×
Register Here to Apply for Jobs or Post Jobs. X

GRC Specialist II

Job in Salt Lake City, Salt Lake County, Utah, 84193, USA
Listing for: SCIGON
Full Time position
Listed on 2026-08-15
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, IT Consultant
Salary/Wage Range or Industry Benchmark: 116000 - 144000 USD Yearly USD 116000.00 144000.00 YEAR
Job Description & How to Apply Below

a { text-decoration: none; color: #464feb;} tr th, tr td { border: 1px solid #;} tr th { background-color: #;}

As a Security GRC Specialist II
, you'll be a key member of the Governance, Risk, and Compliance (GRC) team, leading and executing core GRC programs while serving as a trusted Information Security subject matter expert. This role blends strategic oversight with hands-on execution, partnering with technical teams, business stakeholders, and vendors to ensure security controls, policies, and risk practices are effective, compliant, and clearly communicated.

a { text-decoration: none; color: #464feb;} tr th, tr td { border: 1px solid #;} tr th { background-color: #;}

As a Security GRC Specialist II
, you'll be a key member of the Governance, Risk, and Compliance (GRC) team, leading and executing core GRC programs while serving as a trusted Information Security subject matter expert. This role blends strategic oversight with hands-on execution, partnering with technical teams, business stakeholders, and vendors to ensure security controls, policies, and risk practices are effective, compliant, and clearly communicated.

What You'll Do

GRC Specialist II

Salary: $116,000-$144,000

a { text-decoration: none; color: #464feb;} tr th, tr td { border: 1px solid #;} tr th { background-color: #;}

  • Third-Party Assessments: Lead security assessments and audits, documenting evidence and performing risk assessments as needed.

  • Policy & Standards Management: Create, maintain, and evolve security policies, standards, guidelines, and supporting documentation through strong technical writing.

  • Risk & Compliance Assurance: Manage and support processes that ensure Information Technology (IT) systems meet cybersecurity, risk, and compliance requirements.

  • Security Consulting & SME Support: Serve as an Information Security subject matter expert, advising technical and non-technical stakeholders across the organization.

  • Vendor

    Risk Management:

    Manage the third-party Security Vendor Risk Management program, including assessments, remediation tracking, and lifecycle oversight.

  • Exception & Risk Treatment: Oversee the security exception request process and provide guidance on appropriate risk treatment decisions.

  • Security Awareness Program: Manage the full lifecycle of the Security Awareness program, including roadmap development, training evaluation, and effectiveness measurement.

  • GRC Platform Administration: Support and optimize Governance, Risk, and Compliance (GRC) technology platforms and associated workflows.

  • Controls & Compliance Evaluations: Conduct evaluations of IT programs and components to confirm alignment with published security standards and frameworks.

What You'll Bring
  • Education: Bachelor's degree or equivalent with five (5) years of work experience in IT Security is required.

  • Certifications: Certified Information Systems Security Professional (CISSP), Certified Information Security Auditor (CISA), Certified Information Security Manager (CISM), Advanced in AI Audit (AAIA), Advanced in AI Risk (AAIR), Advanced in AI Security Management (AAISM), or other relevant training and certifications are preferred.

  • Information Security

    Experience:

    Four (4) or more years of Information Security experience, with hands-on technical experience strongly preferred.

  • Framework & GRC Knowledge: Strong working knowledge of security frameworks and standards such as ISO 27001, National Institute of Standards and Technology (NIST), System and Organization Controls (SOC), and Standardized Information Gathering (SIG) is required.

  • AI Risk: Experience in Artificial Intelligence (AI) governance, security, and risk management is required.

  • Technical Writing & Communication: Proven ability to produce clear, well-structured security documentation and communicate complex technical topics to varied audiences.

  • Risk & Vendor Management

    Skills:

    Experience leading risk assessments, vendor security reviews, and security discussions with professionalism and tact.

  • GRC Tools & Technologies: Familiarity with GRC platforms, role-based access controls, and a broad range of security technologies and tools.

  • Analytical & Organizational Strength: Strong problem-solving, project management, and time management skills with the ability to work independently or collaboratively.

  • Technical Acumen: Working knowledge of areas such as authentication, encryption, firewalls, SIEM, intrusion detection/prevention, vulnerability management, mobile security, and privileged access management.

  • Collaboration & Professionalism: Strong interpersonal skills, attention to detail, and a commitment to maintaining accurate records and documentation.

#J-18808-Ljbffr
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary