> Markdown version of [/jobs/ext/1896131-manager-of-cybersecurity-grc](https://www.wearedevelopers.com/jobs/ext/1896131-manager-of-cybersecurity-grc). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Manager of Cybersecurity GRC - **Company:** Kforce Inc. - **Location:** Salt Lake City, UT, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cyber Security, Information Systems, Information Systems Security Architecture Professional, PCI Data Security Standards, Cyber Threat Analysis - **Published:** August 1, 2026 - **Apply:** https://www.kforce.com/find-work/search-jobs/#/detail/MTY5Nn5XUUd-MjE4NDAyOVAxfjk5/ ## About the Role Preferred Certifications: * CISSP (Certified Information Systems Security Professional) * CISM (Certified Information Security Manager) * CRISC (Certified in Risk and Information Systems Control) * CDPSE (Certified Data Privacy Solutions Engineer) * 5+ years of experience in cybersecurity governance, risk management, compliance, or information security leadership * Experience conducting enterprise risk assessments and developing risk mitigation strategies * Proven success creating and maintaining cybersecurity policies, standards, and governance frameworks * Experience managing security awareness and training programs * Strong understanding of audit processes and regulatory compliance requirements * Experience supporting compliance efforts related to PCI-DSS, GDPR, CCPA, SOX, or similar frameworks Desired: * Strong knowledge of cybersecurity control frameworks including NIST CSF, NIST 800-series, ISO 27001, and PCI-DSS * Expertise in cybersecurity risk identification, assessment, reporting, and remediation planning * Experience managing third-party and vendor cybersecurity risk programs * Familiarity with AI governance, emerging technology risks, and security implications of AI adoption * Knowledge of privacy regulations and data protection standards * Strong analytical, organizational, and problem-solving capabilities * Excellent verbal and written communication skills with the ability to engage both technical and non-technical stakeholders * Ability to build relationships and influence cross-functional teams across technology, legal, privacy, audit, and business functions Preferred: * Experience leading enterprise GRC programs, partnering with audit and compliance organizations, and operating within regulated environments will be highly successful in this role * Experience developing cybersecurity metrics, vendor risk programs, and privacy-focused security initiatives is strongly preferred ## Description Kforce's client in Salt Lake City, UT is seeking an experienced Cybersecurity Governance, Risk & Compliance (GRC) Manager to lead enterprise cybersecurity risk management, compliance initiatives, and governance programs. This individual will play a key role in strengthening the organization's security posture by overseeing risk assessments, policy development, regulatory compliance efforts, vendor security reviews, security awareness programs, and cybersecurity reporting. Key Responsibilities: * Lead enterprise cybersecurity governance and risk management initiatives * Conduct ongoing risk assessments to identify threats, vulnerabilities, and emerging cybersecurity concerns * Develop, maintain, and execute risk treatment and mitigation plans aligned with business objectives * Monitor organizational risk exposure and communicate risk findings to leadership and stakeholders * Ensure alignment with industry standards, regulatory requirements, and internal controls * Develop and maintain cybersecurity policies, standards, procedures, and governance frameworks * Evaluate and update security documentation to align with evolving threats, business needs, and regulatory expectations * Partner with business units to drive policy adoption, awareness, and compliance throughout the organization * Design and manage enterprise-wide cybersecurity awareness programs * Deliver training initiatives focused on security best practices, compliance obligations, and emerging cyber threats * Measure program effectiveness and continuously improve awareness efforts based on risk trends and organizational needs * Serve as a primary cybersecurity contact for internal and external audit activities * Coordinate audit responses, remediation efforts, and compliance reporting * Support payment card industry (PCI) compliance programs and ensure ongoing adherence to applicable requirements ## Related Videos - [Forecasting Cyber Attacks with Glassdoor Reviews - Lianne Potter](https://www.wearedevelopers.com/videos/2143-forecasting-cyber-attacks-with-glassdoor-reviews-lianne-potter) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j)