Manager of IT Security

Kforce Inc

Draper (UT)

On-site

USD 140,000 - 180,000

Full time

44 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health insurance
Dental insurance
Vision insurance
401(k) plan
Life insurance
Disability insurance
Paid time off

Job summary

Kforce is seeking a Senior Manager, IT Security - GRC in Draper, UT to lead and mature our cybersecurity governance, risk management, and compliance programs. You will partner with IT, Legal, Internal Audit and business stakeholders to translate risks into business impacts for executives.

Responsibilities include establishing policies and controls, aligning with NIST CSF, ISO 27001, SOC 2, managing risk assessments and third-party risk, overseeing audits, and ensuring regulatory compliance

Qualifications

  • Bachelor’s degree or higher in information security, IT, risk, or related field.
  • 7+ years in cybersecurity, risk, compliance, or audit.
  • 3+ years in GRC leadership or senior-level role.
  • Strong knowledge of NIST CSF, ISO 27001, SOC 2.
  • Experience managing audits and enterprise risk programs.

Responsibilities

  • Lead and mature the enterprise GRC program, including policies, standards, procedures, and metrics.
  • Align cybersecurity frameworks with industry standards (NIST CSF, ISO 27001, CIS, SOC 2).
  • Define and manage risk tolerance, exception management, and control ownership.
  • Ensure alignment between cybersecurity governance and enterprise risk management (ERM).
  • Lead cyber risk assessments, control gap analyses, and third-party risk evaluations.
  • Maintain enterprise risk register including scoring, remediation tracking, and treatment plans.
  • Partner with technical and business teams to mitigate, transfer, or accept risk.
  • Translate technical vulnerabilities into business-impact risk statements.
  • Manage compliance across regulatory and industry frameworks (SOC 2, ISO, SOX, HIPAA, PCI, privacy).
  • Serve as primary liaison for internal/external audits.
  • Coordinate audit responses, evidence collection, and remediation efforts.
  • Support customer security assessments, due diligence, and RFP responses.
  • Monitor regulatory changes and assess impact.

Skills

GRC leadership
Cybersecurity governance
Risk management
Regulatory/compliance
Stakeholder communication

Education

Bachelor’s degree in Information Security, IT, Risk, or related field

Tools

ServiceNow GRC
Archer
Drata
Vanta
OneTrust

Job description

Responsibilities

Kforce has a client that is seeking a Senior Manager, IT Security - GRC in Draper, UT. Overview: The Senior Manager, IT Security - GRC is responsible for leading and maturing the organization's cybersecurity governance, risk management, and compliance programs. This role ensures cybersecurity risks are identified, assessed, and communicated effectively while aligning security controls with regulatory, contractual, and business requirements. This individual will partner closely with IT Infrastructure, Security Operations, Legal, Internal Audit, and business stakeholders to enable secure and compliant operations across the enterprise. The role requires the ability to translate complex technical risks into clear business impact for executive leadership. Key Responsibilities: Governance & Program Management:

  • Lead and mature the enterprise GRC program, including policies, standards, procedures, and metrics
  • Align cybersecurity frameworks with industry standards (NIST CSF, ISO 27001, CIS, SOC 2)
  • Define and manage risk tolerance, exception management, and control ownership
  • Ensure alignment between cybersecurity governance and enterprise risk management (ERM)
  • Lead cyber risk assessments, control gap analyses, and third-party risk evaluations
  • Maintain enterprise risk register including scoring, remediation tracking, and treatment plans
  • Partner with technical and business teams to mitigate, transfer, or accept risk
  • Translate technical vulnerabilities into business-impact risk statements
Responsibilities

Kforce has a client that is seeking a Senior Manager, IT Security - GRC in Draper, UT. Overview: The Senior Manager, IT Security - GRC is responsible for leading and maturing the organization's cybersecurity governance, risk management, and compliance programs. This role ensures cybersecurity risks are identified, assessed, and communicated effectively while aligning security controls with regulatory, contractual, and business requirements. This individual will partner closely with IT Infrastructure, Security Operations, Legal, Internal Audit, and business stakeholders to enable secure and compliant operations across the enterprise. The role requires the ability to translate complex technical risks into clear business impact for executive leadership. Key Responsibilities: Governance & Program Management:

  • Lead and mature the enterprise GRC program, including policies, standards, procedures, and metrics
  • Align cybersecurity frameworks with industry standards (NIST CSF, ISO 27001, CIS, SOC 2)
  • Define and manage risk tolerance, exception management, and control ownership
  • Ensure alignment between cybersecurity governance and enterprise risk management (ERM)
Risk Management
  • Lead cyber risk assessments, control gap analyses, and third-party risk evaluations
  • Maintain enterprise risk register including scoring, remediation tracking, and treatment plans
  • Partner with technical and business teams to mitigate, transfer, or accept risk
  • Translate technical vulnerabilities into business-impact risk statements
Compliance & Assurance
  • Manage compliance across regulatory and industry frameworks (SOC 2, ISO, SOX, HIPAA, PCI, privacy)
  • Serve as primary liaison for internal/external audits
  • Coordinate audit responses, evidence collection, and remediation efforts
  • Support customer security assessments, due diligence, and RFP responses
  • Monitor regulatory changes and assess impact
Requirements
  • Bachelor's degree in Information Security, IT, Risk, or related field
  • 7+ years in cybersecurity, risk, compliance, or audit
  • 3+ years in GRC leadership or senior-level role
  • Strong knowledge of NIST CSF, ISO 27001, SOC 2
  • Experience managing audits and enterprise risk programs
  • Strong communication skills with executive presence
Preferred
  • Certifications: CISSP, CISM, CISA, CRISC, ISO 27001
  • Experience with GRC tools (ServiceNow GRC, Archer, Drata, Vanta, OneTrust)

The pay range is the lowest to highest compensation we reasonably in good faith believe we would pay at posting for this role. We may ultimately pay more or less than this range. Employee pay is based on factors like relevant education, qualifications, certifications, experience, skills, seniority, location, performance, union contract and business needs. This range may be modified in the future.

  • medical/dental/vision insurance
  • HSA
  • FSA
  • 401(k)
  • life, disability & ADD insurance to eligible employees
  • Salaried personnel receive paid time off
  • Hourly employees are not eligible for paid time off unless required by law
  • Hourly employees on a Service Contract Act project are eligible for paid sick leave

Note: Pay is not considered compensation until it is earned, vested and determinable. The amount and availability of any compensation remains in Kforce's sole discretion unless and until paid and may be modified in its discretion consistent with the law.

This job is not eligible for bonuses, incentives or commissions.

Kforce is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager of Cybersecurity GRC
Manager of Cybersecurity GRC

Kforce Inc • West Valley City (UT)

On-site
USD 130,000 - 180,000
Medical Insurance
Dental Insurance
Vision Insurance
+6
Senior IT Security Engineer
Senior IT Security Engineer

Kforce Inc • Draper (UT)

On-site
USD 120,000 - 180,000
Senior IT Security Leader: GRC & Risk Management
Senior IT Security Leader: GRC & Risk Management

Kforce Inc • Draper (UT)

On-site
USD 140,000 - 180,000
Health insurance
Dental insurance
Vision insurance
+4
Manager - IT Governance, Risk and Compliance
Manager - IT Governance, Risk and Compliance

Plexus • Neenah (WI)

On-site
USD 112,000 - 169,000
IT Security Engineer
IT Security Engineer

Kforce Inc • Draper (UT)

On-site
USD 110,000 - 140,000
Medical/Dental/Vision insurance
HSA/FSA options
401(k) plan
+1
Senior Manager – Cybersecurity & Governance, Risk & Compliance (GRC)
Senior Manager – Cybersecurity & Governance, Risk & Compliance (GRC)

Material Handling Systems, Inc. • United States

On-site
USD 133,000 - 200,000
Manager - IT Governance, Risk and Compliance
Manager - IT Governance, Risk and Compliance

Plexus Corp • Neenah (WI)

On-site
USD 112,000 - 169,000
Manager - IT Governance, Risk and Compliance
Manager - IT Governance, Risk and Compliance

Plexus Corp. • Neenah (WI)

On-site
USD 112,000 - 169,000
Cybersecurity GRC Lead: Risk & Compliance
Cybersecurity GRC Lead: Risk & Compliance

Kforce Inc • West Valley City (UT)

On-site
USD 130,000 - 180,000
Medical Insurance
Dental Insurance
Vision Insurance
+6
Director of Cyber Security
Director of Cyber Security

Kforce Inc • Englewood (CO)

On-site
USD 160,000 - 210,000