GRC Security Manager
Robert Half · West Valley City, UT · Yesterday
On-siteInformation TechnologyFull-time
We are looking for an experienced GRC Security Manager to lead cybersecurity governance, risk, and compliance efforts for a health-focused organization in West Valley City, Utah. This position will shape security policies, evaluate enterprise risk, and strengthen compliance practices across the business.
About the role
The GRC Security Manager works closely with audit, legal, privacy, procurement, and technical teams to improve resilience, manage third-party exposure, and support informed security decision-making.
Responsibilities
- Lead enterprise-wide cybersecurity risk reviews to uncover control gaps, assess potential impact, and prioritize remediation plans.
- Create and maintain security policies, standards, and operating procedures that support regulatory expectations and business objectives.
- Partner with departmental leaders to ensure security requirements are clearly communicated, adopted effectively, and consistently followed.
- Build and manage employee security awareness initiatives, updating training content to address evolving threats and measuring program effectiveness.
- Serve as the main point of contact for internal audit activities related to cybersecurity controls, evidence gathering, and issue follow-up.
- Direct compliance efforts tied to applicable security and privacy frameworks, coordinating cross-functional teams to maintain readiness and adherence.
- Develop reporting dashboards and performance indicators that provide leadership with visibility into cyber risk trends and program maturity.
- Oversee third-party security evaluations, including due diligence reviews, risk assessments, and collaboration on contract-related security requirements.
- Identify cybersecurity concerns associated with AI usage and work with technical stakeholders to integrate those risks into the broader control framework.
- Collaborate with privacy and legal partners to align cybersecurity practices with data protection obligations and regulatory requirements.
Requirements
- Bachelor’s degree in Cybersecurity, Information Technology, or a closely related discipline; advanced education is preferred.
- At least 5–7 years of hands-on experience in cybersecurity governance, risk, and compliance, with broader senior-level experience strongly valued.
- Proven background in performing cyber risk assessments, writing security policies, and managing awareness or training programs.
- Working knowledge of established regulatory and compliance frameworks relevant to security, privacy, and risk management.
- Experience supporting internal or external audit processes and coordinating remediation activities across multiple teams.
- Familiarity with vendor risk management practices, including security reviews for third parties and contract-related control considerations.
- Understanding of enterprise security concepts such as application security, network security, SIEM, and broader governance practices.
- Certifications in security, audit, or risk management are preferred.
Benefits
- Medical, vision, dental, and life and disability insurance.
- Eligibility to enroll in our company 401(k) plan.