1

Grc Engineer Jobs in Utah (NOW HIRING)

Solution Architect - Security

Sandy, UT · On-site

$150K - $180K/yr

... GRC. * Translate frameworks into buying decisions - NIST CSF, ISO 27001, CIS, CMMC/DFARS, PCI DSS ... Partner with Telarus field sales, other engineers, and leadership. WHAT SUCCESS LOOKS LIKE * First ...

... GRC. * Translate frameworks into buying decisions - NIST CSF, ISO 27001, CIS, CMMC/DFARS, PCI DSS ... Partner with Telarus field sales, other engineers, and leadership. WHAT SUCCESS LOOKS LIKE * First ...

Showing results 41-42

Grc Engineer information

See Utah salary details

$54.2K

$101.6K

$184.8K

How much do grc engineer jobs pay per year?

As of Aug 17, 2026, the average yearly pay for grc engineer in Utah is $101,626.00, according to ZipRecruiter salary data. Most workers in this role earn between $73,300.00 and $120,600.00 per year, depending on experience, location, and employer.

What is a GRC engineer?

GRC Engineers are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization’s information security and IT frameworks. They help ensure that a company’s policies and procedures meet regulatory requirements, manage risks, and align with business objectives. GRC Engineers often implement and maintain tools, conduct risk assessments, and ensure compliance through audits and reporting. Their role is critical in minimizing risks and protecting organizational assets from security threats.

What are the key skills and qualifications needed to thrive as a GRC engineer?

To thrive as a GRC Engineer, you need a solid understanding of governance, risk management, and compliance frameworks, often supported by a degree in information security or a related field. Familiarity with GRC platforms (such as RSA Archer or ServiceNow GRC), risk assessment tools, and certifications like CISA or CISSP are highly valued. Strong analytical skills, attention to detail, and effective communication are crucial soft skills for collaborating across departments and translating complex requirements. These competencies ensure that organizations can effectively manage risk, maintain regulatory compliance, and safeguard critical information assets.

What are some common challenges faced by GRC engineers when implementing new compliance frameworks?

GRC Engineers often encounter challenges such as integrating new compliance requirements with existing IT systems, ensuring consistent documentation, and keeping up with evolving regulatory standards. Collaboration with various departments—like IT, legal, and operations—is essential to map processes accurately and address potential gaps. Proactive communication and a strong understanding of both technical and regulatory aspects help GRC Engineers overcome these hurdles and support organizational compliance effectively.

What is the difference between Grc Engineer vs Security Analyst?

AspectGrc EngineerSecurity Analyst
CertificationsISO 27001, CISSP, CISACISSP, CompTIA Security+
Work EnvironmentPolicy development, compliance, risk managementMonitoring, incident response, threat analysis
Industry UsageCorporate governance, compliance teamsSecurity operations centers, IT departments

Grc Engineers focus on establishing and maintaining governance, risk, and compliance frameworks, ensuring organizations meet regulatory standards. Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within the cybersecurity industry, Grc Engineers emphasize policy and compliance, whereas Security Analysts focus on threat detection and response.

Are GRC engineer jobs hard to get?

GRC (Governance, Risk, and Compliance) engineer jobs can be competitive, especially for entry-level positions, but having relevant skills in cybersecurity, risk management, and certifications like CISSP or CISA can improve chances. The difficulty of securing a GRC engineer role depends on experience, education, and the demand within the industry or organization. Strong knowledge of compliance frameworks and tools is often required to stand out.

How much do GRC engineers make?

GRC (Governance, Risk, and Compliance) engineers typically earn between $80,000 and $130,000 annually, depending on experience, certifications, and location. Senior roles or those with specialized skills in cybersecurity tools and frameworks can earn higher salaries, often exceeding $150,000.

Is GRC engineer an entry-level job?

A GRC (Governance, Risk, and Compliance) engineer is typically an intermediate to senior role that requires relevant experience and knowledge of security frameworks, compliance standards, and risk management tools. Entry-level positions may be available but often require foundational skills, certifications, or internships in cybersecurity or IT governance.

What are popular job titles related to Grc Engineer jobs in Utah?

For Grc Engineer jobs in Utah, the most frequently searched job titles are:

What job categories do people searching Grc Engineer jobs in Utah look for?

The top searched job categories for Grc Engineer jobs in Utah are:

What cities in Utah are hiring for Grc Engineer jobs?

Cities in Utah with the most Grc Engineer job openings:

Infographic showing various Grc Engineer job openings in Utah as of August 2026, with employment types broken down into 91% Full Time, and 9% Contract. Highlights an 64% In-person, and 36% Remote job distribution, with an average salary of $101,626 per year, or $48.9 per hour.

Solution Architect - Security

Telarus

Sandy, UT • On-site

$150K - $180K/yr

Full-time

Posted 21 days ago


Job description

Telarus is the largest privately held technology services distributor in North America. We put 400+ supplier relationships: Cybersecurity, CX, SD-WAN/SASE, Cloud, and AI: behind a network of Technology Advisors, MSPs, and VARs who sell to everyone from mid-market to Fortune 500.
This role is the security brain those advisors call when the deal gets real. You are not a demo jockey, and you are not a badge on a slide. You are the architect who walks into a CISO conversation on a partner's behalf, runs the discovery, designs the answer, and helps close the business.
Must have experience being customer-facing for technology sales.
WHY THIS ROLE EXISTS
Security is a fast-moving, consultative product - and it is the one where end customers need real help. Deals stall when nobody in the room can hold a credible conversation about risk, controls, frameworks, and what happens at 2 a.m. when the ransomware note appears.
Your job is to make sure that never happens. Every security opportunity in your book should move faster, land bigger, and close cleaner because you were on it.
WHAT YOU WILL OWN
1. Revenue - you carry a number
  • Own influenced security revenue against a quota. This is a performance role with variable comp tied to what you close, not to how many calls you attended.
  • Build and work your own pipeline as you generate opportunities via Advisors. Sit with and help them grow their base, and create opportunities that did not exist before you got there - do not wait for the queue to feed you. The good news: You are not cold-calling.
  • Drive deals to close: multi-thread into the customer, handle objections, build the business case, and stay on it through signature and provisioning.
  • Forecast honestly and manage your pipeline hygiene in Salesforce. We would rather hear bad news early than good news late.

2. Architecture - you design the answer
  • Lead discovery on the partner's behalf: current state, risk posture, compliance drivers, incident history, budget reality, and who actually signs.
  • Design solutions across the full stack - identity and access, network and edge (SASE/SSE/ZTNA), endpoint and XDR, SIEM/SOC and MDR, email and collaboration security, data protection and DLP, cloud posture (CSPM/CNAPP), OT/IoT, offensive testing, and GRC.
  • Translate frameworks into buying decisions - NIST CSF, ISO 27001, CIS, CMMC/DFARS, PCI DSS, HIPAA, SOX, and the state privacy patchwork - and tie controls to the customer's actual exposure and cyber insurance requirements.
  • Run supplier selection with intellectual honesty. Recommend the right fit from our portfolio, not the one that is easiest to quote.
  • Know where your edges are. Spot the cloud, network, CX, or AI attach and pull in the right teammate instead of guessing.

3. Enablement - you make the channel dangerous
  • Train and evangelize advisors and internal employees: whiteboard sessions, webinars, roadshows, mainstage and breakout content at Telarus events.
  • Build reusable assets - battle cards, discovery guides, reference architectures, objection-handling playbooks - so your expertise scales past the calls you personally take.
  • Be a public voice. Podcasts, panels, LinkedIn, industry groups. We want a name that partners ask for.

4. Relationships - you are the connective tissue
  • Own working relationships with supplier channel managers and supplier SEs. Know who to call to get a deal unstuck, a POC scheduled, or pricing sharpened.
  • Maintain deep proficiency in emerging security products, threat trends, and attacker TTPs. This category reinvents itself every 18 months.
  • Partner with Telarus field sales, other engineers, and leadership.

WHAT SUCCESS LOOKS LIKE
  • First 30 days: You know our security portfolio cold, you have met your top supplier contacts, and you are shadowing and then leading live partner calls.
  • First 60 days: You are running discovery solo, you have helped an Advisor create opportunities, and you have delivered your first advisor training.
  • First 90 days: You have a real pipeline you built, closed business on the board, and advisors in your region asking for you by name.
  • First 12 months: You are at or over quota, you have published reusable enablement that the whole SE org uses, and you have added an industry-leading certification.

WHAT YOU NEED - SECURITY DEPTH
These are hard requirements. We will test them in the interview.
  • 8+ years in information security, with at least 3 in a role where you owned outcomes - CISO, vCISO, Information Security Director, security architect, or senior consultant at an MSSP or advisory firm.
  • You have lived through real incidents. Ransomware, business email compromise, data exfiltration, insider threat, third-party breach. You can talk about what actually happened, what the response cost, and what you would do differently.
  • CISSP, CISM, CCSP, GIAC (GSEC/GCIH/GPEN), or equivalent. Security+ alone is not enough for this role.
  • Fluency across the modern stack - not vendor-deep in one product, but credible in every layer and able to say why one architecture beats another.
  • Framework and compliance fluency you can use in a sales conversation, not just recite: NIST, ISO, CIS, PCI, HIPAA, CMMC, SOX.
  • Working knowledge of cloud - hyperscaler architecture, shared responsibility, and where enterprise cloud transformation creates security gaps.
  • You can whiteboard a defensible architecture live, from memory, in front of a skeptical CISO.

WHAT YOU NEED - SELLING ABILITY
Technical brilliance without commercial instinct will fail in this role.
  • A track record you can prove. Quota attainment, influenced revenue, deals you personally moved. Bring numbers to the interview.
  • Enterprise pre-sales, sales overlay, or direct sales experience. You have been on the hook for a number before, and you liked it.
  • Elite discovery. You ask hard questions in a way that feels like a conversation, not an interrogation, and you can get a CISO to admit what is actually broken.
  • Executive presence. You have presented to boards, CFOs, and CISOs and held the room without hiding behind slides.
  • You sell through, not just to. This is an indirect model. You will win by making a partner look brilliant in front of their own customer, and you have to be genuinely fine with them getting the credit.
  • Business-case thinking. You can frame a security investment in terms of risk reduction, insurance premiums, audit findings, and dollars - not features.
  • Operational discipline. Clean CRM, accurate forecast, multiple concurrent deals, nothing dropped.

WHAT YOU NEED - THE PART WE CARE ABOUT MOST
We can teach the portfolio. We cannot teach this.
  • Self-directed. Nobody is going to tell you what to do every day. We will give you guidance and tools, but you will build a plan in your first two weeks because it did not occur to you to wait.
  • Competitive. You track your own numbers. You know where you rank. Losing a deal to a competitor bothers you for a week.
  • Relentlessly curious. You already read the threat reports, tinker with tools on your own time, and have opinions about where this industry is going.
  • Coachable ego. Confident enough to challenge a CISO, secure enough to be wrong in front of your team.
  • Continuous certification. We require one new industry certification per year and we pay for it. If that sounds like a burden rather than a perk, this is not your role.

NICE TO HAVE
  • Prior experience in the technology advisor / agent channel, a TSD(Technology Solutions Distributor).
  • Existing relationships with security suppliers or channel leadership.
  • Public speaking history - conference stage, podcast, published writing.
  • Offensive security background (pen testing, red team) or deep IR/forensics experience.
  • Experience selling into a specific vertical with heavy compliance pressure - healthcare, finance, defense industrial base, or state and local government.

THIS IS NOT THE RIGHT JOB FOR YOU IF
  • You want to be a pure technical resource with no revenue accountability.
  • You need a full inbound queue to stay busy.
  • You are a single-vendor specialist looking to keep selling that one product.
  • You need the customer relationship to be yours, and it will bother you that it belongs to the partner.
  • You have not touched a live security architecture in three years and are leading with your certifications.

WHO YOU WILL WORK WITH
Supplier channel managers and supplier engineers • Telarus field sales and field support managers • The Telarus Solution Architect and Sales Engineering teams • Technology Advisors, MSPs, and VARs • End customers up to and including the C-suite • Telarus executive leadership
OUR HIRING PROCESS
We designed this to be fast and to be hard. Expect four steps:
  • Screen with the SVP of Sales Engineering - 30 minutes, mostly about your numbers and why you want this.
  • Technical deep-dive with the SE team - real architecture, real tradeoffs, no trivia.
  • Live whiteboard and role-play - we hand you a discovery scenario and a skeptical stakeholder, and you run it. This is the step that decides it.
  • Final with leadership and a supplier reference conversation.