Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Information Security Governance, Risk, Compliance (GRC) Supervisor / Manager

ARUP Laboratories

Information Security GRC Supervisor

Schedule: Monday - Friday (40 hrs/wk) 8:00 AM - 5:00 PM

Department: IT General - 210

Primary Purpose:

The Information Security Governance, Risk, and Compliance (GRC) Supervisor at ARUP provides leadership and direction for the Information Security GRC program, ensuring alignment with ARUP security policies, healthcare regulatory requirements, and the NIST Risk Management Framework. This role serves as a critical bridge between information security, technology teams, and business ownerstranslating regulatory and technical security requirements into practical, actionable guidance. The Information Security GRC Supervisor is responsible for educating, training, and transitioning ARUP Business Owners and System Owners to operate in compliance with NIST security standards and ARUP security policies. This role leads risk assessments, compliance activities, audits, and governance processes while delivering clear visibility into ARUP's risk posture through metrics and executive reporting concerning information security. In addition to technical and regulatory oversight, the Information Security GRC Supervisor leads and mentors a team of compliance professionals, drives continuous improvement of governance processes, and partners across the organization to embed risk management and security accountability into daily operationssupporting ARUP's mission to protect clinical, laboratory, and enterprise systems.

About ARUP:

ARUP Laboratories is a national clinical and anatomic pathology reference laboratory and an enterprise of the University of Utah and its Department of Pathology. Based in Salt Lake City, Utah.

ARUP proudly hires top talent to create a work environment of diversity, professional growth and continuous development. Our workforce is committed to the important service we provide to over one million patients each month. We always strive for excellence and have a strong desire to have involvement with the advances in medicine and the role laboratory services plays within each patient's life. We never forget that there is a patient behind every specimen we receive.

We are looking for individuals who want to contribute to ARUP's culture of accountability, integrity, service, and excellence. Consider joining our dynamic team.

Essential Functions:

Leads the development, implementation, and continual improvement of ARUP's Information Security Governance, Risk Management, and Compliance (GRC) program, ensuring alignment with ARUP security policies, institutional objectives, and the NIST Risk Management Framework (RMF).

Serves as a primary educator and change agent for the organization, responsible for teaching, training, and transitioning ARUP Business Owners, System Owners, and technical teams to operate in compliance with NIST security frameworks and ARUP security policies.

Designs and delivers structured training, workshops, and guidance to help business and system owners understand their security responsibilities, risk ownership, control implementation requirements, and ongoing compliance obligations under NIST SP 800-53.

Conducts and oversees system-level risk assessments, translating technical and regulatory requirements into clear, actionable guidance for business stakeholders.

Leads the development, review, and maintenance of security policies, standards, and procedures, ensuring alignment with ARUP policy, HIPAA, CAP, SOC 2, GDPR, ISO standards, and NIST RMF requirements.

Leads internal audits, compliance reviews, and external audit preparation, including coordination with auditors and facilitation of evidence collection, remediation planning, and executive reporting.

Delivers compliance and governance services to business and system owners, supporting full lifecycle alignment with NIST SP 800-53 controls, enterprise risk governance frameworks, and ARUP security policy requirements.

Collaborates with cross-functional teams (IT, Infrastructure, Applications, and Operations) to integrate risk management and compliance practices into organizational processes, including Configuration Management, Change Management, and Change Approval Board (CAB).

Maintains System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), Security Assessment Reports (SARs), Risk Assessment Reports (RARs), and other required cybersecurity documentation.

Identifies gaps in security controls, recommends risk-based improvements, and oversees the implementation and tracking of corrective actions to closure.

Supports system authorization and accreditation activities, ensuring operational environments meet defined security requirements and governance expectations.

Develops and maintains compliance dashboards, risk metrics, and executive-level reporting to communicate risk posture, compliance status, and trends to leadership concerning information security.

Builds and sustains strong working relationships with System Owners, Authorizing Officials, System Administrators, and business leaders to promote shared accountability for information security risk management.

Leads and mentors a team of information security GRC analysts and cybersecurity professionals, providing clear direction, coaching, and performance oversight.

Leads a Vulnerability Management Team responsible for ARUP's Vulnerability Management Program.

Works under moderate supervision, exercising independent judgment in governance, risk, and compliance decision-making, and may mentor junior team members.

Supports 24-hour operational requirements as needed, including time-sensitive risk assessments, audits, or incident-related governance activities.

Physical and Other Requirements:

Stooping: Bending body downward and forward by bending spine at the waist.

Reaching: Extending hand(s) and arm(s) in any direction.

Mobility: The person in this position needs to occasionally move between work sites and inside the office to access file cabinets, office machinery, etc.

Communication: The person in this position will work in a highly collaborative environment which requires frequent, clear, and professional communication with others.

PPE: Biohazard laboratory environment that requires use of personal protective equipment in accordance with CDC and OSHA regulations and company policies.

ARUP Policies and Procedures: To conduct self in compliance with all ARUP Policies and Procedures.

Sedentary Work: Exerting up to 10 pounds of force occasionally and/or negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects.

Fine Motor Control: Picking, pinching, typing or otherwise working on computer equipment.

Vision: Having close, far, and peripheral visual acuity to perform a variety of tasks such as making general observations of depth and distance.

Qualifications

Education

Required : Bachelor's Degree or better in Computer Science or related field.

Experience

Required : Bachelor's degree in IT, computer science, information security, cybersecurity, or a closely related field 3-5 years of experience in cybersecurity, risk management, compliance within large-scale, complex IT environments Demonstrable experience in risk assessment methodologies, familiarity with healthcare and regulatory frameworks (e.g., HIPAA, SOC2,NIST, FISMA, RMF), and practical knowledge of information security principles and best practices Excellent communication, analytical, and problem-solving skills Demonstrate management skills including: Willingness and ability to collaborate across IT and business units; Proactively communicate with all levels of the organization; Strategic thinking (solves problems for the entire organization)

Preferred

Relevant industry certifications (e.g., CISSP, CISM, CRISC) are highly desirable Project management certification (e.g., PMP) is highly desirable

Licenses & Certifications

Project Management Prof

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.

ARUP Laboratories
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Information Security Governance, Risk, Compliance (GRC) Supervisor / Manager in Salt Lake City, UT vacancy
  • $161.93k - $269.88k

     ...understanding of governance, controls and assurance...  ...Strategy Manager on the Audit & Assurance...  ...or training in information technology,...  ...protection, information security, engineering, or...  ...system audits, risk assessment...  ...362186 Risk, Compliance, and Governance... 
    Suggested
    Full time
    Local area
    Visa sponsorship

    Deloitte

    Salt Lake City, UT
    4 days ago
  • $112k - $210k

     ...OhioAbout the JobAs part of Key’s second line of defense Compliance Risk Management function, the Risk Evaluation and Assurance Program (the...  ...management, internal audit, and/or compliance (e.g. - Certified Information Systems Auditor (CISA), Certified Internal Auditor (CIA),... 
    Suggested
    Full time
    Work at office
    Flexible hours
    Shift work

    KeyBank

    Salt Lake City, UT
    3 days ago
  •  ...Title: In-House Paralegal / Contract & Compliance Manager Hours: Full-time, salaried Location...  ...operational efficiency, mitigate legal risks, and optimize legal processes across a...  ...for fit – Employee disputes ~ TBD: Inform compliance work & support we need. How... 
    Suggested
    Full time
    Contract work
    Temporary work
    Relocation

    Zanskar

    Salt Lake City, UT
    2 days ago
  •  ...internal audit and governance: testing whether a...  ...their audit and risk decisions. We turn...  ...which only works if security is the foundation,...  ...audit, risk, and compliance functions at public...  ...Build and manage your own pipeline,...  ...Experience selling GRC, audit, security,... 
    Suggested

    Petual

    Salt Lake City, UT
    21 days ago
  • $114.1k - $268.18k

     ...currently seeking a Manager to join our Advisory...  ...ServiceNow Identity Governance and Veza implementations...  ...application owners, security teams, business stakeholders...  ...in computer science, information security, information...  ...duties, regulatory compliance requirements, and... 
    Suggested
    H1b
    Local area

    KPMG

    Salt Lake City, UT
    2 days ago
  • $136k - $184k

    Strategic Account Manager - MedicaidHybrid...  ...a member of the Government Programs team, our...  ...proactively identify risks, and develop...  ...operational performance, compliance, and day-to-day...  ....As part of our security requirements, new...  ....com. Information about how Cambia... 
    Full time
    Work at office
    Immediate start
    Work from home
    Relocation
    Flexible hours
    3 days per week

    Cambia Health Solutions

    Salt Lake City, UT
    2 days ago
  • $145k - $165k

     ...Position Overview The Compliance Manager is a member of the FUJIFILM...  ...updated polices to address new risk areas or to improve...  ...documentation in connection with government bids or government contracts...  ...Off #LI-REMOTE EEO Information Fujifilm is committed to... 
    Remote work
    Flexible hours

    FUJIFILM Corporation

    Salt Lake City, UT
    5 days ago
  •  ...Job Description Job Description Job Summary: We are seeking a Manager, Information Security (GRC) to own and mature Neumo's Governance, Risk, and Compliance program. This role is critical to maintaining our SOC 1, SOC 2, and PCI certifications and to raising our... 
    Remote job
    Work at office
    Local area

    Neumo Holdings LLC

    West Jordan, UT
    4 days ago
  • $155.17k - $317.88k

     ...revolutionizing how tax is managed and how tax...  ...core responsibilities of compliance, reporting and planning...  ...agile resourcing models, risk, provision and...  ...Solutions DeveloperCertified Secure Software Lifecycle Professional...  ...subject to the rules governing the program, whereby... 
    Work at office

    Deloitte

    Salt Lake City, UT
    1 day ago
  • $135.3k - $183.91k

     ...protect private and personally identifiable information you submit. The information that you...  ...Description:At Regions, the Business Unit Compliance Function Manager operates as a first, second, or third line of defense risk management expert that advises on business... 
    Full time
    For contractors
    Work at office
    Flexible hours
    3 days per week

    Regions Financial

    Salt Lake City, UT
    11 hours ago
  • $120k - $140k

     ...leadership and client to manage expectations and...  ...the confidence to secure a seat at the table...  ...cost optimization, risk mitigation, governance, and innovation across...  ...Ensure documentation, compliance, and governance...  ...stakeholders via formal and informal conversations/... 
    Daily paid
    Contract work
    Temporary work
    Local area
    Remote work

    JLL

    Salt Lake City, UT
    5 days ago
  •  ...Blue Cross NC is seeking a Manager of Healthcare Category Management to lead strategic sourcing and vendor governance for critical healthcare categories. You will guide a high-performing team, shape cost-saving strategies, and ensure contracts align with organizational... 
    Contract work

    Blue Cross and Blue Shield of North Carolina

    Salt Lake City, UT
    3 days ago
  • $210.8k - $281.4k

     ...partner closely with Product, Engineering, Risk, Compliance, and Operations from ideation through...  ...solutions that enable innovation while managing risk responsibly.A Product Launch Co-...  ...helping teams spot issues early, make informed tradeoffs, and navigate the legal and regulatory... 
    Immediate start
    Remote work
    Visa sponsorship

    eBay

    Salt Lake City, UT
    2 days ago
  • $14 per hour

     ...Employee Assistant to Chief Compliance Officer Assist and support the Chief Risk and Compliance Officer...  ...and approval, managing policy website, creating...  ...relationships with the supervisor, team members, faculty...  ..., disability, genetic information, or veteran's status.... 
    Hourly pay
    Part time
    Work at office

    Ensign College

    Salt Lake City, UT
    3 days ago
  • $169.5k

     ...partnering with product management, underwriting,...  ..., and investment governance. Collaborate...  .../pricing/risk management domain...  ...do this job. Compliance Requirement :...  ...access to covered information, cardholder data,...  ...well as all data security guidelines established... 
    For contractors
    Work at office
    Local area

    Highmark Health

    Salt Lake City, UT
    5 days ago
  • We are looking for an experienced GRC Security Manager to lead cybersecurity governance, risk, and compliance efforts for a health-focused organization in West Valley City...  ..., manage third-party exposure, and support informed security decision-making.Responsibilities:• Lead... 
    Contract work

    Robert Half

    West Valley, UT
    1 day ago
  • $99k - $232k

     ...drive insights and make informed business decisions....  ...unique strengths, and managing performance to deliver...  ...OpportunityAs part of the Data Governance team, you will lead...  ...and confirm compliance with standards- Identify...  ...thoughtfully to establish a secure and trusted workplace... 
    Full time
    H1b

    PwC

    Salt Lake City, UT
    3 days ago
  •  ...Position Summary: The Director of Risk Management and Information Security supports the Chief Risk Officer in...  ...credit risk, operational risk, compliance risk, liquidity risk, market risk,...  ...Management (ERM) framework, including risk governance, risk appetite, policies, taxonomy... 
    Monday to Friday
    Weekend work

    Stellantis Financial Services US

    Magna, UT
    7 days ago
  •  ...team leverages methodologies, governance and systems that are unparalleled...  ...a highly motivated Study Manager to join our Metals Project Development...  ...including design reviews and risk analyses, to maximize project value. •    Ensuring compliance with engineering standards,... 
    Local area
    Flexible hours

    Hatch

    Salt Lake City, UT
    12 days ago
  • $92.7k - $125.4k

     ...day, Cambia's dedicated team of Program Managers are living our mission to make health care...  ...pharmacy programs for Medicare program governance and workstream meetings to enhance...  ...Manage program and project teams to identify risks and opportunities across multiple initiatives... 
    Work at office
    Immediate start
    Work from home
    Relocation
    Flexible hours
    3 days per week

    Cambia Health Solutions

    Salt Lake City, UT
    1 day ago
  • $164k - $200k

    Professional Services Commercial Governance & Contract Senior ManagerRole...  ...execution-oriented Senior Manager, Commercial Governance &...  ...strengthens how we manage contractual risk, commercial performance,...  ...commercial, contractual, procurement, compliance, and governance... 
    Contract work
    Temporary work
    Local area

    Slalom

    Salt Lake City, UT
    11 hours ago
  •  ...current and future business objectives.• Partner with HR Management or COE's to evaluate the organization's future...  ...to day-to-day management of employees, reducing legal risks and ensuring regulatory compliance• Expert knowledge of local and federal employment laws... 
    Full time
    Work experience placement
    Work at office
    Local area

    Edwards Lifesciences

    Salt Lake City, UT
    3 days ago
  •  ...delivery firm is hiring a Project Procurement Manager to lead the procurement lifecycle across...  ...that meets scope, cost, schedule, and risk targets.Key ResponsibilitiesImplement...  ...documentation, and ensure alignment with governance requirements.Identify risks, implement corrective... 
    Contract work

    DSJ Global

    Salt Lake City, UT
    4 days ago
  •  ...champion: Team member culture, engagement, and relations; Manage the team member employment files; Talent acquisition –...  ...member experience and retention metrics; and Manage HR compliance risk and ensure regulation compliance. Responsibilities:... 
    Work at office
    Remote work
    Monday to Friday
    Shift work

    Red Stag Fulfillment

    Salt Lake City, UT
    2 days ago
  •  ...receive an alert: Contracts Manager Date: Jan 9, 2026 Location: Salt...  ...leverages methodologies, governance and systems that are unparalleled...  ...in contracts andensuring compliance with the terms and conditions...  ...related performance and minimizing risk. The Site Contracts Manager... 
    Contract work
    For contractors
    Local area

    Hatch Ltd.

    Salt Lake City, UT
    4 days ago
  •  ...future with Qualus as a Client Manager in our Commercial and...  ...modernization, resiliency, security, and sustainability. The firm...  ...industrial, data center, and government clients, and renewable and energy...  ...or sensitive personal information, such as Social Security numbers... 
    Contract work
    Temporary work
    Flexible hours

    Qualus

    Salt Lake City, UT
    4 days ago
  • $134k - $348.5k

     ...SummaryAt PwC, our people in risk and compliance focus on maintaining regulatory compliance and managing risks for clients, providing...  ...recommendations to help businesses make informed decisions and mitigate...  ...driving business growth and secure client satisfaction. As a... 
    Full time
    Temporary work
    H1b

    PwC

    Salt Lake City, UT
    11 hours ago
  • $157.5k - $205k

     ...’ll be responsible for:As Manager, GRM AI Transformation, you...  ...of how Circle’s Global Risk Management (GRM) organization...  ...process owners across compliance, financial crime, security, financial risk, and enterprise...  ...with appropriate governance, controls, and guardrails... 
    Flexible hours
    Shift work

    Circle

    Salt Lake City, UT
    3 days ago
  •  ...continental U.S.The Director, Security Engineering is responsible for...  ...platforms supporting Optiv's Managed Security Services (MSS) and Advanced...  ....Stay abreast of evolving risks, platform capabilities, and...  ...partners, and industry peers to inform engineering and operations processes... 
    Full time
    Work experience placement
    Local area
    Remote work
    Work from home

    Optiv

    Salt Lake City, UT
    3 days ago
  • $102.75k - $150.7k

     ...Strategic Initiatives Project Manager in the Mods and Upgrades...  ...implementation plans, manage risks, and ensure successful delivery...  ...timeline commitments.Establish governance frameworks and facilitate decision...  ...in Business, Engineering, Information Technology, Operations... 
    Full time
    Local area
    Immediate start

    Dematic

    Salt Lake City, UT
    11 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Information Security Governance, Risk, Compliance (GRC) Supervisor / Manager. Be the first to apply!