

GRC Engineers are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization’s information security and IT frameworks. They help ensure that a company’s policies and procedures meet regulatory requirements, manage risks, and align with business objectives. GRC Engineers often implement and maintain tools, conduct risk assessments, and ensure compliance through audits and reporting. Their role is critical in minimizing risks and protecting organizational assets from security threats.

What are the key skills and qualifications needed to thrive as a GRC engineer?

To thrive as a GRC Engineer, you need a solid understanding of governance, risk management, and compliance frameworks, often supported by a degree in information security or a related field. Familiarity with GRC platforms (such as RSA Archer or ServiceNow GRC), risk assessment tools, and certifications like CISA or CISSP are highly valued. Strong analytical skills, attention to detail, and effective communication are crucial soft skills for collaborating across departments and translating complex requirements. These competencies ensure that organizations can effectively manage risk, maintain regulatory compliance, and safeguard critical information assets.

What are some common challenges faced by GRC engineers when implementing new compliance frameworks?

GRC Engineers often encounter challenges such as integrating new compliance requirements with existing IT systems, ensuring consistent documentation, and keeping up with evolving regulatory standards. Collaboration with various departments—like IT, legal, and operations—is essential to map processes accurately and address potential gaps. Proactive communication and a strong understanding of both technical and regulatory aspects help GRC Engineers overcome these hurdles and support organizational compliance effectively.

What is the difference between Grc Engineer vs Security Analyst?

AspectGrc EngineerSecurity Analyst
CertificationsISO 27001, CISSP, CISACISSP, CompTIA Security+
Work EnvironmentPolicy development, compliance, risk managementMonitoring, incident response, threat analysis
Industry UsageCorporate governance, compliance teamsSecurity operations centers, IT departments

Grc Engineers focus on establishing and maintaining governance, risk, and compliance frameworks, ensuring organizations meet regulatory standards. Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within the cybersecurity industry, Grc Engineers emphasize policy and compliance, whereas Security Analysts focus on threat detection and response.

Are GRC engineer jobs hard to get?

GRC (Governance, Risk, and Compliance) engineer jobs can be competitive, especially for entry-level positions, but having relevant skills in cybersecurity, risk management, and certifications like CISSP or CISA can improve chances. The difficulty of securing a GRC engineer role depends on experience, education, and the demand within the industry or organization. Strong knowledge of compliance frameworks and tools is often required to stand out.

How much do GRC engineers make?

GRC (Governance, Risk, and Compliance) engineers typically earn between $80,000 and $130,000 annually, depending on experience, certifications, and location. Senior roles or those with specialized skills in cybersecurity tools and frameworks can earn higher salaries, often exceeding $150,000.

Is GRC engineer an entry-level job?

A GRC (Governance, Risk, and Compliance) engineer is typically an intermediate to senior role that requires relevant experience and knowledge of security frameworks, compliance standards, and risk management tools. Entry-level positions may be available but often require foundational skills, certifications, or internships in cybersecurity or IT governance.

What are popular job titles related to Grc Engineer jobs in Utah?

For Grc Engineer jobs in Utah, the most frequently searched job titles are:

What job categories do people searching Grc Engineer jobs in Utah look for?

The top searched job categories for Grc Engineer jobs in Utah are:

What cities in Utah are hiring for Grc Engineer jobs?

Cities in Utah with the most Grc Engineer job openings:

Infographic showing various Grc Engineer job openings in Utah as of August 2026, with employment types broken down into 91% Full Time, and 9% Contract. Highlights an 64% In-person, and 36% Remote job distribution, with an average salary of $101,626 per year, or $48.9 per hour.

GRC Program Manager

Redo

Draper, UT

$120K - $146K/yr

Full-time

PTO

Posted 3 days ago

New


Job description

About Redo
Redo is an e-commerce growth platform. We help merchants personalize every step of the buyer journey to maximize profit and lifetime value, with solutions spanning returns, warranties, order tracking, and post-purchase communications. We're growing fast, moving quickly, and building the systems that let some of the best brands in commerce trust us with their customers.
About the Role
Security and compliance are core to how Redo operates and how our merchants trust us with their customers. We're growing explosively, and as we scale, we're investing in a dedicated owner to take our governance, risk, and compliance program to the next level — and that's where you come in.
Redo is growing fast, which makes this a rare blue-ocean opportunity to own GRC end to end. This isn't a box-checking role — it's a chance to drive real impact and influence across the organization. You'll deepen and expand our compliance across SOC 2, GDPR, CCPA, and the frameworks that come next, setting the strategy, owning the execution, and shaping how security is built into the company as we grow. You'll also work directly with our merchants, where a strong security story helps close deals.
You'll partner shoulder-to-shoulder with engineering to turn compliance requirements into concrete controls, keep us audit-ready as we scale, and be the person our merchants trust when they run a security review. We're looking for a seasoned practitioner who can operate independently and be the go-to expert on all things GRC.
If you want ownership, visible impact, and the chance to shape a maturing security program at a fast-growing company, this is it.
What You'll Do

  • Own, mature, and scale Redo's GRC program end to end — SOC 2, GDPR, CCPA, PCI, and HIPAA and additional frameworks as our merchant base demands them.

  • Partner closely with engineering to translate framework and control requirements into clear, actionable technical and engineering requirements — and make sure they get implemented and stay implemented.

  • Own audit readiness: lead audits and assessments, manage auditor relationships, and run evidence collection and continuous control monitoring.

  • Lead compliance sales enablement by responding to merchant and prospect security reviews — questionnaires, due-diligence requests, and trust/security documentation — and turn it into a low friction process that smooths sales deals.

  • Build and maintain security policies, standards, and procedures, and drive their adoption across the company.

  • Manage third-party/vendor risk management.

  • Own our GRC tooling and automation, and drive continuous compliance rather than point-in-time scrambles.

  • Lead AI enablement of the compliance program — put AI to work automating evidence collection, control monitoring, security-questionnaire responses, and documentation so the program scales faster than headcount.

  • Manage access reviews, security awareness training, and evidence of ongoing operating effectiveness.

  • Keep leadership informed on compliance posture, gaps, and progress, and represent Redo's security program to customers and partners.

What We're Looking For

  • 5+ years in GRC, security compliance, or a closely related role, with hands-on ownership (not just support) of at least one full compliance program.

  • Demonstrated experience taking a company through a full SOC 2 certification and continued surveillance.

  • Depth of experience helping SaaS platforms support GDPR and data privacy obligations.

  • Experience navigating HIPAA and PCI environments.

  • A self-directed operator who can own and mature a program with minimal oversight — you know what "good" looks like and can drive it independently.

  • Ability to translate control requirements into engineering requirements and to collaborate credibly with software engineers.

  • Experience responding to customer security reviews and security questionnaires.

  • Strong writing and communication skills — you can produce clear policies and explain security posture to both engineers and non-technical stakeholders.

  • Comfortable in a fast-moving, high-growth environment where you set the pace.

  • Experience using AI for custom compliance automation

Nice to Have

  • Relevant certifications such as CISA, CISSP, ISO 27001 Lead Implementer/Auditor, or CIPP/E.

  • Experience with GRC automation platforms (e.g., Vanta, Drata, Secureframe).

Benefits

  • Work with a dynamic, innovative team in the fast-growing ecommerce industry

  • Opportunities for career growth and advancement

  • On-site gym with showers, pickleball, and basketball

  • Flexible PTO company holidays

  • Redo perks: monthly allowance to support purchases from ecommerce stores

  • Company HSA contributions

  • Weekly lunches fully stocked break room

  • $100 monthly babysitting reimbursement

  • Office is minutes from biking and running trails


Redo is an equal opportunity employer and prohibits discrimination and harassment of any kind. We are committed to creating a diverse and inclusive work environment where all employees feel valued, respected, and supported.