Information Security Governance, Risk, Compliance (GRC) Supervisor / Manager
ARUP Laboratories
Information Security GRC Supervisor
Schedule: Monday - Friday (40 hrs/wk) 8:00 AM - 5:00 PM
Department: IT General - 210
Primary Purpose:
The Information Security Governance, Risk, and Compliance (GRC) Supervisor at ARUP provides leadership and direction for the Information Security GRC program, ensuring alignment with ARUP security policies, healthcare regulatory requirements, and the NIST Risk Management Framework. This role serves as a critical bridge between information security, technology teams, and business ownerstranslating regulatory and technical security requirements into practical, actionable guidance. The Information Security GRC Supervisor is responsible for educating, training, and transitioning ARUP Business Owners and System Owners to operate in compliance with NIST security standards and ARUP security policies. This role leads risk assessments, compliance activities, audits, and governance processes while delivering clear visibility into ARUP's risk posture through metrics and executive reporting concerning information security. In addition to technical and regulatory oversight, the Information Security GRC Supervisor leads and mentors a team of compliance professionals, drives continuous improvement of governance processes, and partners across the organization to embed risk management and security accountability into daily operationssupporting ARUP's mission to protect clinical, laboratory, and enterprise systems.
About ARUP:
ARUP Laboratories is a national clinical and anatomic pathology reference laboratory and an enterprise of the University of Utah and its Department of Pathology. Based in Salt Lake City, Utah.
ARUP proudly hires top talent to create a work environment of diversity, professional growth and continuous development. Our workforce is committed to the important service we provide to over one million patients each month. We always strive for excellence and have a strong desire to have involvement with the advances in medicine and the role laboratory services plays within each patient's life. We never forget that there is a patient behind every specimen we receive.
We are looking for individuals who want to contribute to ARUP's culture of accountability, integrity, service, and excellence. Consider joining our dynamic team.
Essential Functions:
Leads the development, implementation, and continual improvement of ARUP's Information Security Governance, Risk Management, and Compliance (GRC) program, ensuring alignment with ARUP security policies, institutional objectives, and the NIST Risk Management Framework (RMF).
Serves as a primary educator and change agent for the organization, responsible for teaching, training, and transitioning ARUP Business Owners, System Owners, and technical teams to operate in compliance with NIST security frameworks and ARUP security policies.
Designs and delivers structured training, workshops, and guidance to help business and system owners understand their security responsibilities, risk ownership, control implementation requirements, and ongoing compliance obligations under NIST SP 800-53.
Conducts and oversees system-level risk assessments, translating technical and regulatory requirements into clear, actionable guidance for business stakeholders.
Leads the development, review, and maintenance of security policies, standards, and procedures, ensuring alignment with ARUP policy, HIPAA, CAP, SOC 2, GDPR, ISO standards, and NIST RMF requirements.
Leads internal audits, compliance reviews, and external audit preparation, including coordination with auditors and facilitation of evidence collection, remediation planning, and executive reporting.
Delivers compliance and governance services to business and system owners, supporting full lifecycle alignment with NIST SP 800-53 controls, enterprise risk governance frameworks, and ARUP security policy requirements.
Collaborates with cross-functional teams (IT, Infrastructure, Applications, and Operations) to integrate risk management and compliance practices into organizational processes, including Configuration Management, Change Management, and Change Approval Board (CAB).
Maintains System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), Security Assessment Reports (SARs), Risk Assessment Reports (RARs), and other required cybersecurity documentation.
Identifies gaps in security controls, recommends risk-based improvements, and oversees the implementation and tracking of corrective actions to closure.
Supports system authorization and accreditation activities, ensuring operational environments meet defined security requirements and governance expectations.
Develops and maintains compliance dashboards, risk metrics, and executive-level reporting to communicate risk posture, compliance status, and trends to leadership concerning information security.
Builds and sustains strong working relationships with System Owners, Authorizing Officials, System Administrators, and business leaders to promote shared accountability for information security risk management.
Leads and mentors a team of information security GRC analysts and cybersecurity professionals, providing clear direction, coaching, and performance oversight.
Leads a Vulnerability Management Team responsible for ARUP's Vulnerability Management Program.
Works under moderate supervision, exercising independent judgment in governance, risk, and compliance decision-making, and may mentor junior team members.
Supports 24-hour operational requirements as needed, including time-sensitive risk assessments, audits, or incident-related governance activities.
Physical and Other Requirements:
Stooping: Bending body downward and forward by bending spine at the waist.
Reaching: Extending hand(s) and arm(s) in any direction.
Mobility: The person in this position needs to occasionally move between work sites and inside the office to access file cabinets, office machinery, etc.
Communication: The person in this position will work in a highly collaborative environment which requires frequent, clear, and professional communication with others.
PPE: Biohazard laboratory environment that requires use of personal protective equipment in accordance with CDC and OSHA regulations and company policies.
ARUP Policies and Procedures: To conduct self in compliance with all ARUP Policies and Procedures.
Sedentary Work: Exerting up to 10 pounds of force occasionally and/or negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects.
Fine Motor Control: Picking, pinching, typing or otherwise working on computer equipment.
Vision: Having close, far, and peripheral visual acuity to perform a variety of tasks such as making general observations of depth and distance.
Qualifications
Education
Required : Bachelor's Degree or better in Computer Science or related field.
Experience
Required : Bachelor's degree in IT, computer science, information security, cybersecurity, or a closely related field 3-5 years of experience in cybersecurity, risk management, compliance within large-scale, complex IT environments Demonstrable experience in risk assessment methodologies, familiarity with healthcare and regulatory frameworks (e.g., HIPAA, SOC2,NIST, FISMA, RMF), and practical knowledge of information security principles and best practices Excellent communication, analytical, and problem-solving skills Demonstrate management skills including: Willingness and ability to collaborate across IT and business units; Proactively communicate with all levels of the organization; Strategic thinking (solves problems for the entire organization)
Preferred
Relevant industry certifications (e.g., CISSP, CISM, CRISC) are highly desirable Project management certification (e.g., PMP) is highly desirable
Licenses & Certifications
Project Management Prof
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.
ARUP Laboratories$161.93k - $269.88k
...understanding of governance, controls and assurance... ...Strategy Manager on the Audit & Assurance... ...or training in information technology,... ...protection, information security, engineering, or... ...system audits, risk assessment... ...362186 Risk, Compliance, and Governance...SuggestedFull timeLocal areaVisa sponsorship$112k - $210k
...OhioAbout the JobAs part of Key’s second line of defense Compliance Risk Management function, the Risk Evaluation and Assurance Program (the... ...management, internal audit, and/or compliance (e.g. - Certified Information Systems Auditor (CISA), Certified Internal Auditor (CIA),...SuggestedFull timeWork at officeFlexible hoursShift work- ...Title: In-House Paralegal / Contract & Compliance Manager Hours: Full-time, salaried Location... ...operational efficiency, mitigate legal risks, and optimize legal processes across a... ...for fit – Employee disputes ~ TBD: Inform compliance work & support we need. How...SuggestedFull timeContract workTemporary workRelocation
- ...internal audit and governance: testing whether a... ...their audit and risk decisions. We turn... ...which only works if security is the foundation,... ...audit, risk, and compliance functions at public... ...Build and manage your own pipeline,... ...Experience selling GRC, audit, security,...Suggested
$114.1k - $268.18k
...currently seeking a Manager to join our Advisory... ...ServiceNow Identity Governance and Veza implementations... ...application owners, security teams, business stakeholders... ...in computer science, information security, information... ...duties, regulatory compliance requirements, and...SuggestedH1bLocal area$136k - $184k
Strategic Account Manager - MedicaidHybrid... ...a member of the Government Programs team, our... ...proactively identify risks, and develop... ...operational performance, compliance, and day-to-day... ....As part of our security requirements, new... ....com. Information about how Cambia...Full timeWork at officeImmediate startWork from homeRelocationFlexible hours3 days per week$145k - $165k
...Position Overview The Compliance Manager is a member of the FUJIFILM... ...updated polices to address new risk areas or to improve... ...documentation in connection with government bids or government contracts... ...Off #LI-REMOTE EEO Information Fujifilm is committed to...Remote workFlexible hours- ...Job Description Job Description Job Summary: We are seeking a Manager, Information Security (GRC) to own and mature Neumo's Governance, Risk, and Compliance program. This role is critical to maintaining our SOC 1, SOC 2, and PCI certifications and to raising our...Remote jobWork at officeLocal area
$155.17k - $317.88k
...revolutionizing how tax is managed and how tax... ...core responsibilities of compliance, reporting and planning... ...agile resourcing models, risk, provision and... ...Solutions DeveloperCertified Secure Software Lifecycle Professional... ...subject to the rules governing the program, whereby...Work at office$135.3k - $183.91k
...protect private and personally identifiable information you submit. The information that you... ...Description:At Regions, the Business Unit Compliance Function Manager operates as a first, second, or third line of defense risk management expert that advises on business...Full timeFor contractorsWork at officeFlexible hours3 days per week$120k - $140k
...leadership and client to manage expectations and... ...the confidence to secure a seat at the table... ...cost optimization, risk mitigation, governance, and innovation across... ...Ensure documentation, compliance, and governance... ...stakeholders via formal and informal conversations/...Daily paidContract workTemporary workLocal areaRemote work- ...Blue Cross NC is seeking a Manager of Healthcare Category Management to lead strategic sourcing and vendor governance for critical healthcare categories. You will guide a high-performing team, shape cost-saving strategies, and ensure contracts align with organizational...Contract work
$210.8k - $281.4k
...partner closely with Product, Engineering, Risk, Compliance, and Operations from ideation through... ...solutions that enable innovation while managing risk responsibly.A Product Launch Co-... ...helping teams spot issues early, make informed tradeoffs, and navigate the legal and regulatory...Immediate startRemote workVisa sponsorship$14 per hour
...Employee Assistant to Chief Compliance Officer Assist and support the Chief Risk and Compliance Officer... ...and approval, managing policy website, creating... ...relationships with the supervisor, team members, faculty... ..., disability, genetic information, or veteran's status....Hourly payPart timeWork at office$169.5k
...partnering with product management, underwriting,... ..., and investment governance. Collaborate... .../pricing/risk management domain... ...do this job. Compliance Requirement :... ...access to covered information, cardholder data,... ...well as all data security guidelines established...For contractorsWork at officeLocal area- We are looking for an experienced GRC Security Manager to lead cybersecurity governance, risk, and compliance efforts for a health-focused organization in West Valley City... ..., manage third-party exposure, and support informed security decision-making.Responsibilities:• Lead...Contract work
$99k - $232k
...drive insights and make informed business decisions.... ...unique strengths, and managing performance to deliver... ...OpportunityAs part of the Data Governance team, you will lead... ...and confirm compliance with standards- Identify... ...thoughtfully to establish a secure and trusted workplace...Full timeH1b- ...Position Summary: The Director of Risk Management and Information Security supports the Chief Risk Officer in... ...credit risk, operational risk, compliance risk, liquidity risk, market risk,... ...Management (ERM) framework, including risk governance, risk appetite, policies, taxonomy...Monday to FridayWeekend work
- ...team leverages methodologies, governance and systems that are unparalleled... ...a highly motivated Study Manager to join our Metals Project Development... ...including design reviews and risk analyses, to maximize project value. • Ensuring compliance with engineering standards,...Local areaFlexible hours
$92.7k - $125.4k
...day, Cambia's dedicated team of Program Managers are living our mission to make health care... ...pharmacy programs for Medicare program governance and workstream meetings to enhance... ...Manage program and project teams to identify risks and opportunities across multiple initiatives...Work at officeImmediate startWork from homeRelocationFlexible hours3 days per week$164k - $200k
Professional Services Commercial Governance & Contract Senior ManagerRole... ...execution-oriented Senior Manager, Commercial Governance &... ...strengthens how we manage contractual risk, commercial performance,... ...commercial, contractual, procurement, compliance, and governance...Contract workTemporary workLocal area- ...current and future business objectives.• Partner with HR Management or COE's to evaluate the organization's future... ...to day-to-day management of employees, reducing legal risks and ensuring regulatory compliance• Expert knowledge of local and federal employment laws...Full timeWork experience placementWork at officeLocal area
- ...delivery firm is hiring a Project Procurement Manager to lead the procurement lifecycle across... ...that meets scope, cost, schedule, and risk targets.Key ResponsibilitiesImplement... ...documentation, and ensure alignment with governance requirements.Identify risks, implement corrective...Contract work
- ...champion: Team member culture, engagement, and relations; Manage the team member employment files; Talent acquisition –... ...member experience and retention metrics; and Manage HR compliance risk and ensure regulation compliance. Responsibilities:...Work at officeRemote workMonday to FridayShift work
- ...receive an alert: Contracts Manager Date: Jan 9, 2026 Location: Salt... ...leverages methodologies, governance and systems that are unparalleled... ...in contracts andensuring compliance with the terms and conditions... ...related performance and minimizing risk. The Site Contracts Manager...Contract workFor contractorsLocal area
- ...future with Qualus as a Client Manager in our Commercial and... ...modernization, resiliency, security, and sustainability. The firm... ...industrial, data center, and government clients, and renewable and energy... ...or sensitive personal information, such as Social Security numbers...Contract workTemporary workFlexible hours
$134k - $348.5k
...SummaryAt PwC, our people in risk and compliance focus on maintaining regulatory compliance and managing risks for clients, providing... ...recommendations to help businesses make informed decisions and mitigate... ...driving business growth and secure client satisfaction. As a...Full timeTemporary workH1b$157.5k - $205k
...’ll be responsible for:As Manager, GRM AI Transformation, you... ...of how Circle’s Global Risk Management (GRM) organization... ...process owners across compliance, financial crime, security, financial risk, and enterprise... ...with appropriate governance, controls, and guardrails...Flexible hoursShift work- ...continental U.S.The Director, Security Engineering is responsible for... ...platforms supporting Optiv's Managed Security Services (MSS) and Advanced... ....Stay abreast of evolving risks, platform capabilities, and... ...partners, and industry peers to inform engineering and operations processes...Full timeWork experience placementLocal areaRemote workWork from home
$102.75k - $150.7k
...Strategic Initiatives Project Manager in the Mods and Upgrades... ...implementation plans, manage risks, and ensure successful delivery... ...timeline commitments.Establish governance frameworks and facilitate decision... ...in Business, Engineering, Information Technology, Operations...Full timeLocal areaImmediate start
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Information Security Governance, Risk, Compliance (GRC) Supervisor / Manager. Be the first to apply!
- head of risk management Salt Lake City, UT
- risk management specialist Salt Lake City, UT
- risk management manager Salt Lake City, UT
- director of risk management Salt Lake City, UT
- director credit risk Salt Lake City, UT
- risk management associate Salt Lake City, UT
- operational risk manager Salt Lake City, UT
- training and compliance manager Salt Lake City, UT
- compliance manager Salt Lake City, UT
- manager regulatory affairs Salt Lake City, UT


