GRC Security Manager

Posted yesterday

robert halfSalt Lake City (UT)

SENIORITY

Manager

Apply

About the role

We are looking for an experienced GRC Security Manager to lead cybersecurity governance, risk, and compliance efforts for a health-focused organization in West Valley City, Utah. This position will shape security policies, evaluate enterprise risk, and strengthen compliance practices across the business. The role also works closely with audit, legal, privacy, procurement, and technical teams to improve resilience, manage third-party exposure, and support informed security decision-making.
Responsibilities: Lead enterprise-wide cybersecurity risk reviews to uncover control gaps, assess potential impact, and prioritize remediation plans. Create and maintain security policies, standards, and operating procedures that support regulatory expectations and business objectives. Partner with departmental leaders to ensure security requirements are clearly communicated, adopted effectively, and consistently followed. Build and manage employee security awareness initiatives, updating training content to address evolving threats and measuring program effectiveness. Serve as the main point of contact for internal audit activities related to cybersecurity controls, evidence gathering, and issue follow-up. Direct compliance efforts tied to applicable security and privacy frameworks, coordinating cross-functional teams to maintain readiness and adherence. Develop reporting dashboards and performance indicators that provide leadership with visibility into cyber risk trends and program maturity. Oversee third-party security evaluations, including due diligence reviews, risk assessments, and collaboration on contract-related security requirements. Identify cybersecurity concerns associated with AI usage and work with technical stakeholders to integrate those risks into the broader control framework. Collaborate with privacy and legal partners to align cybersecurity practices with data protection obligations and regulatory requirements.

Before you apply

Applying takes about a minute. These four things decide how fast it moves after that.

Your profile is current

It's what we read first. Occupations, seniority and locations matter more than a long history.

Two examples you can talk through

Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.

A number in mind

What you're on now and what would make you move. We negotiate better when we know both.

Your notice period

Employers plan around it, and it's the question that stalls offers most often.

Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.

More like this