1

It Risk And Compliance Jobs in Utah (NOW HIRING)

Technology Governance Manager

Midvale, UT · On-site

$89K - $109K/yr

... IT, project management, software development, and legal ... Monitor and report on the resolution of issues identified in audits, compliance reviews, and risk ...

New

... Compliance, and Technology Risk Ensures IT solution architectures support compliance with CLIA, CAP, HIPAA, and applicable state and federal regulations. Ensures IT security patterns that protect PHI ...

... Compliance (GRC), Information Security Risk, or a related discipline. * Experience conducting enterprise risk assessments and developing risk mitigation plans. * Experience using Governance, Risk ...

next page

Showing results 1-20

It Risk And Compliance information

What is IT Risk and Compliance?

IT Risk and Compliance refers to the process of identifying, assessing, and managing risks associated with an organization's information technology systems, while ensuring that these systems adhere to relevant laws, regulations, and internal policies. Professionals in this field work to protect sensitive data, prevent security breaches, and ensure that the organization's IT practices are compliant with industry standards such as GDPR, HIPAA, or SOX. They often conduct risk assessments, implement controls, monitor compliance, and respond to audits. The goal is to minimize potential threats to IT infrastructure and maintain the trust of customers and stakeholders.

What are the key skills and qualifications needed to thrive as an IT Risk and Compliance professional?

To thrive as an IT Risk and Compliance professional, you need a solid understanding of IT governance, risk management frameworks, regulatory requirements, and a relevant degree such as in information technology, cybersecurity, or a related field. Familiarity with tools like GRC (Governance, Risk, and Compliance) platforms, as well as certifications such as CISA, CRISC, or CISSP, is typically required. Strong analytical thinking, attention to detail, and effective communication help professionals excel in navigating complex regulations and collaborating with cross-functional teams. These skills and qualifications are crucial for ensuring organizational compliance, mitigating security risks, and maintaining trust with stakeholders.

How does an IT Risk and Compliance professional typically collaborate with other departments to ensure regulatory adherence?

IT Risk and Compliance professionals regularly work with teams across the organization—such as IT, legal, audit, and business operations—to identify risks, interpret regulations, and implement compliance controls. They facilitate training, conduct assessments, and coordinate responses to audits or incidents, ensuring that everyone understands their responsibilities. Effective communication and strong relationship-building skills are essential, as much of the role involves translating technical requirements into actionable steps for non-technical staff. This cross-functional collaboration helps maintain a culture of compliance and minimizes organizational risk.

What is the difference between It Risk And Compliance vs Cybersecurity Analyst?

AspectIt Risk And ComplianceCybersecurity Analyst
CertificationsISO 27001, CISSP, CISACISSP, CompTIA Security+
Work EnvironmentPolicy development, risk assessments, compliance auditsMonitoring security threats, incident response, vulnerability testing
Employer & Industry UsageFinancial, healthcare, government sectorsTech companies, financial institutions, government agencies

While both roles focus on protecting information, It Risk And Compliance emphasizes establishing policies, ensuring regulatory adherence, and managing overall risk frameworks. Cybersecurity Analysts primarily focus on identifying and mitigating security threats through technical measures. Understanding these differences helps organizations assign the right responsibilities and professionals for their security needs.

Is IT risk and compliance a good career?

IT risk and compliance is a growing field that involves managing cybersecurity threats, ensuring regulatory adherence, and implementing security controls. Professionals in this area often require certifications like CISSP or CISA and work in environments that demand strong analytical and technical skills. It offers opportunities for career advancement and job stability due to increasing regulatory requirements and cybersecurity concerns.
Infographic showing various It Risk And Compliance job openings in Utah as of August 2026, with employment types broken down into 1% As Needed, 77% Full Time, 19% Part Time, and 3% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution.

Director, Governance, Risk & Compliance

Lehi, UT • On-site

MX Technologies, Inc.
501 - 1,000 employees

Full-time

Posted 27 days ago


Job description

As we continue to grow our platform and expand our customer base, we're looking for an experienced Director of Governance, Risk & Compliance (GRC) to lead our enterprise Information Security Governance, Risk, Compliance, and Privacy programs. This leader will partner across Security, Engineering, Legal, Product, Sales, Customer Success, and Operations to ensure MX maintains industry-leading security and privacy standards while enabling the business to move quickly and responsibly.

Reporting directly to the VP & Chief Information Security Officer (CISO), you will lead the Compliance team and own the strategy, execution, and continuous improvement of MX's security governance, privacy, and regulatory compliance programs.

 What You'll DoLead Governance, Risk & Compliance
  • Develop and execute MX's enterprise Governance, Risk & Compliance (GRC) strategy.
  • Build, mature, and continuously improve security, privacy, and risk management programs that align with business objectives and regulatory requirements.
  • Develop, maintain, and operationalize enterprise-wide security policies, standards, controls, and governance processes.
  • Establish scalable compliance frameworks that support continued company growth while reducing organizational risk.
Own Privacy & Regulatory Compliance
  • Lead the company's global privacy program across multiple jurisdictions.
  • Ensure compliance with applicable privacy regulations, including GDPR, CCPA, HIPAA, PIPEDA, UK Data Protection Act, and other emerging regulations.
  • Partner with Legal, Engineering, Product, and business stakeholders to perform Privacy Impact Assessments (PIAs) and advise on privacy requirements throughout the product lifecycle.
  • Develop governance frameworks for responsible data collection, storage, processing, retention, and sharing.
  • Oversee data mapping initiatives, vendor privacy reviews, and data governance practices.
Manage Audits & Customer Assurance
  • Own all internal and external security, privacy, and compliance audits.
  • Lead certification efforts including SOC 2, ISO 27001, PCI DSS, and other applicable frameworks.
  • Serve as the executive owner for customer security and privacy questionnaires.
  • Partner with Sales and Customer Success to support enterprise customer due diligence and security reviews.
Drive Risk Management
  • Continuously assess organizational security, compliance, and privacy risks.
  • Monitor effectiveness of security controls and recommend improvements where necessary.
  • Build reporting and metrics that provide executive leadership visibility into organizational risk posture.
  • Develop mitigation strategies and partner across engineering and operations to reduce risk.
Lead & Develop the Team
  • Lead, mentor, and grow a high-performing Compliance and Privacy team.
  • Foster a culture of accountability, operational excellence, and continuous improvement.
  • Develop scalable processes that improve efficiency while maintaining regulatory compliance.
Build Cross-Functional Partnerships
  • Partner closely with Security, Engineering, Legal, Product, Sales, Support, and Operations to embed security and privacy into business processes.
  • Influence stakeholders across the organization to balance business objectives with regulatory obligations.
  • Lead company-wide privacy and compliance awareness initiatives and employee training programs.
Basic Qualifications
  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Information Systems, Business, Legal Studies, or a related field.
  • 10+ years of experience leading Information Security Governance, Risk, Compliance, Privacy, or Security Operations programs.
  • Deep expertise with compliance frameworks
  • Experience implementing Governance, Risk & Compliance (GRC) platforms and common control frameworks.
Preferred Qualifications
  • Professional certifications such as: CIPP, CIPM, CIPT, CISM, CISA
  • Experience working within fintech or highly regulated industries.
  • Knowledge of Business Continuity Planning and Disaster Recovery.
  • Experience supporting multinational organizations with global regulatory requirements.
  • Familiarity with Web Application Firewalls (WAFs), Content Delivery Networks (CDNs), and modern cloud infrastructure.