1

Grc Risk Analyst Jobs in Utah (NOW HIRING)

This role operates under the direction of GRC leadership and is responsible for day-to-day risk ... The ideal candidate is detail-oriented and analytical, with the ability to translate technical ...

As a security analyst at Lucid you will be helping to protect corporate assets, including our world ... party risk management, GRC, customer due diligence, etc. * Understanding of common security ...

As a security analyst at Lucid you will be helping to protect corporate assets, including our world ... party risk management, GRC, customer due diligence, etc. * Understanding of common security ...

Sr. Technology Compliance Product Owner

Lehi, UT · On-site

$118K - $156K/yr

... analysis. * Build trusted partnerships across Security, Engineering, Legal, Privacy, Product, HR ... What you need to succeed * 5-8+ years of experience in Governance, Risk & Compliance (GRC ...

... risk-based prioritization aligned to business impact and threat intelligence * Partner with GRC ... Strong analytical and problem-solving skills * Excellent communication skills translating technical ...

IT Security Operations Manager

Draper, UT · On-site

$120K - $150K/yr

The role partners closely with Security Architecture, Governance/Risk/Compliance (GRC), IT Infras ... Conduct root cause analysis and post-incident reviews to strengthen security controls * Coordinate ...

Senior IT Internal Auditor

South Jordan, UT · On-site

$80K - $100K/yr

Advanced computer skillsincludingspreadsheets, word processing, database, GRC applications, and ... COMPETENCIES Analytical mindset with strong attention to detail Professional skepticism and risk ...

Senior IT Internal Auditor

South Jordan, UT · On-site

$80K - $100K/yr

... GRC applications, and other applicable auditing or accounting software programs. • Exceptional ... • Analytical mindset with strong attention to detail • Professional skepticism and risk ...

Showing results 21-40

Grc Risk Analyst information

What is the difference between Grc Risk Analyst vs Compliance Analyst?

AspectGrc Risk AnalystCompliance Analyst
CertificationsISO 31000, FRM, CRISCISO 19600, CCEP, CISA
Work EnvironmentRisk management teams, corporate officesRegulatory departments, corporate offices
Industry UsageFinance, banking, insurance, corporate riskFinancial services, healthcare, manufacturing
Job FocusIdentifying, assessing, and mitigating risks across enterpriseEnsuring compliance with laws and regulations

While both roles involve regulatory and risk considerations, a Grc Risk Analyst focuses on enterprise-wide risk management strategies, whereas a Compliance Analyst concentrates on adherence to specific laws and regulations. Both roles require similar certifications and often work in overlapping industries, but their core responsibilities differ in scope and focus.

What is a GRC Risk Analyst?

GRC Risk Analysts are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization. They assess and manage risks related to business operations, ensure compliance with relevant laws and regulations, and help implement policies and controls to mitigate potential threats. These analysts work closely with management to identify vulnerabilities, develop risk management strategies, and monitor the effectiveness of compliance programs. Their goal is to protect the organization from financial, legal, and reputational harm while supporting business objectives.

What are the key skills and qualifications needed to thrive as a GRC Risk Analyst?

To thrive as a GRC (Governance, Risk, and Compliance) Risk Analyst, you need a solid understanding of risk management principles, regulatory requirements, and compliance frameworks, often supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (such as RSA Archer or MetricStream), risk assessment methodologies, and certifications like CRISC or CISA is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and convey findings to stakeholders. These skills are critical for ensuring organizational compliance, minimizing risk exposure, and supporting informed decision-making.

What are some common challenges a GRC Risk Analyst might face when implementing new risk management frameworks within an organization?

A GRC Risk Analyst often encounters challenges such as resistance to change from stakeholders, integrating new frameworks with existing processes, and ensuring consistent understanding across departments. Aligning risk management practices with organizational goals while adhering to regulatory requirements can also be complex. Success in this role requires strong communication skills, adaptability, and the ability to educate and collaborate with team members from diverse backgrounds.
What job categories do people searching Grc Risk Analyst jobs in Utah look for? The top searched job categories for Grc Risk Analyst jobs in Utah are:
What cities in Utah are hiring for Grc Risk Analyst jobs? Cities in Utah with the most Grc Risk Analyst job openings:

Cybersecurity Engineer

KēSTA I.T.

Draper, UT

$90K - $114K/yr

Full-time

Re-posted 20 days ago


Job description

Come build, innovate, disrupt, and thrive!


KēSTA I.T. is actively seeking a Cybersecurity Engineer for an immediate full-time opportunity with our industry leading client.


Are you on the lookout for a unique career opportunity that offers the chance to make a significant impact? If you're eager to contribute to a thriving and stable organization while maintaining your confidentiality, continue reading...


A Cybersecurity / GRC Engineer supports the execution and continuous improvement of an organization’s governance, risk, and compliance (GRC) program. This role operates under the direction of GRC leadership and is responsible for day-to-day risk, compliance, and audit activities to ensure cybersecurity practices align with regulatory, contractual, and business requirements.


This position plays a key role in operationalizing cybersecurity governance by conducting risk assessments, supporting audits, maintaining control frameworks, and partnering across IT and business teams to track and remediate findings. The ideal candidate is detail-oriented and analytical, with the ability to translate technical risks and controls into clear documentation and actionable insights.


Responsibilities

  • Conduct cybersecurity risk assessments for systems, applications, and business processes
  • Support third-party and vendor risk assessments, including due diligence reviews
  • Identify control gaps, document risks, and assist in developing remediation plans
  • Maintain and update the enterprise risk register, including risk scoring and tracking
  • Partner with control owners to validate mitigation efforts and assess risk status
  • Support internal and external audits by coordinating evidence collection and responses
  • Track audit findings and remediation activities, ensuring proper validation and closure
  • Assist with security questionnaires, RFP responses, and due diligence requests
  • Support compliance with regulatory and contractual requirements
  • Maintain and update cybersecurity policies, standards, and procedures
  • Map controls to industry frameworks such as NIST CSF, ISO 27001, and CIS
  • Support the development and maintenance of a unified control framework
  • Assist with control testing activities and documentation of effectiveness
  • Develop and maintain GRC metrics, dashboards, and reporting artifacts
  • Track key risk indicators (KRIs), audit trends, and remediation progress
  • Prepare reports and summaries for leadership and stakeholders
  • Maintain organized documentation and evidence repositories
  • Collaborate with cross-functional teams to drive risk awareness and remediation efforts
  • Support process improvements to enhance GRC efficiency and scalability
  • Assist in the implementation and optimization of GRC tools and automation
  • Stay current on evolving cybersecurity risks and compliance requirements
  • Perform additional related duties as needed


Requirements

  • Bachelor’s degree in Cybersecurity, Information Technology, Risk Management, or a related field
  • 3+ years of experience in cybersecurity, risk, compliance, or audit-related roles
  • Experience supporting audits, risk assessments, and compliance initiatives
  • Experience collaborating across IT and business teams
  • Working knowledge of cybersecurity frameworks such as NIST CSF, ISO 27001, and CIS


Preferred Qualifications:

  • Relevant certifications such as Security+, CISA, CRISC, or similar
  • Familiarity with GRC platforms (e.g., ServiceNow GRC, Archer, Drata, Vanta or similar tools)


Core Skills:

  • Strong analytical, documentation, and organizational capabilities
  • Ability to communicate technical concepts clearly to non-technical stakeholders
  • Attention to detail and ability to manage multiple priorities effectively



About KēSTA I.T.:


Our name says it all; KēSTA I.T. (Keys-to-I.T.) AND our people are our keys to our success!


KēSTA I.T. is a premier Utah-based technical staffing and consulting services firm. We specialize in temporary and permanent placement of Software, Hardware, Network, Cloud, CRM/ERP, Data, End-User support, Web and Executive / leadership-based positions on a full time and consulting basis. If you're interested in a role where top performance is rewarded, personal time is valued, and excellence is demanded at every level we want to talk to you today!


Where do you want to go? We've got the keys! ~ KēSTA I.T.


WWW.KeSTAIT.COM