The Information Security Governance, Risk, and Compliance (GRC) Supervisor at ARUP provides ... Leads and mentors a team of information security GRC analysts and cybersecurity professionals ...
The Information Security Governance, Risk, and Compliance (GRC) Supervisor at ARUP provides ... Leads and mentors a team of information security GRC analysts and cybersecurity professionals ...
The Information Security Governance, Risk, and Compliance (GRC) Supervisor at ARUP provides ... Leads and mentors a team of information security GRC analysts and cybersecurity professionals ...
The Information Security Governance, Risk, and Compliance (GRC) Supervisor at ARUP provides ... Leads and mentors a team of information security GRC analysts and cybersecurity professionals ...
Senior Information Governance Specialist II
Salt Lake City, UT · On-site
Medical
Retirement
PTO
... and security teams to address access risks. • Policy Exception Management: Assess and manage ... • Risk Analysis & Audits: Conduct audits, data analysis, and fact finding to identify risks ...
Senior Information Governance Specialist II
Salt Lake City, UT · On-site
Medical
Retirement
PTO
... and security teams to address access risks. • Policy Exception Management: Assess and manage ... • Risk Analysis & Audits: Conduct audits, data analysis, and fact finding to identify risks ...
You will conduct risk assessments, support accreditation activities, evaluate system security ... Ability to provide clear analysis and recommendations to program test leadership Additional ...
You will conduct risk assessments, support accreditation activities, evaluate system security ... Ability to provide clear analysis and recommendations to program test leadership Additional ...
Position Summary Odyssey Systems has an exciting opportunity for a Senior Information System ... Vulnerability assessment and risk mitigation analysis * STIG/SRG implementation and configuration ...
Position Summary Odyssey Systems has an exciting opportunity for a Senior Information System ... Vulnerability assessment and risk mitigation analysis * STIG/SRG implementation and configuration ...
... information security technologies. This helps satisfy our Senior Security Architects desire to ... Risk Management, Proxy, EDR, IAM, SIEM & Analytics A good listener with ability to work with ...
... information security technologies. This helps satisfy our Senior Security Architects desire to ... Risk Management, Proxy, EDR, IAM, SIEM & Analytics A good listener with ability to work with ...
... information security technologies. This helps satisfy our Senior Security Architects desire to ... Risk Management, Proxy, EDR, IAM, SIEM & Analytics • A good listener with ability to work with ...
... information security technologies. This helps satisfy our Senior Security Architects desire to ... Risk Management, Proxy, EDR, IAM, SIEM & Analytics • A good listener with ability to work with ...
... information security technologies. This helps satisfy our Senior Security Architects desire to ... Risk Management, Proxy, EDR, IAM, SIEM & Analytics A good listener with ability to work with ...
... information security technologies. This helps satisfy our Senior Security Architects desire to ... Risk Management, Proxy, EDR, IAM, SIEM & Analytics A good listener with ability to work with ...
Information System Security Officer (ISSO) Senior
Medical
Dental
Vision
Life
Retirement
PTO
As a Senior Information System Security Officer (ISSO) your duties will include, but are not ... Vulnerability assessment and risk mitigation analysis * STIG/SRG implementation and configuration ...
Information System Security Officer (ISSO) Senior
Medical
Dental
Vision
Life
Retirement
PTO
As a Senior Information System Security Officer (ISSO) your duties will include, but are not ... Vulnerability assessment and risk mitigation analysis * STIG/SRG implementation and configuration ...
Become a part of the "strength within." Hexcel is currently seeking an IT SOX Senior Analyst for ... Conduct risk assessments and support IT controls to mitigate risks. * Develop control test plans ...
Quick apply
Become a part of the "strength within." Hexcel is currently seeking an IT SOX Senior Analyst for ... Conduct risk assessments and support IT controls to mitigate risks. * Develop control test plans ...
The incumbent serves as a senior Information System Security Officer (ISSO). The incumbent develops network and systems design; and provides oversight assistance in the implementation of systems ...
The incumbent serves as a senior Information System Security Officer (ISSO). The incumbent develops network and systems design; and provides oversight assistance in the implementation of systems ...
Security Compliance Analyst
Medical
Dental
Vision
Proven work experience as IT Audit & Risk Assessor with a passion for details and security ... non-technical audience including senior management. * Demonstrated ability to establish ...
Security Compliance Analyst
Medical
Dental
Vision
Proven work experience as IT Audit & Risk Assessor with a passion for details and security ... non-technical audience including senior management. * Demonstrated ability to establish ...
Proven work experience as IT Audit & Risk Assessor with a passion for details and security ... non-technical audience including senior management. * Demonstrated ability to establish ...
Quick apply
Proven work experience as IT Audit & Risk Assessor with a passion for details and security ... non-technical audience including senior management. * Demonstrated ability to establish ...
Security Compliance Analyst
Salt Lake City, UT · On-site
Medical
Dental
Vision
Proven work experience as IT Audit & Risk Assessor with a passion for details and security ... non-technical audience including senior management. * Demonstrated ability to establish ...
Security Compliance Analyst
Salt Lake City, UT · On-site
Medical
Dental
Vision
Proven work experience as IT Audit & Risk Assessor with a passion for details and security ... non-technical audience including senior management. * Demonstrated ability to establish ...
Senior Insurance Analyst
Salt Lake City, UT · On-site
Medical
Dental
Vision
Life
Retirement
PTO
... Senior Insurance Analyst II to join our Global Insurance & Risk Management team. In this role, you ... , IT Security, Real Estate, Facilities, HR) to identify and mitigate risk exposures. Skills ...
Senior Insurance Analyst
Salt Lake City, UT · On-site
Medical
Dental
Vision
Life
Retirement
PTO
... Senior Insurance Analyst II to join our Global Insurance & Risk Management team. In this role, you ... , IT Security, Real Estate, Facilities, HR) to identify and mitigate risk exposures. Skills ...
IT Infrastructure - Sr. Project Manager, IT
$122K - $122K/yr
Drive advanced risk management, anticipating organizational, technical, and vendor-related risks ... Ensure adherence to enterprise security, compliance, and technology standards, partnering with ...
IT Infrastructure - Sr. Project Manager, IT
$122K - $122K/yr
Drive advanced risk management, anticipating organizational, technical, and vendor-related risks ... Ensure adherence to enterprise security, compliance, and technology standards, partnering with ...
IT Infrastructure - Sr. Project Manager, IT
Draper, UT · On-site
$122K - $122K/yr
Drive advanced risk management, anticipating organizational, technical, and vendor-related risks ... Ensure adherence to enterprise security, compliance, and technology standards, partnering with ...
IT Infrastructure - Sr. Project Manager, IT
Draper, UT · On-site
$122K - $122K/yr
Drive advanced risk management, anticipating organizational, technical, and vendor-related risks ... Ensure adherence to enterprise security, compliance, and technology standards, partnering with ...
IT Infrastructure - Sr. Project Manager, IT
Draper, UT · On-site
$122K - $122K/yr
Drive advanced risk management, anticipating organizational, technical, and vendor-related risks ... Ensure adherence to enterprise security, compliance, and technology standards, partnering with ...
IT Infrastructure - Sr. Project Manager, IT
Draper, UT · On-site
$122K - $122K/yr
Drive advanced risk management, anticipating organizational, technical, and vendor-related risks ... Ensure adherence to enterprise security, compliance, and technology standards, partnering with ...
Security Analyst III
Salt Lake City, UT · On-site
You will focus on the execution of day-to-day GRC (Governance, Risk, and Compliance) operations ... Partner with Legal, Engineering, IT, Finance, and HR to ensure corporate security policies are ...
Security Analyst III
Salt Lake City, UT · On-site
You will focus on the execution of day-to-day GRC (Governance, Risk, and Compliance) operations ... Partner with Legal, Engineering, IT, Finance, and HR to ensure corporate security policies are ...
Security Analyst III
Salt Lake City, UT · On-site +1
You will focus on the execution of day-to-day GRC (Governance, Risk, and Compliance) operations ... Partner with Legal, Engineering, IT, Finance, and HR to ensure corporate security policies are ...
Security Analyst III
Salt Lake City, UT · On-site +1
You will focus on the execution of day-to-day GRC (Governance, Risk, and Compliance) operations ... Partner with Legal, Engineering, IT, Finance, and HR to ensure corporate security policies are ...
Senior Information Security Risk Analyst information
See Utah salary details
$29.11 - $32.71
6% of jobs
$32.71 - $36.31
5% of jobs
$36.31 - $39.91
8% of jobs
$41.62 is the 25th percentile. Wages below this are outliers.
$39.91 - $43.51
11% of jobs
$43.51 - $47.11
12% of jobs
The median wage is $50.49 / hr.
$47.11 - $50.71
8% of jobs
$50.71 - $54.31
7% of jobs
$54.31 - $57.91
9% of jobs
$59.54 is the 75th percentile. Wages above this are outliers.
$57.91 - $61.51
17% of jobs
$61.51 - $65.11
8% of jobs
$65.11 - $68.72
7% of jobs
$29
$53
$68
How much do senior information security risk analyst jobs pay per hour?
What is the difference between Senior Information Security Risk Analyst vs Information Security Analyst?
| Aspect | Senior Information Security Risk Analyst | Information Security Analyst |
|---|---|---|
| Certifications | CISSP, CISA, CRISC | CISSP, Security+, CEH |
| Work Environment | Focus on risk assessment, policy development, and strategic planning | Implementing security measures, monitoring, and incident response |
| Employer & Industry Usage | Financial, healthcare, and large enterprises with complex security needs | Variety of industries, including tech, retail, and government |
Senior Information Security Risk Analysts typically handle advanced risk assessments and strategic security planning, often requiring certifications like CISSP or CISA. Information Security Analysts focus on implementing security controls and monitoring systems. Both roles are vital in maintaining organizational security but differ in scope and seniority.
How does a senior information security risk analyst typically collaborate with other departments to manage organizational risk?
What are the key skills and qualifications needed to thrive as a senior information security risk analyst?
What does a senior information security risk analyst do?
What are popular job titles related to Senior Information Security Risk Analyst jobs in Utah?
For Senior Information Security Risk Analyst jobs in Utah, the most frequently searched job titles are:
What job categories do people searching Senior Information Security Risk Analyst jobs in Utah look for?
The top searched job categories for Senior Information Security Risk Analyst jobs in Utah are:
What cities in Utah are hiring for Senior Information Security Risk Analyst jobs?
Cities in Utah with the most Senior Information Security Risk Analyst job openings:
Full-time
Re-posted 19 days ago
Job description
Schedule:
Monday - Friday (40 hrs/wk)
8:00 AM - 5:00 PM
Department: IT General - 210
Primary Purpose:
The Information Security Governance, Risk, and Compliance (GRC) Supervisor at ARUP provides leadership and direction for the Information Security GRC program, ensuring alignment with ARUP security policies, healthcare regulatory requirements, and the NIST Risk Management Framework. This role serves as a critical bridge between information security, technology teams, and business owners—translating regulatory and technical security requirements into practical, actionable guidance. The Information Security GRC Supervisor is responsible for educating, training, and transitioning ARUP Business Owners and System Owners to operate in compliance with NIST security standards and ARUP security policies. This role leads risk assessments, compliance activities, audits, and governance processes while delivering clear visibility into ARUP’s risk posture through metrics and executive reporting concerning information security. In addition to technical and regulatory oversight, the Information Security GRC Supervisor leads and mentors a team of compliance professionals, drives continuous improvement of governance processes, and partners across the organization to embed risk management and security accountability into daily operations—supporting ARUP’s mission to protect clinical, laboratory, and enterprise systems.
About ARUP:
ARUP Laboratories is a national clinical and anatomic pathology reference laboratory and an enterprise of the University of Utah and its Department of Pathology. Based in Salt Lake City, Utah.
ARUP proudly hires top talent to create a work environment of diversity, professional growth and continuous development. Our workforce is committed to the important service we provide to over one million patients each month. We always strive for excellence and have a strong desire to have involvement with the advances in medicine and the role laboratory services plays within each patient’s life. We never forget that there is a patient behind every specimen we receive.
We are looking for individuals who want to contribute to ARUP's culture of accountability, integrity, service, and excellence. Consider joining our dynamic team.
Essential Functions:
Leads the development, implementation, and continual improvement of ARUP’s Information Security Governance, Risk Management, and Compliance (GRC) program, ensuring alignment with ARUP security policies, institutional objectives, and the NIST Risk Management Framework (RMF).
Serves as a primary educator and change agent for the organization, responsible for teaching, training, and transitioning ARUP Business Owners, System Owners, and technical teams to operate in compliance with NIST security frameworks and ARUP security policies.
Designs and delivers structured training, workshops, and guidance to help business and system owners understand their security responsibilities, risk ownership, control implementation requirements, and ongoing compliance obligations under NIST SP 800-53.
Conducts and oversees - system-level risk assessments, translating technical and regulatory requirements into clear, actionable guidance for business stakeholders.
Leads the development, review, and maintenance of security policies, standards, and procedures, ensuring alignment with ARUP policy, HIPAA, CAP, SOC 2, GDPR, ISO standards, and NIST RMF requirements.
Leads internal audits, compliance reviews, and external audit preparation, including coordination with auditors and facilitation of evidence collection, remediation planning, and executive reporting.
Delivers compliance and governance services to business and system owners, supporting full lifecycle alignment with NIST SP 800-53 controls, enterprise risk governance frameworks, and ARUP security policy requirements.
Collaborates with cross-functional teams (IT, Infrastructure, Applications, and Operations) to integrate risk management and compliance practices into organizational processes, including Configuration Management, Change Management, and Change Approval Board (CAB).
Maintains System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), Security Assessment Reports (SARs), Risk Assessment Reports (RARs), and other required cybersecurity documentation.
Identifies gaps in security controls, recommends risk-based improvements, and oversees the implementation and tracking of corrective actions to closure.
Supports system authorization and accreditation activities, ensuring operational environments meet defined security requirements and governance expectations.
Develops and maintains compliance dashboards, risk metrics, and executive-level reporting to communicate risk posture, compliance status, and trends to leadership concerning information security.
Builds and sustains strong working relationships with System Owners, Authorizing Officials, System Administrators, and business leaders to promote shared accountability for information security risk management.
Leads and mentors a team of information security GRC analysts and cybersecurity professionals, providing clear direction, coaching, and performance oversight.
Leads a Vulnerability Management Team responsible for ARUP’s Vulnerability Management Program.
Works under moderate supervision, exercising independent judgment in governance, risk, and compliance decision-making, and may mentor junior team members.
Supports 24-hour operational requirements as needed, including time-sensitive risk assessments, audits, or incident-related governance activities.
Physical and Other Requirements:
Stooping: Bending body downward and forward by bending spine at the waist.
Reaching: Extending hand(s) and arm(s) in any direction.
Mobility: The person in this position needs to occasionally move between work sites and inside the office to access file cabinets, office machinery, etc.
Communication: The person in this position will work in a highly collaborative environment which requires frequent, clear, and professional communication with others.
PPE: Biohazard laboratory environment that requires use of personal protective equipment in accordance with CDC and OSHA regulations and company policies.
ARUP Policies and Procedures: To conduct self in compliance with all ARUP Policies and Procedures.
Sedentary Work: Exerting up to 10 pounds of force occasionally and/or negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects.
Fine Motor Control: Picking, pinching, typing or otherwise working on computer equipment.
Vision: Having close, far, and peripheral visual acuity to perform a variety of tasks such as making general observations of depth and distance.
About Arup
Sourced by ZipRecruiter