Senior Security GRC Lead Austin | Chicago | New York City | Salt Lake City | San Francisco Gong harnesses the power of AI to transform how revenue teams win. The Gong Revenue AI Operating System ...
Senior Security GRC Lead Austin | Chicago | New York City | Salt Lake City | San Francisco Gong harnesses the power of AI to transform how revenue teams win. The Gong Revenue AI Operating System ...
We seek a GRC Strategy & Security Insights Lead to drive a data driven shift in our GRC program. This role is positioned where strategy, action, and communication meet. Translate security priorities ...
We seek a GRC Strategy & Security Insights Lead to drive a data driven shift in our GRC program. This role is positioned where strategy, action, and communication meet. Translate security priorities ...
The Information Security GRC Supervisor is responsible for educating, training, and transitioning ARUP Business Owners and System Owners to operate in compliance with NIST security standards and ARUP ...
The Information Security GRC Supervisor is responsible for educating, training, and transitioning ARUP Business Owners and System Owners to operate in compliance with NIST security standards and ARUP ...
The Information Security GRC Supervisor is responsible for educating, training, and transitioning ARUP Business Owners and System Owners to operate in compliance with NIST security standards and ARUP ...
The Information Security GRC Supervisor is responsible for educating, training, and transitioning ARUP Business Owners and System Owners to operate in compliance with NIST security standards and ARUP ...
The Information Security GRC Supervisor is responsible for educating, training, and transitioning ARUP Business Owners and System Owners to operate in compliance with NIST security standards and ARUP ...
The Information Security GRC Supervisor is responsible for educating, training, and transitioning ARUP Business Owners and System Owners to operate in compliance with NIST security standards and ARUP ...
Manager of Cybersecurity GRC
Salt Lake City, UT · On-site
$107K - $145K/yr
Kforce's client in Salt Lake City, UT is seeking an experienced Cybersecurity Governance, Risk & Compliance (GRC) Manager to lead enterprise cybersecurity risk management, compliance initiatives, and ...
Manager of Cybersecurity GRC
Salt Lake City, UT · On-site
$107K - $145K/yr
Kforce's client in Salt Lake City, UT is seeking an experienced Cybersecurity Governance, Risk & Compliance (GRC) Manager to lead enterprise cybersecurity risk management, compliance initiatives, and ...
GRC Security Manager
West Valley City, UT · On-site
$150K - $165K/yr
We are looking for an experienced GRC Security Manager to lead cybersecurity governance, risk, and compliance efforts for a health-focused organization in West Valley City, Utah. This position will ...
New
Quick apply
GRC Security Manager
West Valley City, UT · On-site
$150K - $165K/yr
We are looking for an experienced GRC Security Manager to lead cybersecurity governance, risk, and compliance efforts for a health-focused organization in West Valley City, Utah. This position will ...
New
Cybersecurity Engineer
Draper, UT · On-site
$90K - $114K/yr
A Cybersecurity / GRC Engineer supports the execution and continuous improvement of an organization's governance, risk, and compliance (GRC) program. This role operates under the direction of GRC ...
Quick apply
Cybersecurity Engineer
Draper, UT · On-site
$90K - $114K/yr
A Cybersecurity / GRC Engineer supports the execution and continuous improvement of an organization's governance, risk, and compliance (GRC) program. This role operates under the direction of GRC ...
Track risks in the risk register using a GRC tool and publish dashboards with the risk health of organizational functions * Facilitate Risk Committee Meetings, establishing the agenda, and ...
Track risks in the risk register using a GRC tool and publish dashboards with the risk health of organizational functions * Facilitate Risk Committee Meetings, establishing the agenda, and ...
Sr. Technology Compliance Product Owner
$118K - $156K/yr
Serve as the primary Tech GRC lead for internal readiness assessments, regulatory audits, certifications, and external assurance engagements. * Coordinate audit planning, evidence collection ...
Sr. Technology Compliance Product Owner
$118K - $156K/yr
Serve as the primary Tech GRC lead for internal readiness assessments, regulatory audits, certifications, and external assurance engagements. * Coordinate audit planning, evidence collection ...
The role partners closely with Compliance, Technology, GRC, Internal Audit, Operational Risk, and business stakeholders to improve compliance risk transparency, strengthen governance reporting ...
The role partners closely with Compliance, Technology, GRC, Internal Audit, Operational Risk, and business stakeholders to improve compliance risk transparency, strengthen governance reporting ...
Experience working with enterprise GRC processes (risk assessments, control design, issue management). Preferred Qualifications * Master's Degree in Information Technology, Cybersecurity, Data ...
Experience working with enterprise GRC processes (risk assessments, control design, issue management). Preferred Qualifications * Master's Degree in Information Technology, Cybersecurity, Data ...
Enterprise Risk Manager
Lehi, UT · On-site
Track risks in the risk register using a GRC tool and publish dashboards with the risk health of organizational functions * Facilitate Risk Committee Meetings, establishing the agenda, and ...
Enterprise Risk Manager
Lehi, UT · On-site
Track risks in the risk register using a GRC tool and publish dashboards with the risk health of organizational functions * Facilitate Risk Committee Meetings, establishing the agenda, and ...
Develop and execute MX's enterprise Governance, Risk & Compliance (GRC) strategy. * Build, mature, and continuously improve security, privacy, and risk management programs that align with business ...
Develop and execute MX's enterprise Governance, Risk & Compliance (GRC) strategy. * Build, mature, and continuously improve security, privacy, and risk management programs that align with business ...
This role will report directly into the Head of GRC and operate both strategically and very hands-on. Responsibilities * Own the end-to-end third-party risk lifecycle: intake, due diligence, risk ...
This role will report directly into the Head of GRC and operate both strategically and very hands-on. Responsibilities * Own the end-to-end third-party risk lifecycle: intake, due diligence, risk ...
Security Analyst III
Salt Lake City, UT · On-site
You will focus on the execution of day-to-day GRC (Governance, Risk, and Compliance) operations, third-party risk assessments, and championing customer trust. Lucid Software's security team fosters ...
Security Analyst III
Salt Lake City, UT · On-site
You will focus on the execution of day-to-day GRC (Governance, Risk, and Compliance) operations, third-party risk assessments, and championing customer trust. Lucid Software's security team fosters ...
Security Analyst III
Salt Lake City, UT · On-site +1
You will focus on the execution of day-to-day GRC (Governance, Risk, and Compliance) operations, third-party risk assessments, and championing customer trust. Lucid Software's security team fosters ...
Security Analyst III
Salt Lake City, UT · On-site +1
You will focus on the execution of day-to-day GRC (Governance, Risk, and Compliance) operations, third-party risk assessments, and championing customer trust. Lucid Software's security team fosters ...
Develop and execute MX's enterprise Governance, Risk & Compliance (GRC) strategy. * Build, mature, and continuously improve security, privacy, and risk management programs that align with business ...
Develop and execute MX's enterprise Governance, Risk & Compliance (GRC) strategy. * Build, mature, and continuously improve security, privacy, and risk management programs that align with business ...
Cybersecurity Analyst
Midvale, UT · Hybrid
We are seeking a Cybersecurity Analyst to join Zions Bancorporation's Enterprise Information Security (EIS) Governance, Risk and Compliance (GRC) team. The Cybersecurity Analyst will support the ...
Cybersecurity Analyst
Midvale, UT · Hybrid
We are seeking a Cybersecurity Analyst to join Zions Bancorporation's Enterprise Information Security (EIS) Governance, Risk and Compliance (GRC) team. The Cybersecurity Analyst will support the ...
You own SOC 2 Type II and ISO 27001 certification programs end-to-end, operate SIEM and EDR tooling, and maintain the GRC framework that keeps the company audit-ready at all times. You are the ...
You own SOC 2 Type II and ISO 27001 certification programs end-to-end, operate SIEM and EDR tooling, and maintain the GRC framework that keeps the company audit-ready at all times. You are the ...
Grc information
See Utah salary details
$43.99 - $46.69
9% of jobs
$46.69 - $49.40
0% of jobs
$49.40 - $52.10
0% of jobs
$52.10 - $54.81
5% of jobs
$54.81 - $57.51
5% of jobs
$57.51 - $60.22
0% of jobs
$61.01 is the 25th percentile. Wages below this are outliers.
$60.22 - $62.93
19% of jobs
The median wage is $64.28 / hr.
$62.93 - $65.63
24% of jobs
$65.63 - $68.34
10% of jobs
$68.96 is the 75th percentile. Wages above this are outliers.
$68.34 - $71.04
12% of jobs
$71.04 - $73.75
15% of jobs
$43
$63
$73
How much do grc jobs pay per hour?
Are GRC jobs hard to get?
Is GRC a good career?
What is a GRC?
A GRC (Governance, Risk, and Compliance) job involves managing an organization's policies, regulations, and risk management frameworks to ensure compliance with legal and industry standards. Professionals in this role assess risks, implement controls, and develop strategies to mitigate potential threats while aligning business operations with regulatory requirements. They often work with stakeholders across IT, security, and legal departments to maintain compliance and improve risk management processes.
What are the key skills and qualifications needed for a GRC role?
To thrive in a GRC (Governance, Risk, and Compliance) role, you need a solid understanding of regulatory frameworks, risk assessment methodologies, and compliance standards, often supported by a degree in business, information technology, or a related field. Familiarity with GRC software platforms (such as RSA Archer, LogicGate, or MetricStream), and professional certifications like CRISC, CISA, or CISSP, are highly valued. Strong analytical thinking, attention to detail, and clear communication skills are important for interpreting regulations and working with cross-functional teams. These skills ensure that organizations manage risks effectively, meet regulatory requirements, and maintain enterprise-wide compliance.
What are the daily responsibilities of a GRC professional?
In a GRC position, your day-to-day tasks often include conducting risk assessments, monitoring compliance with internal policies and external regulations, and collaborating with various departments to implement controls or corrective actions. You may also manage and update policies, prepare reports for management, and respond to regulatory audits or inquiries. Additionally, GRC professionals facilitate training sessions to improve organizational awareness of risks and ensure ongoing adherence to compliance standards. The role is dynamic and involves proactive problem-solving to help keep the organization secure and compliant.
Is GRC still in demand?
What are GRC jobs?

Other
Medical, Dental, Vision, Retirement, PTO
Posted 25 days ago
Job description
Austin | Chicago | New York City | Salt Lake City | San Francisco
Gong harnesses the power of AI to transform how revenue teams win. The Gong Revenue AI Operating System unifies data, insights, and workflows into a single, trusted system that observes, guides, and acts alongside the world's most successful revenue teams. Powered by the Gong Revenue Graph, AI-powered intelligence, specialized agents, and trusted applications, Gong helps more than 5,000 companies around the world deeply understand their teams and customers, automate critical sales workflows, and close more deals with less effort. For more information, visit gong.io.
At Gong, you will join a company built on innovative products, ambitious goals, and passionate people. We are shaping the future of revenue intelligence and we want people who are excited to build what comes next. You will work with a team that dreams big, moves fast, and cares deeply about the craft and about each other. Here, transparency and trust are core to how we operate, and every person has the opportunity to make a visible impact. If you want to grow, stretch, and do work that truly matters, Gong is the place to do the best work of your career.
This is a high-visibility, high-impact role at the center of Gong's security and compliance story. As our Senior GRC Security Lead, you will be the architect of foundational programs we are building — Gong's first-ever Common Controls Framework, standing up a formal risk process and register, implementing a GRC tooling ecosystem, and owning the full policy, standards, and exceptions management lifecycle.
This is not a role for someone looking to inherit a mature program. It's a role for a builder — someone who thrives in ambiguity, operates with urgency, and finds energy in creating order from complexity. You will work directly with Legal, Sales, Engineering, Customer Audit teams, and executive stakeholders, and your fingerprints will be visible across everything Gong builds for compliance and trust for years to come.
Responsibilities- Design and implement Gong's Common Controls Framework, mapping controls across SOC 2, ISO 27001, 27017, 27701, 27018, HIPAA, PCI, and other applicable frameworks.
- Rationalize overlapping requirements across frameworks to reduce compliance burden and create a single source of truth for control ownership.
- Partner with Engineering, Infrastructure, and Product Security to embed controls at the architecture level, not just as audit checkboxes.
- Establish control testing methodology, evidence collection standards, and continuous control monitoring processes.
- Serve as the subject-matter expert on control mapping during customer and external audits, RFPs, and enterprise sales engagements.
- Build Gong's product & enterprise risk register from the ground up — defining risk taxonomy, scoring methodology, risk appetite thresholds, and ownership models.
- Implementation of a GRC platform and system of record, and ability to build executive level dashboards to track vulnerability, risk, and control remediation.
- Create and maintain risk treatment plans in partnership with risk owners across the business, tracking remediation milestones and escalating blockers.
- Develop executive-level risk reporting cadences and dashboards for the Head of GRC and senior leadership.
- Own the complete lifecycle of Gong's information security policy suite — creation, review cycles, version control, and employee acknowledgment tracking.
- Establish and operate a formal exceptions management program, including intake, risk assessment, approval workflows, compensating controls, and periodic review.
- Ensure policies remain aligned with evolving regulatory requirements, industry frameworks, and Gong's rapidly changing technology environment.
- Drive policy adoption through clear communication, training support, and cross-functional partnership.
- Liaise with external auditors and certification bodies for SOC 2, ISO, and other certifications
- 7+ years of progressive experience in GRC, Information Security, or a closely related function — with meaningful time spent building or scaling programs, not just running them.
- Demonstrated hands-on experience building a GRC program at scale — ideally in a high-growth SaaS or technology company.
- Deep expertise across multiple compliance and security frameworks, including SOC 2 Type II, ISO 27001, NIST CSF, and at least one regulatory framework (GDPR, CCPA, HIPAA, or equivalent).
- Experience creating and implementing GRC Record of Truth/Tooling.
- Strong policy and standards writing ability — capable of translating complex regulatory language into clear, actionable documentation.
- Experience conducting and managing product & enterprise risk assessments, with a working knowledge of risk quantification methodologies.
- Proven ability to manage and communicate with senior stakeholders, including Legal, Engineering, and executive audiences.
- Bachelor's degree in Information Security, Computer Science, Business, or a related field; equivalent practical experience considered.
- Relevant certifications strongly preferred: CISSP, CISM, CRISC, CISA, CCSP, or comparable credentials.
- We offer Gongsters a variety of medical, dental, and vision plans, designed to fit you and your family's needs.
- Wellbeing Fund - flexible wellness stipend to support a healthy lifestyle.
- Mental Health benefits with covered therapy and coaching.
- 401(k) program to help you invest in your future.
- Education & learning stipend for personal growth and development.
- Flexible vacation time to promote a healthy work-life blend.
- Paid parental leave to support you and your family.
- Company-wide recharge days each quarter.
- Work from home stipend to help you succeed in a remote environment.
The annual salary hiring range for this position is $121,000 - $185,000 USD. Compensation is based on factors unique to each candidate, including, but not limited to, job-related skills, qualification, education, experience, and location. At Gong, we have a location-based compensation structure, which means there may be a different range for candidates in other locations. The total compensation package for this position, in addition to base compensation, may include incentive compensation, bonus, equity, and benefits. Some of our sales compensation programs also offer the potential to achieve above targeted earnings for those who exceed their sales targets.
We are always looking for outstanding Gongsters! So if this sounds like something that interests you regardless of compensation, please reach out. We may have more roles for you to consider and would love to connect.
We have noticed a rise in recruiting impersonations across the industry, where scammers attempt to access candidates' personal and financial information through fake interviews and offers. All Gong recruiting email communications will always come from the @gong.io domain. Any outreach claiming to be from Gong via other sources should be ignored.
Gong is an equal-opportunity employer. We believe that diversity is integral to our success, and do not discriminate based on race, color, religion, age, sex, sexual orientation, gender identity, national origin, disability, military status, genetic information, or any other basis protected by applicable law.
To review Gong's privacy policy, visit gong.io/gong-io-job-candidates-privacy-notice/ for more details.