1

Grc Manager Jobs in Utah (NOW HIRING)

Senior Security GRC Lead Austin | Chicago | New York City | Salt Lake City | San Francisco Gong ... Establish and operate a formal exceptions management program, including intake, risk assessment ...

GRC Security Manager

West Valley City, UT · On-site

$150K - $165K/yr

We are looking for an experienced GRC Security Manager to lead cybersecurity governance, risk, and compliance efforts for a health-focused organization in West Valley City, Utah. This position will ...

Manage audit strategy across programs and align GRC strategy with revenue-generating certifications. Track and report revenue influenced by certifications. * Partner with GTM teams to position ...

What you need to succeed * 5-8+ years of experience in Governance, Risk & Compliance (GRC), Information Security, Audit, Risk Management, or a related field. * Solid understanding of industry ...

A Cybersecurity / GRC Engineer supports the execution and continuous improvement of an organization ... Bachelor's degree in Cybersecurity, Information Technology, Risk Management, or a related field ...

A Sr. Manager of IT Security Operations is responsible for leading and advancing an organization ... The role partners closely with Security Architecture, Governance/Risk/Compliance (GRC), IT Infras ...

Gong is seeking an experienced Third Party Risk Manager to join our Governance, Risk, and Compliance (GRC) team. In this role, you will own and mature Gong's third-party risk management program ...

next page

Showing results 1-20

Grc Manager information

See Utah salary details

$25.7K

$114.8K

$174.6K

How much do grc manager jobs pay per year?

As of Aug 9, 2026, the average yearly pay for grc manager in Utah is $114,791.00, according to ZipRecruiter salary data. Most workers in this role earn between $90,223.00 and $149,319.00 per year, depending on experience, location, and employer.

What does a GRC manager do?

A typical day for a GRC Manager involves coordinating risk assessments, reviewing regulatory compliance requirements, and working closely with departments such as IT, Legal, and Internal Audit to implement controls and mitigate risks. This role often includes developing or updating policies, conducting training sessions, and preparing reports for senior leadership or regulatory bodies. GRC Managers also keep an eye on emerging risks and compliance trends, ensuring that the organization proactively adapts its governance and risk strategies. Collaboration and regular communication with diverse teams make the work dynamic and engaging, as no two days are exactly the same.

What are the key skills and qualifications needed to thrive as a GRC manager?

To thrive as a GRC Manager, you need a deep understanding of governance, risk management, and compliance frameworks, often supported by a bachelor's degree in business, information security, or a related field. Experience with GRC platforms (such as RSA Archer, MetricStream, or ServiceNow), risk assessment tools, and certifications like CISA, CRISC, or CISSP are highly valued. Leadership, strong analytical skills, and effective communication are vital soft skills for influencing stakeholders and managing cross-functional teams. These abilities are essential to ensure regulatory adherence, mitigate organizational risks, and drive a culture of compliance throughout the company.

What is a GRC manager?

A GRC (Governance, Risk, and Compliance) Manager is responsible for developing and overseeing an organization's risk management, regulatory compliance, and corporate governance programs. They ensure that internal policies and external regulations are followed to mitigate risks and maintain legal and ethical standards. Their role includes implementing frameworks, conducting risk assessments, and collaborating with different departments to align business objectives with compliance requirements. GRC Managers also provide training and guidance to employees on regulatory changes and best practices.

What are the most commonly searched types of Grc jobs in Utah? The most popular types of Grc jobs in Utah are:
What are popular job titles related to Grc Manager jobs in Utah? For Grc Manager jobs in Utah, the most frequently searched job titles are:
What cities in Utah are hiring for Grc Manager jobs? Cities in Utah with the most Grc Manager job openings:
Infographic showing various Grc Manager job openings in Utah as of August 2026, with employment types broken down into 88% Full Time, 11% Part Time, and 1% Contract. Highlights an 84% Physical, 3% Hybrid, and 13% Remote job distribution, with an average salary of $114,791 per year, or $55.2 per hour.

Manager of Cybersecurity GRC

Kforce Technology Staffing

Salt Lake City, UT • On-site

$107K - $145K/yr

Other

Medical, Dental, Vision, Life, Retirement, PTO

Posted 8 days ago


Job description

RESPONSIBILITIES:
Kforce's client in Salt Lake City, UT is seeking an experienced Cybersecurity Governance, Risk & Compliance (GRC) Manager to lead enterprise cybersecurity risk management, compliance initiatives, and governance programs. This individual will play a key role in strengthening the organization's security posture by overseeing risk assessments, policy development, regulatory compliance efforts, vendor security reviews, security awareness programs, and cybersecurity reporting.
Key Responsibilities:
* Lead enterprise cybersecurity governance and risk management initiatives
* Conduct ongoing risk assessments to identify threats, vulnerabilities, and emerging cybersecurity concerns
* Develop, maintain, and execute risk treatment and mitigation plans aligned with business objectives
* Monitor organizational risk exposure and communicate risk findings to leadership and stakeholders
* Ensure alignment with industry standards, regulatory requirements, and internal controls
* Develop and maintain cybersecurity policies, standards, procedures, and governance frameworks
* Evaluate and update security documentation to align with evolving threats, business needs, and regulatory expectations
* Partner with business units to drive policy adoption, awareness, and compliance throughout the organization
* Design and manage enterprise-wide cybersecurity awareness programs
* Deliver training initiatives focused on security best practices, compliance obligations, and emerging cyber threats
* Measure program effectiveness and continuously improve awareness efforts based on risk trends and organizational needs
* Serve as a primary cybersecurity contact for internal and external audit activities
* Coordinate audit responses, remediation efforts, and compliance reporting
* Support payment card industry (PCI) compliance programs and ensure ongoing adherence to applicable requirements
REQUIREMENTS:
Preferred Certifications:
* CISSP (Certified Information Systems Security Professional)
* CISM (Certified Information Security Manager)
* CRISC (Certified in Risk and Information Systems Control)
* CDPSE (Certified Data Privacy Solutions Engineer)
* 5+ years of experience in cybersecurity governance, risk management, compliance, or information security leadership
* Experience conducting enterprise risk assessments and developing risk mitigation strategies
* Proven success creating and maintaining cybersecurity policies, standards, and governance frameworks
* Experience managing security awareness and training programs
* Strong understanding of audit processes and regulatory compliance requirements
* Experience supporting compliance efforts related to PCI-DSS, GDPR, CCPA, SOX, or similar frameworks
Desired:
* Strong knowledge of cybersecurity control frameworks including NIST CSF, NIST 800-series, ISO 27001, and PCI-DSS
* Expertise in cybersecurity risk identification, assessment, reporting, and remediation planning
* Experience managing third-party and vendor cybersecurity risk programs
* Familiarity with AI governance, emerging technology risks, and security implications of AI adoption
* Knowledge of privacy regulations and data protection standards
* Strong analytical, organizational, and problem-solving capabilities
* Excellent verbal and written communication skills with the ability to engage both technical and non-technical stakeholders
* Ability to build relationships and influence cross-functional teams across technology, legal, privacy, audit, and business functions
Preferred:
* Experience leading enterprise GRC programs, partnering with audit and compliance organizations, and operating within regulated environments will be highly successful in this role
* Experience developing cybersecurity metrics, vendor risk programs, and privacy-focused security initiatives is strongly preferred
The pay range is the lowest to highest compensation we reasonably in good faith believe we would pay at posting for this role. We may ultimately pay more or less than this range. Employee pay is based on factors like relevant education, qualifications, certifications, experience, skills, seniority, location, performance, union contract and business needs. This range may be modified in the future.
We offer comprehensive benefits including medical/dental/vision insurance, HSA, FSA, 401(k), and life, disability & ADD insurance to eligible employees. Salaried personnel receive paid time off. Hourly employees are not eligible for paid time off unless required by law. Hourly employees on a Service Contract Act project are eligible for paid sick leave.
Note: Pay is not considered compensation until it is earned, vested and determinable. The amount and availability of any compensation remains in Kforce's sole discretion unless and until paid and may be modified in its discretion consistent with the law.
This job is not eligible for bonuses, incentives or commissions.
Kforce is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.
By clicking ?Apply Today? you agree to receive calls, AI-generated calls, text messages or emails from Kforce and its affiliates, and service providers. Note that if you choose to communicate with Kforce via text messaging the frequency may vary, and message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You will always have the right to cease communicating via text by using key words such as STOP.