1

Grc Engineer Jobs in Utah (NOW HIRING)

Senior Security Engineer, IAM

Salt Lake City, UT · On-site

$110K - $151K/yr

This engineer owns the architecture, strategy, and operational maturity of AI-enabled identity ... Partner with GRC on identity controls aligned to SOX, SOC 2, ISO 27001, HIPAA, GDPR, and CCPA, and ...

You will focus on the execution of day-to-day GRC (Governance, Risk, and Compliance) operations ... Partner with Legal, Engineering, IT, Finance, and HR to ensure corporate security policies are ...

You will focus on the execution of day-to-day GRC (Governance, Risk, and Compliance) operations ... Partner with Legal, Engineering, IT, Finance, and HR to ensure corporate security policies are ...

Showing results 21-40

Grc Engineer information

See Utah salary details

$54.2K

$101.6K

$184.8K

How much do grc engineer jobs pay per year?

As of Sep 12, 2026, the average yearly pay for grc engineer in Utah is $101,626.00, according to ZipRecruiter salary data. Most workers in this role earn between $73,300.00 and $120,600.00 per year, depending on experience, location, and employer.

What is a GRC engineer?

GRC Engineers are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization’s information security and IT frameworks. They help ensure that a company’s policies and procedures meet regulatory requirements, manage risks, and align with business objectives. GRC Engineers often implement and maintain tools, conduct risk assessments, and ensure compliance through audits and reporting. Their role is critical in minimizing risks and protecting organizational assets from security threats.

What are the key skills and qualifications needed to thrive as a GRC engineer?

To thrive as a GRC Engineer, you need a solid understanding of governance, risk management, and compliance frameworks, often supported by a degree in information security or a related field. Familiarity with GRC platforms (such as RSA Archer or ServiceNow GRC), risk assessment tools, and certifications like CISA or CISSP are highly valued. Strong analytical skills, attention to detail, and effective communication are crucial soft skills for collaborating across departments and translating complex requirements. These competencies ensure that organizations can effectively manage risk, maintain regulatory compliance, and safeguard critical information assets.

What are some common challenges faced by GRC engineers when implementing new compliance frameworks?

GRC Engineers often encounter challenges such as integrating new compliance requirements with existing IT systems, ensuring consistent documentation, and keeping up with evolving regulatory standards. Collaboration with various departments—like IT, legal, and operations—is essential to map processes accurately and address potential gaps. Proactive communication and a strong understanding of both technical and regulatory aspects help GRC Engineers overcome these hurdles and support organizational compliance effectively.

What is the difference between Grc Engineer vs Security Analyst?

AspectGrc EngineerSecurity Analyst
CertificationsISO 27001, CISSP, CISACISSP, CompTIA Security+
Work EnvironmentPolicy development, compliance, risk managementMonitoring, incident response, threat analysis
Industry UsageCorporate governance, compliance teamsSecurity operations centers, IT departments

Grc Engineers focus on establishing and maintaining governance, risk, and compliance frameworks, ensuring organizations meet regulatory standards. Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within the cybersecurity industry, Grc Engineers emphasize policy and compliance, whereas Security Analysts focus on threat detection and response.

Are GRC engineer jobs hard to get?

GRC (Governance, Risk, and Compliance) engineer jobs can be competitive, especially for entry-level positions, but having relevant skills in cybersecurity, risk management, and certifications like CISSP or CISA can improve chances. The difficulty of securing a GRC engineer role depends on experience, education, and the demand within the industry or organization. Strong knowledge of compliance frameworks and tools is often required to stand out.

How much do GRC engineers make?

GRC (Governance, Risk, and Compliance) engineers typically earn between $80,000 and $130,000 annually, depending on experience, certifications, and location. Senior roles or those with specialized skills in cybersecurity tools and frameworks can earn higher salaries, often exceeding $150,000.

Is GRC engineer an entry-level job?

A GRC (Governance, Risk, and Compliance) engineer is typically an intermediate to senior role that requires relevant experience and knowledge of security frameworks, compliance standards, and risk management tools. Entry-level positions may be available but often require foundational skills, certifications, or internships in cybersecurity or IT governance.

What job categories do people searching Grc Engineer jobs in Utah look for?

The top searched job categories for Grc Engineer jobs in Utah are:

What cities in Utah are hiring for Grc Engineer jobs?

Cities in Utah with the most Grc Engineer job openings:

Infographic showing various Grc Engineer job openings in Utah as of September 2026, with employment types broken down into 91% Full Time, and 9% Contract. Highlights an 64% In-person, and 36% Remote job distribution, with an average salary of $101,626 per year, or $48.9 per hour.

Info Security sys Engineering

Salt Lake City, UT • On-site

CYNET SYSTEMS
IT Services • 501 - 1,000 employees

$55 - $60/hr

Contractor

Medical, Dental, Vision, Life, Retirement

Posted 24 days ago


Job description

Job Overview:

Pay Range: $55.00hr - $60.00hr

Requirement/Must Have:

  • Bachelor’s degree in cybersecurity, computer science, information systems, or related field with minimum 4+ years of prior relevant experience, or a Graduate Degree and a minimum of 2+ years of prior related experience, or in lieu of a degree, minimum of 8+ years of prior related experience.
  • One DoD 8140 / 8570-compliant certification (e.g., Security+, CISSP, SSCP, GSEC), or ability to obtain within 6 months of hire.
  • Must have a DoD Secret Clearance.
  • Understanding of networking concepts (TCP/IP, network architecture, boundary defense).
  • Experience working with embedded systems or communications systems.
  • Familiarity with Agile or DevSecOps environments.
  • Experience working in cross-functional engineering teams.

Responsibilities:

  • Execute and support RMF lifecycle activities including categorization, control selection, implementation, assessment, authorization, and continuous monitoring.
  • Develop, maintain, and review RMF documentation such as SSPs, SARs, POA&Ms, and Security Plans.
  • Interpret and apply security controls from NIST SP 800-53, CNSSI 1253, and related guidance.
  • Support implementation and validation of Security Technical Implementation Guides (STIGs) and other configuration baselines.
  • Collaborate with cross-functional engineering teams including systems, software, and hardware to ensure security requirements are properly implemented.
  • Interface with internal stakeholders, Authorizing Officials (AOs), and external assessors to support authorization efforts.
  • Track and report compliance status, risks, and remediation activities to program leadership.
  • Contribute to continuous monitoring strategies and ongoing system compliance.
  • Perform documentation analysis creation and lab work with IT systems and specialized embedded systems.
  • Travel up to 10% as needed.

Nice to Have:

  • Exposure to cryptographic systems, FIPS 140-3, or NSA certification processes.
  • Experience with high-assurance or classified systems.
  • Hands-on experience executing RMF within DoD environments.
  • Familiarity with tools such as eMASS or XACTA.
  • Experience applying NIST SP 800-53 security controls and STIGs.
  • Experience supporting Authority to Operate (ATO) processes.
  • Strong technical writing and documentation skills.
  • Familiarity with TEMPEST, Anti-Tamper, or related system security disciplines.
  • Experience supporting government customers in a SETA/A&AS role.
  • Additional certifications such as CISM, CISA, CEH, or GIAC.
  • Active TS/SCI clearance or ability to obtain.

Skills:

  • Risk Management Framework (RMF).
  • NIST SP 800-53.
  • CNSSI 1253.
  • STIGs.
  • Cybersecurity Governance, Risk, and Compliance (GRC).
  • Security Technical Implementation Guides.
  • eMASS.
  • XACTA.
  • TCP/IP.
  • Network Architecture.
  • Boundary Defense.
  • Embedded Systems.
  • Agile.
  • DevSecOps.

Qualification And Education:

  • Strong foundation in cybersecurity governance, risk, and compliance (GRC).
  • Strong technical writing and documentation skills.
  • Excellent communication and presentation skills.

Benefits:

Our Benefits Include:

  • Medical, Dental, and Vision Insurance
  • 401(k) Retirement Plan
  • Health Savings Account (HSA)
  • Disability Insurance (Short-Term and Long-Term)
  • Life and AD&D Insurance
  • Paid Sick Leave (where required by applicable state or local law)
  • Supplemental Insurance Plans
  • Identity Theft Protection
  • Pet Insurance
  • Employee Wellness Programs
  • Employee Assistance Program (EAP)
  • Career Growth and Professional Development Opportunities

Disclaimer: Benefits eligibility, accrual rates, and usage limits may vary based on employment status, length of service, and work location. Paid Sick Leave is provided in strict accordance with applicable state and municipal mandates. Cynet Systems Inc. reserves the right to modify, amend, or terminate any benefit plans at any time in accordance with applicable laws.


About Cynet Systems


Founded in 2010 and headquartered in the Washington, DC metro area, Cynet Systems Inc. is a leading technology staffing and workforce solutions company serving Fortune 500 companies, government agencies, and enterprise organizations across the United States and Canada. We deliver agile, scalable talent solutions across IT, engineering, life sciences, clinical, and professional staffing, powered by a high-performing recruitment engine operating across North America and Asia.

As a nationally and locally certified Minority Business Enterprise (MBE), Cynet Systems is committed to helping organizations build high-performing teams while empowering professionals to grow rewarding careers. Our organization is certified to ISO 9001, ISO 14001, ISO 27001, and SOC 2 Type II standards, reflecting our commitment to quality, security, operational excellence, and customer success.


Cynet Systems logo

About Cynet Systems

Sourced by ZipRecruiter

Cynet Systems Inc is a staffing and recruiting corporation nestled in Ashburn, VA, USA. Established in 2010, the company operates within the Information Technology and Services sector, specializing in providing effective workforce solutions to different business needs, including IT consulting, direct hire, and contract staffing services. Through the years, Cynet Systems has built an impressive portfolio, going beyond borders and expanding its operations internationally in Canada and India. Rooted in its core values of teamwork, leadership, and commitment, Cynet Systems helps businesses unlock their full potential by providing versatile and competent professionals that perfectly align with their needs. Fueled by their unwavering mission to deliver top-tier talent to businesses worldwide, Cynet Systems garnered various recognitions including SIA's fastest-growing staffing firms and Best Place to Work in Virginia for 2019.

Industry

It services

Company size

501 - 1,000 Employees

Headquarters location

Sterling, VA, US

Year founded

2010

Social media