Information Security Governance, Risk, Compliance; GRC Supervisor
Listed on 2026-06-18
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant
Information Security Governance, Risk, Compliance (GRC) Supervisor
Job Category: Management
Requisition Number: INFOR
022545
- Posted:
May 27, 2026 - Full-Time
ARUP Main
500 Chipeta Way
Salt Lake City, UT , USA
Schedule: Monday - Friday (40 hrs/wk) 8:00 AM - 5:00 PM
Department: IT General - 210
Primary PurposeThe Information Security Governance, Risk, and Compliance (GRC) Supervisor at ARUP provides leadership and direction for the Information Security GRC program, ensuring alignment with ARUP security policies, healthcare regulatory requirements, and the NIST Risk Management Framework. This role serves as a critical bridge between information security, technology teams, and business owners—translating regulatory and technical security requirements into practical, actionable guidance. The Information Security GRC Supervisor is responsible for educating, training, and transitioning ARUP Business Owners and System Owners to operate in compliance with NIST security standards and ARUP security policies.
This role leads risk assessments, compliance activities, audits, and governance processes while delivering clear visibility into ARUP’s risk posture through metrics and executive reporting concerning information security. In addition to technical and regulatory oversight, the Information Security GRC Supervisor leads and mentors a team of compliance professionals, drives continuous improvement of governance processes, and partners across the organization to embed risk management and security accountability into daily operations—supporting ARUP’s mission to protect clinical, laboratory, and enterprise systems.
Functions
- Leads the development, implementation, and continual improvement of ARUP’s Information Security Governance, Risk Management, and Compliance (GRC) program, ensuring alignment with ARUP security policies, institutional objectives, and the NIST Risk Management Framework (RMF).
- Serves as a primary educator and change agent for the organization, responsible for teaching, training, and transitioning ARUP Business Owners, System Owners, and technical teams to operate in compliance with NIST security frameworks and ARUP security policies.
- Designs and delivers structured training, workshops, and guidance to help business and system owners understand their security responsibilities, risk ownership, control implementation requirements, and ongoing compliance obligations under NIST SP 800-53.
- Conducts and oversees system-level risk assessments, translating technical and regulatory requirements into clear, actionable guidance for business stakeholders.
- Leads the development, review, and maintenance of security policies, standards, and procedures, ensuring alignment with ARUP policy, HIPAA, CAP, SOC 2, GDPR, ISO standards, and NIST RMF requirements.
- Leads internal audits, compliance reviews, and external audit preparation, including coordination with auditors and facilitation of evidence collection, remediation planning, and executive reporting.
- Delivers compliance and governance services to business and system owners, supporting full lifecycle alignment with NIST SP 800-53 controls, enterprise risk governance frameworks, and ARUP security policy requirements.
- Collaborates with cross-functional teams (IT, Infrastructure, Applications, and Operations) to integrate risk management and compliance practices into organizational processes, including Configuration Management, Change Management, and Change Approval Board (CAB).
- Maintains System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), Security Assessment Reports (SARs), Risk Assessment Reports (RARs), and other required cybersecurity documentation.
- Identifies gaps in security controls, recommends risk-based improvements, and oversees the implementation and tracking of corrective actions to closure.
- Supports system authorization and accreditation activities, ensuring operational environments meet defined security requirements and governance expectations.
- Develops and maintains compliance dashboards, risk metrics, and executive-level reporting to communicate risk posture, compliance status, and trends to leadership concerning information…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).