GRC Specialist II

SCIGON

Salt Lake City (UT)

On-site

USD 116,000 - 144,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

SCIGON is seeking a Security GRC Specialist II in Salt Lake City to lead core GRC programs and act as a security SME. The role blends strategic oversight with hands-on execution, partnering with technical teams, stakeholders, and vendors to ensure controls, policies, and risk practices are effective and clearly communicated.

You will drive third-party assessments, policy governance, and risk assurance while supporting GRC platforms and security awareness initiatives.

Qualifications

  • Bachelor's degree in IT Security or equivalent with five years of experience.
  • Four or more years of Information Security experience, hands-on preferred.
  • CISSP, CISA, CISM or equivalent certifications preferred.
  • Strong knowledge of ISO 27001, NIST, SOC, SIG frameworks.
  • Experience in AI governance, security and risk management.
  • Clear technical writing and communication skills.
  • Experience leading risk assessments and vendor security reviews.
  • Familiarity with GRC platforms and RBAC.
  • Strong analytical and organizational abilities.
  • Working knowledge of authentication, encryption, firewalls, SIEM, vulnerability management.

Responsibilities

  • Lead security assessments and audits, document evidence and perform risk assessments as needed.
  • Create, maintain, and evolve security policies, standards, guidelines, and documentation.
  • Manage IT security risk and compliance assurance processes across systems.
  • Serve as an Information Security SME to advise stakeholders across the organization.
  • Oversee third-party Security Vendor Risk Management program and remediation tracking.
  • Manage security exception requests and advise on risk treatment decisions.
  • Oversee Security Awareness program roadmap, training evaluation and effectiveness.
  • Support and optimize GRC technology platforms and workflows.
  • Conduct evaluations to ensure IT programs align with security standards.

Skills

Third-Party Assessments
Policy & Standards Management
Risk & Compliance Assurance
Security Consulting & SME Support
Vendor Risk Management
Exception & Risk Treatment
Security Awareness Program
GRC Platform Administration
Controls & Compliance Evaluations

Education

Bachelor's degree or equivalent with five years of work experience in IT Security

Job description

a { text-decoration: none; color: #464feb;} tr th, tr td { border: 1px solid #e6e6e6;} tr th { background-color: #f5f5f5;}

As a Security GRC Specialist II, you'll be a key member of the Governance, Risk, and Compliance (GRC) team, leading and executing core GRC programs while serving as a trusted Information Security subject matter expert. This role blends strategic oversight with hands-on execution, partnering with technical teams, business stakeholders, and vendors to ensure security controls, policies, and risk practices are effective, compliant, and clearly communicated.

a { text-decoration: none; color: #464feb;} tr th, tr td { border: 1px solid #e6e6e6;} tr th { background-color: #f5f5f5;}

As a Security GRC Specialist II, you'll be a key member of the Governance, Risk, and Compliance (GRC) team, leading and executing core GRC programs while serving as a trusted Information Security subject matter expert. This role blends strategic oversight with hands-on execution, partnering with technical teams, business stakeholders, and vendors to ensure security controls, policies, and risk practices are effective, compliant, and clearly communicated.

What You'll Do

GRC Specialist II

Salary: $116,000-$144,000

a { text-decoration: none; color: #464feb;} tr th, tr td { border: 1px solid #e6e6e6;} tr th { background-color: #f5f5f5;}

  • Third-Party Assessments: Lead security assessments and audits, documenting evidence and performing risk assessments as needed.

  • Policy & Standards Management: Create, maintain, and evolve security policies, standards, guidelines, and supporting documentation through strong technical writing.

  • Risk & Compliance Assurance: Manage and support processes that ensure Information Technology (IT) systems meet cybersecurity, risk, and compliance requirements.

  • Security Consulting & SME Support: Serve as an Information Security subject matter expert, advising technical and non-technical stakeholders across the organization.

  • Vendor Risk Management: Manage the third-party Security Vendor Risk Management program, including assessments, remediation tracking, and lifecycle oversight.

  • Exception & Risk Treatment: Oversee the security exception request process and provide guidance on appropriate risk treatment decisions.

  • Security Awareness Program: Manage the full lifecycle of the Security Awareness program, including roadmap development, training evaluation, and effectiveness measurement.

  • GRC Platform Administration: Support and optimize Governance, Risk, and Compliance (GRC) technology platforms and associated workflows.

  • Controls & Compliance Evaluations: Conduct evaluations of IT programs and components to confirm alignment with published security standards and frameworks.

What You'll Bring
  • Education: Bachelor's degree or equivalent with five (5) years of work experience in IT Security is required.

  • Certifications: Certified Information Systems Security Professional (CISSP), Certified Information Security Auditor (CISA), Certified Information Security Manager (CISM), Advanced in AI Audit (AAIA), Advanced in AI Risk (AAIR), Advanced in AI Security Management (AAISM), or other relevant training and certifications are preferred.

  • Information Security Experience: Four (4) or more years of Information Security experience, with hands-on technical experience strongly preferred.

  • Framework & GRC Knowledge: Strong working knowledge of security frameworks and standards such as ISO 27001, National Institute of Standards and Technology (NIST), System and Organization Controls (SOC), and Standardized Information Gathering (SIG) is required.

  • AI Risk: Experience in Artificial Intelligence (AI) governance, security, and risk management is required.

  • Technical Writing & Communication: Proven ability to produce clear, well-structured security documentation and communicate complex technical topics to varied audiences.

  • Risk & Vendor Management Skills: Experience leading risk assessments, vendor security reviews, and security discussions with professionalism and tact.

  • GRC Tools & Technologies: Familiarity with GRC platforms, role-based access controls, and a broad range of security technologies and tools.

  • Analytical & Organizational Strength: Strong problem-solving, project management, and time management skills with the ability to work independently or collaboratively.

  • Technical Acumen: Working knowledge of areas such as authentication, encryption, firewalls, SIEM, intrusion detection/prevention, vulnerability management, mobile security, and privileged access management.

  • Collaboration & Professionalism: Strong interpersonal skills, attention to detail, and a commitment to maintaining accurate records and documentation.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Analyst
GRC Analyst

Golden Technology • North Carolina

Hybrid
USD 120,000 - 160,000
GRC Specialist (Governance, Risk & Compliance)
GRC Specialist (Governance, Risk & Compliance)

360CyberX • United States

On-site
USD 70,000 - 90,000
GRC Lead
GRC Lead

Jobtailor • Houston (TX)

On-site
USD 120,000 - 180,000
GRC Analyst
GRC Analyst

The Emery Company, LLC • Houston (TX)

On-site
USD 85,000 - 110,000
Governance Risk and Compliance Analyst Intermediate
Governance Risk and Compliance Analyst Intermediate

Cone Health • Greensboro (NC)

On-site
USD 110,000 - 140,000
Information Security Governance Specialist
Information Security Governance Specialist

SRM Digital • Roanoke (TX)

On-site
USD 120,000 - 160,000
Lead GRC Analyst (IT/Security)
Lead GRC Analyst (IT/Security)

Ultra Clean Technology • Manor (TX)

On-site
USD 90,000 - 120,000
Governance, Risk & Compliance Analyst I
Governance, Risk & Compliance Analyst I

Geographic Solutions, Inc. • Dunedin (FL)

On-site
USD 60,000 - 100,000
GRC Analyst II
GRC Analyst II

Frontgrade Technologies • Colorado Springs (CO)

On-site
USD 70,000 - 90,000
Immediate Medical, Dental, and Vision
401K Match with 100% immediate vesting
Tuition Reimbursement/Student Loan Repayment
+2
Sr. IT Security Analyst
Sr. IT Security Analyst

The Marzetti Company • Columbus (OH)

On-site
USD 90,000 - 120,000