1

Grc Risk Analyst Jobs in Utah (NOW HIRING)

... risk-based prioritization aligned to business impact and threat intelligence * Partner with GRC ... Strong analytical and problem-solving skills * Excellent communication skills translating technical ...

The role partners closely with Security Architecture, Governance/Risk/Compliance (GRC), IT Infras ... Conduct root cause analysis and post-incident reviews to strengthen security controls * Coordinate ...

SOX Manager

Draper, UT

$94K - $125K/yr

Risk Assessment & Scoping: Perform the annual qualitative and quantitative risk assessment to ... Analytical Thinking: Strong conceptual and problem-solving skills with meticulous attention to ...

Drive threat modeling and architectural risk assessments for strategic initiatives; translate ... Partner with Security Engineering, Application Security, Security Operations, and GRC to ensure ...

ServiceNow Developer

Salt Lake City, UT · On-site

$85K - $141K/yr

Strong analytical, problem-solving skills. * Ability to work effectively in a team environment ... risk management, etc.), particularly in a federal environment. * Candidates with an ACTIVE "SECRET ...

next page

Showing results 1-20

Grc Risk Analyst information

What is the difference between Grc Risk Analyst vs Compliance Analyst?

AspectGrc Risk AnalystCompliance Analyst
CertificationsISO 31000, FRM, CRISCISO 19600, CCEP, CISA
Work EnvironmentRisk management teams, corporate officesRegulatory departments, corporate offices
Industry UsageFinance, banking, insurance, corporate riskFinancial services, healthcare, manufacturing
Job FocusIdentifying, assessing, and mitigating risks across enterpriseEnsuring compliance with laws and regulations

While both roles involve regulatory and risk considerations, a Grc Risk Analyst focuses on enterprise-wide risk management strategies, whereas a Compliance Analyst concentrates on adherence to specific laws and regulations. Both roles require similar certifications and often work in overlapping industries, but their core responsibilities differ in scope and focus.

What are GRC Risk Analysts?

GRC Risk Analysts are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization. They assess and manage risks related to business operations, ensure compliance with relevant laws and regulations, and help implement policies and controls to mitigate potential threats. These analysts work closely with management to identify vulnerabilities, develop risk management strategies, and monitor the effectiveness of compliance programs. Their goal is to protect the organization from financial, legal, and reputational harm while supporting business objectives.

What are the key skills and qualifications needed to thrive as a GRC Risk Analyst, and why are they important?

To thrive as a GRC (Governance, Risk, and Compliance) Risk Analyst, you need a solid understanding of risk management principles, regulatory requirements, and compliance frameworks, often supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (such as RSA Archer or MetricStream), risk assessment methodologies, and certifications like CRISC or CISA is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and convey findings to stakeholders. These skills are critical for ensuring organizational compliance, minimizing risk exposure, and supporting informed decision-making.

What are some common challenges a GRC Risk Analyst might face when implementing new risk management frameworks within an organization?

A GRC Risk Analyst often encounters challenges such as resistance to change from stakeholders, integrating new frameworks with existing processes, and ensuring consistent understanding across departments. Aligning risk management practices with organizational goals while adhering to regulatory requirements can also be complex. Success in this role requires strong communication skills, adaptability, and the ability to educate and collaborate with team members from diverse backgrounds.
What job categories do people searching Grc Risk Analyst jobs in Utah look for? The top searched job categories for Grc Risk Analyst jobs in Utah are:
What cities in Utah are hiring for Grc Risk Analyst jobs? Cities in Utah with the most Grc Risk Analyst job openings:

Sr. Manager, IT Security Operations

swirecc

Draper, UT

Other

Posted 17 days ago


Job description

What does a Sr. Manager of IT Security Operations do at Swire Coca - Cola?
Swire Coca-Cola is seeking a Sr. Manager, IT Security - Operations to lead and mature the organization's security operations capabilities. This role is responsible for overseeing the detection, response, and remediation of cybersecurity threats while ensuring the stability and continuous improvement of core security services. The Sr. Manager will lead Security Operations, Incident Response, Vulnerability Management, Identity & Access Management and Monitoring functions, ensuring the organization can effectively identify and respond to evolving threats. This role partners closely with Security Architecture, GRC, IT Infrastructure, and business teams to ensure operational security controls are aligned with enterprise risk priorities. This position requires a strong leader with deep technical expertise, operational discipline, and the ability to translate complex security events into clear business impact for leadership. The ideal candidate will bring a balance of hands-on operational experience and strategic leadership to drive continuous improvement across the cybersecurity program.
Responsibilities

  • Lead and oversee Security Operations (SOC) activities, including monitoring, detection, and alert triage
  • Ensure effective operation of security tools such as SIEM, EDR, NDR, and related monitoring platforms
  • Continuously improve detection capabilities through tuning, use case development, and threat intelligence integration
  • Establish and maintain operational runbooks and standard operating procedures
  • Lead incident response activities, including investigation, containment, eradication, and recovery
  • Ensure incident response processes are well-defined, tested, and continuously improved
  • Oversee root cause analysis and post-incident reviews to strengthen controls
  • Coordinate with legal, communications, and leadership during high-impact incidents
  • Lead the vulnerability management program, including scanning, prioritization, and remediation tracking
  • Partner with IT and application teams to reduce exposure and improve patching effectiveness
  • Lead the design and continuous improvement of IAM capabilities, including identity lifecycle management (Joiner/Mover/Leaver), authentication, and authorization aligned with least privilege principles
  • Lead, mentor, and develop cybersecurity operations team members
  • Oversee the implementation, integration, and optimization of security technologies
  • Ensure security tools are configured, maintained, and delivering value
  • Partner with Security Architecture on tool selection and roadmap planning
  • Drive automation and efficiency within security operations workflows
  • Track and report on vulnerability trends and remediation metrics
  • Implement and manage access control models (RBAC/ABAC), MFA, conditional access, and privileged access management (PAM) to secure enterprise identities
  • Oversee identity governance processes, including access reviews, certifications, role design, and segregation of duties (SoD) controls
  • Partner with cross-functional teams to integrate IAM solutions, drive automation, and report on key metrics such as provisioning timelines, access risks, and compliance status
  • Develop and deliver operational metrics, dashboards, and reporting for leadership
  • Track KPIs such as detection time, response time, and remediation timelines
  • Provide clear, actionable reporting on threats, incidents, and operational risk posture
  • Drive continuous improvement initiatives across operational processes
  • Establish risk-based prioritization aligned to business impact and threat intelligence
  • Partner with GRC, Security Architecture, IT, and business stakeholders
  • Support cross-functional incident response coordination and tabletop exercises
  • Foster a culture of accountability, continuous learning, and operational excellence


Requirements

  • Bachelor’s Degree in Cybersecurity, Information Technology, Computer Science, or related field required
  • Certifications such as CISSP, CISM, or GIAC preferred
  • 8+ years of cybersecurity experience, focused on operations, incident response, or threat management required
  • 3+ years of leadership experience managing security teams or programs required
  • Strong experience with SIEM, EDR, vulnerability management, and detection tools required
  • Experience leading vulnerability management and remediation programs required
  • Experience developing metrics, dashboards, and executive reporting required
  • Deep understanding of incident response methodologies and frameworks
  • Strong analytical and problem-solving skills
  • Excellent communication skills translating technical issues into business impact

#LI-HH1