Information Security Governance, Risk, Compliance (GRC) Supervisor
ARUP Laboratories
Information Security Governance, Risk, Compliance (GRC) Supervisor Job Category: Management Requisition Number: INFOR022545 Posted: May 27, 2026 Full-Time Locations ARUP Main 500 Chipeta Way Salt Lake City, UT 84108 1221, USA Schedule: Monday - Friday (40 hrs/wk) 8:00 AM - 5:00 PM Department: IT General - 210 Primary Purpose The Information Security Governance, Risk, and Compliance (GRC) Supervisor at ARUP provides leadership and direction for the Information Security GRC program, ensuring alignment with ARUP security policies, healthcare regulatory requirements, and the NIST Risk Management Framework. This role serves as a critical bridge between information security, technology teams, and business owners—translating regulatory and technical security requirements into practical, actionable guidance. The Information Security GRC Supervisor is responsible for educating, training, and transitioning ARUP Business Owners and System Owners to operate in compliance with NIST security standards and ARUP security policies. This role leads risk assessments, compliance activities, audits, and governance processes while delivering clear visibility into ARUP’s risk posture through metrics and executive reporting concerning information security. In addition to technical and regulatory oversight, the Information Security GRC Supervisor leads and mentors a team of compliance professionals, drives continuous improvement of governance processes, and partners across the organization to embed risk management and security accountability into daily operations—supporting ARUP’s mission to protect clinical, laboratory, and enterprise systems. Essential Functions Leads the development, implementation, and continual improvement of ARUP’s Information Security Governance, Risk Management, and Compliance (GRC) program, ensuring alignment with ARUP security policies, institutional objectives, and the NIST Risk Management Framework (RMF). Serves as a primary educator and change agent for the organization, responsible for teaching, training, and transitioning ARUP Business Owners, System Owners, and technical teams to operate in compliance with NIST security frameworks and ARUP security policies. Designs and delivers structured training, workshops, and guidance to help business and system owners understand their security responsibilities, risk ownership, control implementation requirements, and ongoing compliance obligations under NIST SP 800-53. Conducts and oversees system-level risk assessments, translating technical and regulatory requirements into clear, actionable guidance for business stakeholders. Leads the development, review, and maintenance of security policies, standards, and procedures, ensuring alignment with ARUP policy, HIPAA, CAP, SOC 2, GDPR, ISO standards, and NIST RMF requirements. Leads internal audits, compliance reviews, and external audit preparation, including coordination with auditors and facilitation of evidence collection, remediation planning, and executive reporting. Delivers compliance and governance services to business and system owners, supporting full lifecycle alignment with NIST SP 800-53 controls, enterprise risk governance frameworks, and ARUP security policy requirements. Collaborates with cross-functional teams (IT, Infrastructure, Applications, and Operations) to integrate risk management and compliance practices into organizational processes, including Configuration Management, Change Management, and Change Approval Board (CAB). Maintains System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), Security Assessment Reports (SARs), Risk Assessment Reports (RARs), and other required cybersecurity documentation. Identifies gaps in security controls, recommends risk-based improvements, and oversees the implementation and tracking of corrective actions to closure. Supports system authorization and accreditation activities, ensuring operational environments meet defined security requirements and governance expectations. Develops and maintains compliance dashboards, risk metrics, and executive-level reporting to communicate risk posture, compliance status, and trends to leadership concerning information security. Builds and sustains strong working relationships with System Owners, Authorizing Officials, System Administrators, and business leaders to promote shared accountability for information security risk management. Leads and mentors a team of information security GRC analysts and cybersecurity professionals, providing clear direction, coaching, and performance oversight. Leads a Vulnerability Management Team responsible for ARUP’s Vulnerability Management Program. Works under moderate supervision, exercising independent judgment in governance, risk, and compliance decision-making, and may mentor junior team members. Supports 24-hour operational requirements as needed, including time-sensitive risk assessments, audits, or incident-related governance activities. Physical and Other Requirements Stooping: Bending body downward and forward by bending spine at the waist. Reaching: Extending hand(s) and arm(s) in any direction. Mobility: The person in this position needs to occasionally move between work sites and inside the office to access file cabinets, office machinery, etc. Communication: The person in this position will work in a highly collaborative environment which requires frequent, clear, and professional communication with others. PPE: Biohazard laboratory environment that requires use of personal protective equipment in accordance with CDC and OSHA regulations and company policies. ARUP Policies and Procedures: To conduct self in compliance with all ARUP Policies and Procedures. Sedentary Work: Exerting up to 10 pounds of force occasionally and/or negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects. Fine Motor Control: Picking, pinching, typing or otherwise working on computer equipment. Vision: Having close, far, and peripheral visual acuity to perform a variety of tasks such as making general observations of depth and distance. Education Required: Bachelor's Degree or better in Computer Science or related field. Experience Required Bachelor's degree in IT, computer science, information security, cybersecurity, or a closely related field. 3-5 years of experience in cybersecurity, risk management, compliance within large-scale, complex IT environments. Demonstrable experience in risk assessment methodologies, familiarity with healthcare and regulatory frameworks (e.g., HIPAA, SOC2, NIST, FISMA, RMF), and practical knowledge of information security principles and best practices. Excellent communication, analytical, and problem-solving skills. Demonstrated management skills including willingness and ability to collaborate across IT and business units; proactively communicate with all levels of the organization; strategic thinking. Preferred Relevant industry certifications (e.g., CISSP, CISM, CRISC) are highly desirable. Project management certification (e.g., PMP) is highly desirable. Preferred Licenses & Certifications Project Management Professional (PMP). Equal Opportunity Employer Protected Veterans/Individuals with Disabilities. This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor. #J-18808-Ljbffr
$80.05k - $165k
...for leading Cybersecurity and IT governance, risk, and compliance efforts, including the establishment... ...documentation detailing how information should be secured including the maintenance and development... ...tracking, and closure of GRC-related issues in ServiceNow, ensuring...Suggested- Senior Governance, Risk, and Compliance (GRC) Process Analyst Company: The Boeing Company Boeing is seeking... ...management coordination, risk assessments, security controls validation, and corporate/... .... This role will partner with Information Security, IT&O, Internal Audit,...SuggestedPermanent employmentFull timeWork experience placementRelocationVisa sponsorshipWork visaRelocation packageFlexible hoursShift work
$118.8k - $178.2k
...IT Compliance Manager page is loaded## IT Compliance Managerlocations... ...testing efforts within Information Security team. This role is responsible... ...and a passion for proactive risk management.**Responsibilities... ...practices.* Experience with GRC platforms (e.g., Archer, LogicGate...SuggestedPermanent employmentRemote work$172k - $250k
...is seeking a Director of Information Security Audit & Compliance to join the team. Approved... ...information security program is governed through a consistent,... ...remediation plans. Governance, Risk & Control Framework... ...Experience implementing GRC tooling to support audit and...SuggestedInternshipSeasonal workWork at officeLocal areaFlexible hours3 days per week- ...Cybersecurity, Data Privacy, & Compliance Cottonwood Heights, Utah... ..., data privacy, and data governance programs while ensuring... ...executes the organization's information security strategy, establishes and matures... ...information security risks within the organization....Suggested
$118.5k - $251.6k
...Manager of Data Center Compliance Integration** . You will... ...Program across commercial, government, and hyperscale... ...operational effectiveness, risk posture, and program maturity. ~ Inform development of KPIs, dashboards... ...of Information Security ~ Strong understanding...Contract workTemporary workFlexible hours$139.4k - $291.8k
...Description As Director of Compliance & Property Management... ...the administrative, governance, and regulatory... ...manage property-related risks involving land use,... ...infrastructure reliability, security, sustainability, and... ...Range and benefit information provided in this posting...Full timeContract workTemporary workWork at officeLocal areaRelocation packageFlexible hours- Sr. Manager, Compliance Governance, Regulatory Operations & AI Enablement Overview The Sr. Manager... ...within the U.S. Consumer Regulatory Risk Identification, Advisory and Assessment... ...to uphold our brand promise of trust, security, and service. As part of Team Amex, you...Full timeWork at officeLocal areaFlexible hours
- ...As the Financial Compliance Manager for the Utah Transit Authority, you will have the opportunity to strengthen how one of the largest public... ...responsibly. In this role, your work directly supports risk reduction, regulatory compliance, and the integrity of UTA’s financial...Full timeContract workTemporary workImmediate startFlexible hours
- ...Quanta-Services is seeking a Director, Engineering PMO - Transmission Line to lead the engineering governance for transmission line projects. This role requires a strong engineering background and the ability to manage large, multidisciplinary teams effectively. The ideal...
$124k - $280k
...problem-solving approaches Secure timely delivery of projects... ...KPIs/OKRs, dashboards, and governance processes Experience... ...DAOs) and their regulatory, risk, and compliance implications Experience... ...; age; disability; genetic information (including family medical history...Full timeContract workH1b$337.7k
...outside counsel Identify emerging IP risks and opportunities in partnership with scientific... ..., freedom to operate, and IP risk to inform R&D and business decisions Interpret... ...internal stakeholders on IP-related risks, compliance, and business implications across...Work at officeLocal areaRemote work- ...CSL Plasma Inc. seeks a Director, Portfolio Strategy & Market Insights to lead investment governance and oversee the Market Insights capability. This role provides strategic advisory to senior leadership, shaping resource allocation critical for long-term growth. Ideal...
- ...collaborate closely with Product Leadership, Sales, and Finance, driving performance analysis, pricing initiatives, and lifecycle governance. The ideal candidate has 3-6 years in product management or consulting, strong analytical skills, and the ability to present...
$78.8k - $145.13k
...healthcare financing, enterprise risk management and regulatory compliance, data analytics and... ...technology, or government data) will also be considered... ...changing direction when new information or data emerges.... ...employees' health, financial security, and well-being....Full timeTemporary workWork experience placementRemote workFlexible hours- ...Purpose:The Compliance Manager reports to the AVP of Compliance Management... ...and mitigating compliance risks for the Bank.Tasks:Provides... ...Committee packets on time.Stays informed on the regulatory environment... ...review, SP corporate governance and vendor onboarding process...Contract workWork at officeNight shift
- ...company is seeking a Director, Legal to be their sole in-house legal advisor. This role requires managing all legal matters, ensuring compliance, and working closely with senior leadership. Ideal candidates will have a Juris Doctorate, 10+ years of corporate legal...Remote work
$145k - $165k
...A global technology company is seeking a Compliance Manager to oversee the operations of its compliance programs, focusing on healthcare... ...The role involves developing compliance frameworks, conducting risk assessments, and providing training. Competitive salary of $145...Remote work- ...Airways™ is seeking a Director of Cybersecurity, Data Privacy, & Compliance to lead enterprise cybersecurity efforts and ensure compliance with regulations. This role is essential for managing data governance programs and guiding the use of technology in support of our...
- ...candidate will oversee the drafting and negotiation of various types of contracts and collaborate with cross-functional teams to ensure compliance. The role requires a minimum of 4–6 years of experience in contract management, a Bachelor's degree or JD, and expertise in CLM...Contract workBank staff
- SME Industries is seeking a dedicated Safety Professional to minimize job-related accidents and enhance safety measures in the workplace. The role demands effective communication and analytical skills to develop and implement safety programs while training operational ...
- ...management company in Salt Lake City seeks an experienced environmental professional to manage groundwater and associated media compliance. The role includes oversight of environmental protection programs, budget management, and direct communication with stakeholders....Work at officeRemote work
- ...Prinova Group LLC. in Salt Lake City is seeking a Quality Systems Supervisor to oversee QA functions and ensure compliance with regulations. This role involves managing product lot releases and supporting internal audits while maintaining high standards within the quality...
- A leading health insurance provider is seeking a Medical Director responsible for reviewing clinical cases and ensuring compliance with CMS guidelines. This remote position requires an MD or DO degree, board certification, and at least 10 years of clinical experience....Remote work
- Route 92 Medical Inc is searching for a Quality Manager in South Jordan, UT. This full-time role focuses on ensuring compliance with regulatory requirements while collaborating with cross-functional teams to drive quality improvements. Candidates should have a degree in...Full time
$117.4k - $161.37k
...PacifiCorp is looking for a dedicated professional in Salt Lake City who will manage Significant Event Reporting and support compliance for the thermal generation fleet. The role involves collaborating with various departments to improve operational standards and training...- STO Building Group Careers is looking for a qualified ESH professional to implement corporate safety policies across various project sites in the U.S. Responsibilities include managing safety programs, conducting safety reviews, and establishing a strong safety culture ...
$121k - $181.6k
...aerospace and defense company seeks a Manager, Global Supply Chain 2 to oversee compliance operations. This remote role will involve managing compliance-related operations, ensuring adherence to government audits, and leading a team of compliance pros. Candidates must have a...Remote work- ...functions of the Arivo Compliance/Legal Department.... ...Regulatory Compliance and Risk Management Monitor... ...and compile required information for all licensing and... ...appropriate approvals are secured. IV. Legal... ...Review and respond to government seizures. Coordinate...Contract workFixed term contractWork at office
- ...developing, and directing the hospital’s nursing services and other clinical functions. The CCO participates with the hospital’s governing body, management, medical staff and clinical leaders in the hospital’s decision making structures and processes and is responsible...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Information Security Governance, Risk, Compliance (GRC) Supervisor. Be the first to apply!
- regulatory affairs director Salt Lake City, UT
- regulatory manager Salt Lake City, UT
- head compliance Salt Lake City, UT
- director global regulatory affairs Salt Lake City, UT
- compliance manager Salt Lake City, UT
- manager regulatory affairs Salt Lake City, UT
- compliance director Salt Lake City, UT
- regulatory & compliance manager Salt Lake City, UT
- training and compliance manager Salt Lake City, UT
- risk underwriter Salt Lake City, UT

