1

Grc Jobs in Utah (NOW HIRING)

GRC Program Manager

Draper, UT · On-site

$120K - $146K/yr

Redo is growing fast, which makes this a rare blue-ocean opportunity to own GRC end to end. This isn't a box-checking role -- it's a chance to drive real impact and influence across the organization.

We seek a GRC Strategy & Security Insights Lead to drive a data driven shift in our GRC program. This role is positioned where strategy, action, and communication meet. Translate security priorities ...

We are looking for an experienced GRC Security Manager to lead cybersecurity governance, risk, and compliance efforts for a health-focused organization in West Valley City, Utah. This position will ...

Serve as the primary Tech GRC lead for internal readiness assessments, regulatory audits, certifications, and external assurance engagements. * Coordinate audit planning, evidence collection ...

You will focus on the execution of day-to-day GRC (Governance, Risk, and Compliance) operations, third-party risk assessments, and championing customer trust. Lucid Software's security team fosters ...

You will focus on the execution of day-to-day GRC (Governance, Risk, and Compliance) operations, third-party risk assessments, and championing customer trust. Lucid Software's security team fosters ...

next page

Showing results 1-20

Grc information

See Utah salary details

$43

$63

$73

How much do grc jobs pay per hour?

As of Sep 2, 2026, the average hourly pay for grc in Utah is $63.70, according to ZipRecruiter salary data. Most workers in this role earn between $61.30 and $70.05 per hour, depending on experience, location, and employer.

What is a GRC?

A GRC (Governance, Risk, and Compliance) job involves managing an organization's policies, regulations, and risk management frameworks to ensure compliance with legal and industry standards. Professionals in this role assess risks, implement controls, and develop strategies to mitigate potential threats while aligning business operations with regulatory requirements. They often work with stakeholders across IT, security, and legal departments to maintain compliance and improve risk management processes.

What are the daily responsibilities of a GRC professional?

In a GRC position, your day-to-day tasks often include conducting risk assessments, monitoring compliance with internal policies and external regulations, and collaborating with various departments to implement controls or corrective actions. You may also manage and update policies, prepare reports for management, and respond to regulatory audits or inquiries. Additionally, GRC professionals facilitate training sessions to improve organizational awareness of risks and ensure ongoing adherence to compliance standards. The role is dynamic and involves proactive problem-solving to help keep the organization secure and compliant.

What are the key skills and qualifications needed for a GRC role?

To thrive in a GRC (Governance, Risk, and Compliance) role, you need a solid understanding of regulatory frameworks, risk assessment methodologies, and compliance standards, often supported by a degree in business, information technology, or a related field. Familiarity with GRC software platforms (such as RSA Archer, LogicGate, or MetricStream), and professional certifications like CRISC, CISA, or CISSP, are highly valued. Strong analytical thinking, attention to detail, and clear communication skills are important for interpreting regulations and working with cross-functional teams. These skills ensure that organizations manage risks effectively, meet regulatory requirements, and maintain enterprise-wide compliance.

Are GRC jobs hard to get?

GRC (Governance, Risk, and Compliance) jobs can be competitive, especially for entry-level positions, but having relevant certifications like CISA or CISSP and experience with compliance frameworks can improve your chances. The difficulty of securing a GRC role depends on your skills, education, and the current job market demand for compliance professionals.

Is GRC a good career?

GRC (Governance, Risk, and Compliance) is a growing field within cybersecurity and corporate management, focusing on ensuring organizations meet regulatory requirements and manage risks effectively. It often requires knowledge of compliance standards, risk assessment, and security frameworks, with certifications like CISA or CISSP enhancing job prospects. The career offers opportunities in various industries, with roles typically involving analysis, policy development, and audits.

Is GRC still in demand?

GRC (Governance, Risk, and Compliance) roles remain in demand as organizations prioritize cybersecurity, regulatory adherence, and risk management. Professionals with skills in compliance frameworks, audit, and security tools are sought after across various industries, especially in regulated sectors like finance and healthcare.

What are GRC jobs?

GRC jobs refer to roles focused on Governance, Risk Management, and Compliance within organizations. These positions involve developing policies, assessing risks, ensuring regulatory adherence, and often require knowledge of frameworks like ISO, COBIT, or NIST, as well as certifications such as CISA or CISSP.

What are the most commonly searched types of Grc jobs in Utah?

The most popular types of Grc jobs in Utah are:

What are popular job titles related to Grc jobs in Utah?

For Grc jobs in Utah, the most frequently searched job titles are:

What cities in Utah are hiring for Grc jobs?

Cities in Utah with the most Grc job openings:

Infographic showing various Grc job openings in Utah as of August 2026, with employment types broken down into 96% Full Time, and 4% Contract. Highlights an 74% In-person, 4% Hybrid, and 22% Remote job distribution, with an average salary of $132,496 per year, or $63.7 per hour.

GRC Program Manager

Redo

Draper, UT • On-site

$120K - $146K/yr

Full-time

PTO

Posted 18 days ago


Job description

About Redo
Redo is an e-commerce growth platform. We help merchants personalize every step of the buyer journey to maximize profit and lifetime value, with solutions spanning returns, warranties, order tracking, and post-purchase communications. We're growing fast, moving quickly, and building the systems that let some of the best brands in commerce trust us with their customers.
About the Role
Security and compliance are core to how Redo operates and how our merchants trust us with their customers. We're growing explosively, and as we scale, we're investing in a dedicated owner to take our governance, risk, and compliance program to the next level — and that's where you come in.
Redo is growing fast, which makes this a rare blue-ocean opportunity to own GRC end to end. This isn't a box-checking role — it's a chance to drive real impact and influence across the organization. You'll deepen and expand our compliance across SOC 2, GDPR, CCPA, and the frameworks that come next, setting the strategy, owning the execution, and shaping how security is built into the company as we grow. You'll also work directly with our merchants, where a strong security story helps close deals.
You'll partner shoulder-to-shoulder with engineering to turn compliance requirements into concrete controls, keep us audit-ready as we scale, and be the person our merchants trust when they run a security review. We're looking for a seasoned practitioner who can operate independently and be the go-to expert on all things GRC.
If you want ownership, visible impact, and the chance to shape a maturing security program at a fast-growing company, this is it.
What You'll Do

  • Own, mature, and scale Redo's GRC program end to end — SOC 2, GDPR, CCPA, PCI, and HIPAA and additional frameworks as our merchant base demands them.

  • Partner closely with engineering to translate framework and control requirements into clear, actionable technical and engineering requirements — and make sure they get implemented and stay implemented.

  • Own audit readiness: lead audits and assessments, manage auditor relationships, and run evidence collection and continuous control monitoring.

  • Lead compliance sales enablement by responding to merchant and prospect security reviews — questionnaires, due-diligence requests, and trust/security documentation — and turn it into a low friction process that smooths sales deals.

  • Build and maintain security policies, standards, and procedures, and drive their adoption across the company.

  • Manage third-party/vendor risk management.

  • Own our GRC tooling and automation, and drive continuous compliance rather than point-in-time scrambles.

  • Lead AI enablement of the compliance program — put AI to work automating evidence collection, control monitoring, security-questionnaire responses, and documentation so the program scales faster than headcount.

  • Manage access reviews, security awareness training, and evidence of ongoing operating effectiveness.

  • Keep leadership informed on compliance posture, gaps, and progress, and represent Redo's security program to customers and partners.

What We're Looking For

  • 5+ years in GRC, security compliance, or a closely related role, with hands-on ownership (not just support) of at least one full compliance program.

  • Demonstrated experience taking a company through a full SOC 2 certification and continued surveillance.

  • Depth of experience helping SaaS platforms support GDPR and data privacy obligations.

  • Experience navigating HIPAA and PCI environments.

  • A self-directed operator who can own and mature a program with minimal oversight — you know what "good" looks like and can drive it independently.

  • Ability to translate control requirements into engineering requirements and to collaborate credibly with software engineers.

  • Experience responding to customer security reviews and security questionnaires.

  • Strong writing and communication skills — you can produce clear policies and explain security posture to both engineers and non-technical stakeholders.

  • Comfortable in a fast-moving, high-growth environment where you set the pace.

  • Experience using AI for custom compliance automation

Nice to Have

  • Relevant certifications such as CISA, CISSP, ISO 27001 Lead Implementer/Auditor, or CIPP/E.

  • Experience with GRC automation platforms (e.g., Vanta, Drata, Secureframe).

Benefits

  • Work with a dynamic, innovative team in the fast-growing ecommerce industry

  • Opportunities for career growth and advancement

  • On-site gym with showers, pickleball, and basketball

  • Flexible PTO company holidays

  • Redo perks: monthly allowance to support purchases from ecommerce stores

  • Company HSA contributions

  • Weekly lunches fully stocked break room

  • $100 monthly babysitting reimbursement

  • Office is minutes from biking and running trails


Redo is an equal opportunity employer and prohibits discrimination and harassment of any kind. We are committed to creating a diverse and inclusive work environment where all employees feel valued, respected, and supported.