You will build the foundation for data governance, risk acceptance and exceptions processes, and a ... Own and execute Neumo's GRC strategy and roadmap, in partnership with the CISO. * Manage, mentor ...
You will build the foundation for data governance, risk acceptance and exceptions processes, and a ... Own and execute Neumo's GRC strategy and roadmap, in partnership with the CISO. * Manage, mentor ...
RainFocus, one of the most innovative software companies, is in search of an exceptional Senior Governance, Risk, and Compliance (GRC) Analyst . About RainFocus RainFocus cares about its employees ...
RainFocus, one of the most innovative software companies, is in search of an exceptional Senior Governance, Risk, and Compliance (GRC) Analyst . About RainFocus RainFocus cares about its employees ...
RainFocus, one of the most innovative software companies, is in search of an exceptional Senior Governance, Risk, and Compliance (GRC) Analyst . About RainFocus RainFocus cares about its employees ...
RainFocus, one of the most innovative software companies, is in search of an exceptional Senior Governance, Risk, and Compliance (GRC) Analyst . About RainFocus RainFocus cares about its employees ...
Senior Governance, Risk, and Compliance (GRC) Analyst (Remote)
Orem, UT · On-site
$110 - $140/hr
RainFocus, one of the most innovative software companies, is in search of an exceptional Senior Governance, Risk, and Compliance (GRC) Analyst. About RainFocus RainFocus cares about its employees ...
Senior Governance, Risk, and Compliance (GRC) Analyst (Remote)
Orem, UT · On-site
$110 - $140/hr
RainFocus, one of the most innovative software companies, is in search of an exceptional Senior Governance, Risk, and Compliance (GRC) Analyst. About RainFocus RainFocus cares about its employees ...
Enterprise Risk Manager
Lehi, UT · On-site
Track risks in the risk register using a GRC tool and publish dashboards with the risk health of organizational functions * Facilitate Risk Committee Meetings, establishing the agenda, and ...
Enterprise Risk Manager
Lehi, UT · On-site
Track risks in the risk register using a GRC tool and publish dashboards with the risk health of organizational functions * Facilitate Risk Committee Meetings, establishing the agenda, and ...
Enterprise Risk Manager
Lehi, UT · On-site
Track risks in the risk register using a GRC tool and publish dashboards with the risk health of organizational functions * Facilitate Risk Committee Meetings, establishing the agenda, and ...
Enterprise Risk Manager
Lehi, UT · On-site
Track risks in the risk register using a GRC tool and publish dashboards with the risk health of organizational functions * Facilitate Risk Committee Meetings, establishing the agenda, and ...
Senior Governance Risk and Compliance Analyst
Orem, UT · On-site
$120 - $160/hr
Lead RainFocus's GRC program across SOC 2, ISO 27001, PCI DSS, and other client/regulatory ... Own the annual security risk assessment process (NIST SP 800-30 methodology), including stakeholder ...
Senior Governance Risk and Compliance Analyst
Orem, UT · On-site
$120 - $160/hr
Lead RainFocus's GRC program across SOC 2, ISO 27001, PCI DSS, and other client/regulatory ... Own the annual security risk assessment process (NIST SP 800-30 methodology), including stakeholder ...
GRC Program Manager
Draper, UT · On-site
$120K - $146K/yr
Manage third-party/vendor risk management. * Own our GRC tooling and automation, and drive ... continuous compliance rather than point-in-time scrambles. * Lead AI enablement of the compliance ...
Quick apply
GRC Program Manager
Draper, UT · On-site
$120K - $146K/yr
Manage third-party/vendor risk management. * Own our GRC tooling and automation, and drive ... continuous compliance rather than point-in-time scrambles. * Lead AI enablement of the compliance ...
Develop and execute MX's enterprise Governance, Risk & Compliance (GRC) strategy. * Build, mature, and continuously improve security, privacy, and risk management programs that align with business ...
Develop and execute MX's enterprise Governance, Risk & Compliance (GRC) strategy. * Build, mature, and continuously improve security, privacy, and risk management programs that align with business ...
GRC Strategy and Insights Lead
Lehi, UT · On-site
The Opportunity Adobe's Technology Governance, Risk & Compliance Organization plays a meaningful ... We seek a GRC Strategy & Security Insights Lead to drive a data driven shift in our GRC program.
GRC Strategy and Insights Lead
Lehi, UT · On-site
The Opportunity Adobe's Technology Governance, Risk & Compliance Organization plays a meaningful ... We seek a GRC Strategy & Security Insights Lead to drive a data driven shift in our GRC program.
Manager of Cybersecurity GRC
Salt Lake City, UT · On-site
$107K - $145K/yr
... GRC) Manager to lead enterprise cybersecurity risk management, compliance initiatives, and ... Conduct ongoing risk assessments to identify threats, vulnerabilities, and emerging cybersecurity ...
Manager of Cybersecurity GRC
Salt Lake City, UT · On-site
$107K - $145K/yr
... GRC) Manager to lead enterprise cybersecurity risk management, compliance initiatives, and ... Conduct ongoing risk assessments to identify threats, vulnerabilities, and emerging cybersecurity ...
GRC Security Manager
West Valley City, UT · On-site
We are looking for an experienced GRC Security Manager to lead cybersecurity governance, risk, and compliance efforts for a health-focused organization in West Valley City, Utah. This position will ...
Quick apply
GRC Security Manager
West Valley City, UT · On-site
We are looking for an experienced GRC Security Manager to lead cybersecurity governance, risk, and compliance efforts for a health-focused organization in West Valley City, Utah. This position will ...
Rapidly analyze complex supply chain and risk data (including GRC/Archer data integrity), translating results into clearly written reports and memos. Ensure accuracy, appropriate tone, and clarity ...
Rapidly analyze complex supply chain and risk data (including GRC/Archer data integrity), translating results into clearly written reports and memos. Ensure accuracy, appropriate tone, and clarity ...
Rapidly analyze complex supply chain and risk data (including GRC/Archer data integrity), translating results into clearly written reports and memos. Ensure accuracy, appropriate tone, and clarity ...
Rapidly analyze complex supply chain and risk data (including GRC/Archer data integrity), translating results into clearly written reports and memos. Ensure accuracy, appropriate tone, and clarity ...
Rapidly analyze complex supply chain and risk data (including GRC/Archer data integrity), translating results into clearly written reports and memos. Ensure accuracy, appropriate tone, and clarity ...
Rapidly analyze complex supply chain and risk data (including GRC/Archer data integrity), translating results into clearly written reports and memos. Ensure accuracy, appropriate tone, and clarity ...
Rapidly analyze complex supply chain and risk data (including GRC/Archer data integrity), translating results into clearly written reports and memos. Ensure accuracy, appropriate tone, and clarity ...
Rapidly analyze complex supply chain and risk data (including GRC/Archer data integrity), translating results into clearly written reports and memos. Ensure accuracy, appropriate tone, and clarity ...
Develop and execute MX's enterprise Governance, Risk & Compliance (GRC) strategy. * Build, mature, and continuously improve security, privacy, and risk management programs that align with business ...
Develop and execute MX's enterprise Governance, Risk & Compliance (GRC) strategy. * Build, mature, and continuously improve security, privacy, and risk management programs that align with business ...
The Risk Analyst plays an important role in supporting the Company's Enterprise Risk Management ... Working knowledge of Excel, Microsoft Powerpoint, MicroSoft PowerBI and knowledge IRM/GRC systems ...
The Risk Analyst plays an important role in supporting the Company's Enterprise Risk Management ... Working knowledge of Excel, Microsoft Powerpoint, MicroSoft PowerBI and knowledge IRM/GRC systems ...
IT Risk Analyst II
Salt Lake City, UT · On-site
$108K - $162K/yr
Technical 407 Pay Range: $108,200.00 - $162,400.00 The IT Risk Analyst II is a member of WGU ... Experience with TPRM platforms or GRC tooling. * Higher education experience. Location 5 days ...
IT Risk Analyst II
Salt Lake City, UT · On-site
$108K - $162K/yr
Technical 407 Pay Range: $108,200.00 - $162,400.00 The IT Risk Analyst II is a member of WGU ... Experience with TPRM platforms or GRC tooling. * Higher education experience. Location 5 days ...
IT Risk Analyst II
Salt Lake City, UT · On-site
$108K - $162K/yr
Technical 407 Pay Range: $108,200.00 - $162,400.00 The IT Risk Analyst II is a member of WGU ... Experience with TPRM platforms or GRC tooling. * Higher education experience. Location 5 days ...
IT Risk Analyst II
Salt Lake City, UT · On-site
$108K - $162K/yr
Technical 407 Pay Range: $108,200.00 - $162,400.00 The IT Risk Analyst II is a member of WGU ... Experience with TPRM platforms or GRC tooling. * Higher education experience. Location 5 days ...
Grc Risk information
What is the difference between Grc Risk vs Grc Analyst?
| Aspect | Grc Risk | Grc Analyst |
|---|---|---|
| Certifications | ISO 31000, CRISC, COSO | CISA, CRISC, CISSP |
| Work Environment | Risk management teams, compliance departments | IT, audit, compliance teams |
| Industry Usage | Financial, healthcare, corporate sectors | IT, finance, consulting firms |
| Primary Focus | Identifying and managing enterprise risks | Analyzing controls, assessing risks in systems |
Grc Risk professionals focus on enterprise-wide risk management strategies, while Grc Analysts typically analyze specific controls and systems to identify vulnerabilities. Both roles require similar certifications and often work within the same industries, but Grc Risk has a broader scope in risk oversight, whereas Grc Analysts concentrate on detailed control assessments.
What are popular job titles related to Grc Risk jobs in Utah?
For Grc Risk jobs in Utah, the most frequently searched job titles are:
What job categories do people searching Grc Risk jobs in Utah look for?
The top searched job categories for Grc Risk jobs in Utah are:
What cities in Utah are hiring for Grc Risk jobs?
Cities in Utah with the most Grc Risk job openings:

Manager, Information Security (GRC) (Remote)
West Jordan, UT • On-site
Full-time
Posted 9 days ago
Job description
Job Summary:
We are seeking a Manager, Information Security (GRC) to own and mature Neumo's Governance, Risk, and Compliance program. This role is critical to maintaining our SOC 1, SOC 2, and PCI certifications and to raising our overall information security maturity. You will build the foundation for data governance, risk acceptance and exceptions processes, and a recurring cadence of monthly, quarterly, and annual risk mitigation. This is a hands-on leadership role: you will manage 1–2 direct reports while personally driving audits, risk assessments, and control automation, and participate in incident management alongside the broader security team.
You will be the connective tissue between security engineering, legal, engineering, and executive leadership: translating regulatory and contractual requirements into practical controls, and translating control performance into risk language leadership can act on.
This role directly protects Neumo's ability to do business: Our certifications are foundational to customer trust and revenue. You will have the mandate to modernize how we manage risk and compliance, including building automation and AI-driven workflows that scale the program without scaling headcount linearly.
Duties and Responsibilities:
Leadership & Program Ownership
- Own and execute Neumo's GRC strategy and roadmap, in partnership with the CISO.
- Manage, mentor, and grow 1–2 direct reports supporting compliance, risk, and audit activities.
- Set the foundation for data governance: data classification, ownership, retention, and handling standards.
- Build and maintain the risk register; lead monthly, quarterly, and annual risk mitigation cycles.
- Own the risk acceptance and policy exception process, including documentation, approval workflows, and periodic review.
- Report on compliance posture, audit status, and risk trends to executive stakeholders and the board as needed.
Compliance & Audit Management
- Own end-to-end readiness and execution for SOC 1, SOC 2, and PCI DSS audits, including evidence collection, auditor coordination, and remediation tracking.
- Maintain and continuously improve the internal control framework mapped to SOC 1/2, PCI, and other applicable frameworks (e.g., ISO 27001, NIST CSF).
- Track control ownership, testing cadence, and control health across the organization using the GRC platform and Jira.
- Partner with engineering and IT teams to close control gaps and drive remediation of audit findings within SLA.
Risk, Automation & Cross-Functional Work
- Design and implement control automation to reduce manual evidence collection and continuous control monitoring (CCM).
- Leverage AI/LLM tooling to accelerate evidence review, policy drafting, control testing, and risk analysis, with appropriate human oversight.
- Participate in incident management as the GRC/risk representative: assessing regulatory and contractual impact and ensuring proper documentation.
- Manage third-party/vendor risk assessments and questionnaires (customer security questionnaires, vendor due diligence).
- Partner with Legal and Privacy on data protection, regulatory, and contractual compliance requirements.
Education and Experience:
- 6+ years of experience in GRC, information security compliance, or IT audit, including experience managing or mentoring others.
- Direct experience owning SOC 1, SOC 2, and PCI DSS compliance programs end-to-end, including audit management.
- Hands-on experience with GRC platforms (e.g., Vanta, Drata, ServiceNow GRC, OneTrust, Archer, or similar).
- Experience building risk management programs: risk registers, risk acceptance/exception processes, and recurring risk mitigation cadences.
- Foundational experience with data governance concepts (classification, ownership, retention).
- Relevant certifications (e.g., CISA, CRISC, CISSP, CISM) are a plus but not required.
Knowledge, Skills and Abilities:
- Strong working knowledge of Jira for control tracking, remediation workflows, and cross-team coordination.
- Demonstrated ability to build or deploy control automation and continuous control monitoring.
- Comfort leveraging AI tools to scale GRC operations (evidence review, policy generation, risk analysis).
- Ability to participate effectively in incident management, translating technical incidents into risk and compliance impact.
- Excellent written and verbal communication skills; able to translate technical and regulatory detail for executive audiences.
Work Environment:
- Office setting with a moderate noise level.
- The employee will work at an individual workstation, using a telephone and computer.
- Periodic flexibility outside standard business hours may be required to support audits or incident response.
Physical Demands:
- Must be able to remain seated for extended periods.
- Regular use of a computer and other office machinery, such as printers and copy machines.
- Occasional movement around the office.
- Frequent communication via telephone.
Neumo Summary:
With the backing of four decades of public sector expertise and corporate capability, Neumo has successfully supported government services. Neumo was honored and recognized for four (4) consecutive years as a GovTech 100 Company representing the top 100 companies focused on making a difference in and selling to state and local government agencies across the United States.
Neumo is committed to helping communities thrive and brings a wealth of experience combined with innovation. Today, Neumo offers more administrative and financial support to government officials than any other organization. And with a responsive, client-focused approach, we foster partnerships that give our customers the certainty they need to accomplish more.
Neumo offers a competitive benefits and compensation package and are looking for team members who will thrive in our dynamic environment.
Neumo is an Equal Opportunity Employer. Selection for a position will be made without regard to race, religion, national origin, sex, political affiliation, marital status, non-disqualifying physical handicap, and age.