ARUP Laboratories

Information Security Governance, Risk, Compliance (GRC) Supervisor

ARUP Laboratories$90K — $120K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in Information Security Governance, Risk, and Compliance (GRC) or related area
  • In-depth knowledge of NIST Risk Management Framework (RMF) and NIST SP 800-53
  • Proficiency in risk assessment methodologies and compliance frameworks (HIPAA, CAP, SOC 2, GDPR, ISO standards)
  • Strong interpersonal and communication skills for training and mentoring
  • Ability to lead and inspire a team of compliance professionals
  • Experience with executive reporting and metrics development
  • Relevant security certifications (CISSP, CISM, or equivalent) desirable

Responsibilities

  • Lead the development and enhancement of the GRC program to align with security policies and regulatory requirements
  • Educate and train business and system owners on compliance with security frameworks
  • Deliver structured workshops and guidance on risk ownership and control implementation
  • Conduct system-level risk assessments and translate requirements into actionable guidance
  • Oversee internal audits and manage relationships with external auditors for compliance activities
  • Maintain cybersecurity documentation such as System Security Plans and Risk Assessment Reports
  • Build strong partnerships with IT and business teams to integrate security into operations

Benefits

  • Health, vision, and dental insurance
  • 401(k) retirement plan with company match
  • Generous paid time off policy
  • Professional development and training opportunities
  • Collaborative work environment with a focus on continuous improvement
Full Job Description
Schedule:
Monday - Friday (40 hrs/wk)
8:00 AM - 5:00 PM

Department: IT General - 210

Primary Purpose:

The Information Security Governance, Risk, and Compliance (GRC) Supervisor at ARUP provides leadership and direction for the Information Security GRC program, ensuring alignment with ARUP security policies, healthcare regulatory requirements, and the NIST Risk Management Framework. This role serves as a critical bridge between information security, technology teams, and business owners-translating regulatory and technical security requirements into practical, actionable guidance. The Information Security GRC Supervisor is responsible for educating, training, and transitioning ARUP Business Owners and System Owners to operate in compliance with NIST security standards and ARUP security policies. This role leads risk assessments, compliance activities, audits, and governance processes while delivering clear visibility into ARUP's risk posture through metrics and executive reporting concerning information security. In addition to technical and regulatory oversight, the Information Security GRC Supervisor leads and mentors a team of compliance professionals, drives continuous improvement of governance processes, and partners across the organization to embed risk management and security accountability into daily operations-supporting ARUP's mission to protect clinical, laboratory, and enterprise systems.

Essential Functions:

Leads the development, implementation, and continual improvement of ARUP's Information Security Governance, Risk Management, and Compliance (GRC) program, ensuring alignment with ARUP security policies, institutional objectives, and the NIST Risk Management Framework (RMF).

Serves as a primary educator and change agent for the organization, responsible for teaching, training, and transitioning ARUP Business Owners, System Owners, and technical teams to operate in compliance with NIST security frameworks and ARUP security policies.

Designs and delivers structured training, workshops, and guidance to help business and system owners understand their security responsibilities, risk ownership, control implementation requirements, and ongoing compliance obligations under NIST SP 800-53.

Conducts and oversees - system-level risk assessments, translating technical and regulatory requirements into clear, actionable guidance for business stakeholders.

Leads the development, review, and maintenance of security policies, standards, and procedures, ensuring alignment with ARUP policy, HIPAA, CAP, SOC 2, GDPR, ISO standards, and NIST RMF requirements.

Leads internal audits, compliance reviews, and external audit preparation, including coordination with auditors and facilitation of evidence collection, remediation planning, and executive reporting.

Delivers compliance and governance services to business and system owners, supporting full lifecycle alignment with NIST SP 800-53 controls, enterprise risk governance frameworks, and ARUP security policy requirements.

Collaborates with cross-functional teams (IT, Infrastructure, Applications, and Operations) to integrate risk management and compliance practices into organizational processes, including Configuration Management, Change Management, and Change Approval Board (CAB).

Maintains System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), Security Assessment Reports (SARs), Risk Assessment Reports (RARs), and other required cybersecurity documentation.

Identifies gaps in security controls, recommends risk-based improvements, and oversees the implementation and tracking of corrective actions to closure.

Supports system authorization and accreditation activities, ensuring operational environments meet defined security requirements and governance expectations.

Develops and maintains compliance dashboards, risk metrics, and executive-level reporting to communicate risk posture, compliance status, and trends to leadership concerning information security.

Builds and sustains strong working relationships with System Owners, Authorizing Officials, System Administrators, and business leaders to promote shared accountability for information security risk management.

Leads and mentors a team of information security GRC analysts and cybersecurity professionals, providing clear direction, coaching, and performance oversight.

Leads a Vulnerability Management Team responsible for ARUP's Vulnerability Management Program.

Works under moderate supervision, exercising independent judgment in governance, risk, and compliance decision-making, and may mentor junior team members.

Supports 24-hour operational requirements as needed, including time-sensitive risk assessments, audits, or incident-related governance activities.

Physical and Other Requirements:

Stooping: Bending body downward and forward by bending spine at the waist.

Reaching: Extending hand(s) and arm(s) in any direction.

Mobility: The person in this position needs to occasionally move between work sites and inside the office to access file cabinets, office machinery, etc.

Communication: The person in this position will work in a highly collaborative environment which requires frequent, clear, and professional communication with others.

PPE: Biohazard laboratory environment that requires use of personal protective equipment in accordance with CDC and OSHA regulations and company policies.

ARUP Policies and Procedures: To conduct self in compliance with all ARUP Policies and Procedures.

Sedentary Work: Exerting up to 10 pounds of force occasionally and/or negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects.

Fine Motor Control: Picking, pinching, typing or otherwise working on computer equipment.

Vision: Having close, far, and peripheral visual acuity to perform a variety of tasks such as making general observations of depth and distance.

About ARUP Laboratories

ARUP Laboratories is a national clinical and anatomic pathology reference laboratory and a worldwide leader in innovative laboratory research and development. ARUP offers an extensive lab testing menu of highly complex and unique medical tests in clinical and anatomic pathology. Owned by the University of Utah, ARUP Laboratories' clients include more than half of the nation's university teaching hospitals and children's hospitals, as well as multihospital groups, major commercial laboratories, group purchasing organizations, military and government facilities, and major clinics. In addition, ARUP is a worldwide leader in innovative laboratory research and development, led by the efforts of the ARUP Institute for Clinical and Experimental Pathology®.
Learn more about ARUP Laboratories
Size
4,000 employees
Industry
Founded
1983

Similar Jobs

More Jobs at ARUP Laboratories

More Information Technology Jobs

Find similar Information Security Governance, Risk, Compliance (GRC) Supervisor jobs: