1

Grc Engineer Jobs in Utah (NOW HIRING)

A Cybersecurity / GRC Engineer supports the execution and continuous improvement of an organization's governance, risk, and compliance (GRC) program. This role operates under the direction of GRC ...

Find opportunities for automation and collaborate with GRC Engineering to improve control monitoring and evidence collection. * Contribute to critical initiatives that improve Tech GRC capabilities ...

... for a Security Engineer to serve as a key technical expert on our Infrastructure Security ... Maintain risk registers and GRC platforms; ensure findings are triaged and resolved within SLA

Security Engineering Lead

Logan, UT · On-site

$132K - $176K/yr

... GRC framework that keeps the company audit-ready at all times. You are the founding pod lead for ... Recruit, develop, and lead the Security Engineer as the pod scales. Qualifications * Bachelor ...

Security Engineering Lead

Logan, UT · On-site

$132K - $176K/yr

... GRC framework that keeps the company audit-ready at all times. You are the founding pod lead for ... Recruit, develop, and lead the Security Engineer as the pod scales. Qualifications * Bachelor ...

You will focus on the execution of day-to-day GRC (Governance, Risk, and Compliance) operations ... Partner with Legal, Engineering, IT, Finance, and HR to ensure corporate security policies are ...

You will focus on the execution of day-to-day GRC (Governance, Risk, and Compliance) operations ... Partner with Legal, Engineering, IT, Finance, and HR to ensure corporate security policies are ...

Governance, Risk & Compliance Lead

Draper, UT · On-site

$146K/yr

... engineering teams. • A track record of being an early or first GRC hire: building from zero, staying hands-on, then hiring and leading a team as the company grows. • Clear, confident ...

next page

Showing results 1-20

Grc Engineer information

See Utah salary details

$54.2K

$101.6K

$184.8K

How much do grc engineer jobs pay per year?

As of Jul 28, 2026, the average yearly pay for grc engineer in Utah is $101,626.00, according to ZipRecruiter salary data. Most workers in this role earn between $73,300.00 and $120,600.00 per year, depending on experience, location, and employer.

What are GRC Engineers?

GRC Engineers are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization’s information security and IT frameworks. They help ensure that a company’s policies and procedures meet regulatory requirements, manage risks, and align with business objectives. GRC Engineers often implement and maintain tools, conduct risk assessments, and ensure compliance through audits and reporting. Their role is critical in minimizing risks and protecting organizational assets from security threats.

Is GRC still in demand?

GRC (Governance, Risk, and Compliance) engineers are in high demand due to increasing cybersecurity regulations and the need for organizations to manage risks effectively. Skills in risk assessment, compliance frameworks, and security tools like GRC software are valuable in this field, which is expected to grow as organizations prioritize security and regulatory adherence.

What engineers make $200,000 a year?

Senior GRC (Governance, Risk, and Compliance) engineers with extensive experience, specialized skills in cybersecurity frameworks, and relevant certifications such as CISSP or CISA can earn $200,000 or more annually. Compensation varies based on industry, location, and company size, with roles often requiring expertise in risk management, compliance standards, and security tools.

What are the key skills and qualifications needed to thrive as a GRC Engineer, and why are they important?

To thrive as a GRC Engineer, you need a solid understanding of governance, risk management, and compliance frameworks, often supported by a degree in information security or a related field. Familiarity with GRC platforms (such as RSA Archer or ServiceNow GRC), risk assessment tools, and certifications like CISA or CISSP are highly valued. Strong analytical skills, attention to detail, and effective communication are crucial soft skills for collaborating across departments and translating complex requirements. These competencies ensure that organizations can effectively manage risk, maintain regulatory compliance, and safeguard critical information assets.

What engineers make $500,000?

Senior engineers in specialized fields such as software engineering, data engineering, or cybersecurity can earn $500,000 or more annually, especially with extensive experience, advanced skills, and in high-demand industries. Executive or leadership roles like engineering managers or directors may also reach this compensation level. Achieving this often requires advanced certifications, a strong track record, and working in competitive or high-paying markets.

What are some common challenges faced by GRC Engineers when implementing new compliance frameworks?

GRC Engineers often encounter challenges such as integrating new compliance requirements with existing IT systems, ensuring consistent documentation, and keeping up with evolving regulatory standards. Collaboration with various departments—like IT, legal, and operations—is essential to map processes accurately and address potential gaps. Proactive communication and a strong understanding of both technical and regulatory aspects help GRC Engineers overcome these hurdles and support organizational compliance effectively.

What is the difference between Grc Engineer vs Security Analyst?

AspectGrc EngineerSecurity Analyst
CertificationsISO 27001, CISSP, CISACISSP, CompTIA Security+
Work EnvironmentPolicy development, compliance, risk managementMonitoring, incident response, threat analysis
Industry UsageCorporate governance, compliance teamsSecurity operations centers, IT departments

Grc Engineers focus on establishing and maintaining governance, risk, and compliance frameworks, ensuring organizations meet regulatory standards. Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within the cybersecurity industry, Grc Engineers emphasize policy and compliance, whereas Security Analysts focus on threat detection and response.

How much does a GRC engineer make?

A GRC (Governance, Risk, and Compliance) engineer's salary typically ranges from $80,000 to $130,000 annually, depending on experience, certifications, and location. Senior roles or those with specialized skills in security tools and frameworks can earn higher salaries.
What are popular job titles related to Grc Engineer jobs in Utah? For Grc Engineer jobs in Utah, the most frequently searched job titles are:
What cities in Utah are hiring for Grc Engineer jobs? Cities in Utah with the most Grc Engineer job openings:
Infographic showing various Grc Engineer job openings in Utah as of July 2026, with employment types broken down into 91% Full Time, and 9% Contract. Highlights an 64% In-person, and 36% Remote job distribution, with an average salary of $101,626 per year, or $48.9 per hour.

Cybersecurity Engineer

KēSTA I.T.

Draper, UT

$90K - $114K/yr

Full-time

Posted 11 days ago


Job description

Come build, innovate, disrupt, and thrive!


KēSTA I.T. is actively seeking a Cybersecurity Engineer for an immediate full-time opportunity with our industry leading client.


Are you on the lookout for a unique career opportunity that offers the chance to make a significant impact? If you're eager to contribute to a thriving and stable organization while maintaining your confidentiality, continue reading...


A Cybersecurity / GRC Engineer supports the execution and continuous improvement of an organization’s governance, risk, and compliance (GRC) program. This role operates under the direction of GRC leadership and is responsible for day-to-day risk, compliance, and audit activities to ensure cybersecurity practices align with regulatory, contractual, and business requirements.


This position plays a key role in operationalizing cybersecurity governance by conducting risk assessments, supporting audits, maintaining control frameworks, and partnering across IT and business teams to track and remediate findings. The ideal candidate is detail-oriented and analytical, with the ability to translate technical risks and controls into clear documentation and actionable insights.


Responsibilities

  • Conduct cybersecurity risk assessments for systems, applications, and business processes
  • Support third-party and vendor risk assessments, including due diligence reviews
  • Identify control gaps, document risks, and assist in developing remediation plans
  • Maintain and update the enterprise risk register, including risk scoring and tracking
  • Partner with control owners to validate mitigation efforts and assess risk status
  • Support internal and external audits by coordinating evidence collection and responses
  • Track audit findings and remediation activities, ensuring proper validation and closure
  • Assist with security questionnaires, RFP responses, and due diligence requests
  • Support compliance with regulatory and contractual requirements
  • Maintain and update cybersecurity policies, standards, and procedures
  • Map controls to industry frameworks such as NIST CSF, ISO 27001, and CIS
  • Support the development and maintenance of a unified control framework
  • Assist with control testing activities and documentation of effectiveness
  • Develop and maintain GRC metrics, dashboards, and reporting artifacts
  • Track key risk indicators (KRIs), audit trends, and remediation progress
  • Prepare reports and summaries for leadership and stakeholders
  • Maintain organized documentation and evidence repositories
  • Collaborate with cross-functional teams to drive risk awareness and remediation efforts
  • Support process improvements to enhance GRC efficiency and scalability
  • Assist in the implementation and optimization of GRC tools and automation
  • Stay current on evolving cybersecurity risks and compliance requirements
  • Perform additional related duties as needed


Requirements

  • Bachelor’s degree in Cybersecurity, Information Technology, Risk Management, or a related field
  • 3+ years of experience in cybersecurity, risk, compliance, or audit-related roles
  • Experience supporting audits, risk assessments, and compliance initiatives
  • Experience collaborating across IT and business teams
  • Working knowledge of cybersecurity frameworks such as NIST CSF, ISO 27001, and CIS


Preferred Qualifications:

  • Relevant certifications such as Security+, CISA, CRISC, or similar
  • Familiarity with GRC platforms (e.g., ServiceNow GRC, Archer, Drata, Vanta or similar tools)


Core Skills:

  • Strong analytical, documentation, and organizational capabilities
  • Ability to communicate technical concepts clearly to non-technical stakeholders
  • Attention to detail and ability to manage multiple priorities effectively



About KēSTA I.T.:


Our name says it all; KēSTA I.T. (Keys-to-I.T.) AND our people are our keys to our success!


KēSTA I.T. is a premier Utah-based technical staffing and consulting services firm. We specialize in temporary and permanent placement of Software, Hardware, Network, Cloud, CRM/ERP, Data, End-User support, Web and Executive / leadership-based positions on a full time and consulting basis. If you're interested in a role where top performance is rewarded, personal time is valued, and excellence is demanded at every level we want to talk to you today!


Where do you want to go? We've got the keys! ~ KēSTA I.T.


WWW.KeSTAIT.COM