Cybersecurity GRC Manager
Salt Lake City, Utah, United States
USANA Health Sciences
About USANASince 1992, USANA has provided the world with the highest-quality products focused on nutritional supplements, skincare, and a healthy lifestyle. But our commitment to excellence goes far beyond our products. USANA is dedicated to share our vision of health by empowering a global family of incredible employees based in more than 20 different markets around the world. Community is at our core. It is our commitment to always strive to be open-minded listeners, hold ourselves and others accountable, be respectful, and celebrate the strength that comes from collaboration. Through initiatives like our Diversity, Equity, and Inclusion Council, we create a company culture where all members of the USANA Family feel cared for, included, and valued. USANA has repeatedly been named one of Utah’s Best Companies to Work For by Utah Business magazine, one of America’s Best Companies to Work For by Outside Magazine, one of the Best Places to Work for in the Direct Selling Industry by Direct Selling News, and named a top employer by Best of State.Position location: Salt Lake City, Utah; hybrid/on-site Who We Are Looking For
We are looking for an experienced individual to join the USANA’s security team as a cybersecurity GRC manager. In this position, you will be responsible for leading and managing the organization’s cybersecurity governance, risk, and compliance (GRC) programs. This role will focus on conducting cyber risk assessments, implementing risk mitigation strategies, developing and enforcing security policies, and overseeing user awareness training. You will also serve as the primary liaison to internal audit teams, work closely on PCI compliance efforts, and assist with the development of key cybersecurity metrics. What You Will Do as USANA’s Cybersecurity GRC Manager
We are looking for an experienced individual to join the USANA’s security team as a cybersecurity GRC manager. In this position, you will be responsible for leading and managing the organization’s cybersecurity governance, risk, and compliance (GRC) programs. This role will focus on conducting cyber risk assessments, implementing risk mitigation strategies, developing and enforcing security policies, and overseeing user awareness training. You will also serve as the primary liaison to internal audit teams, work closely on PCI compliance efforts, and assist with the development of key cybersecurity metrics. What You Will Do as USANA’s Cybersecurity GRC Manager
- Monitor and report on the organization's risk posture, providing regular updates.
- Ensure cybersecurity policies are aligned with industry best practices, regulatory requirements, and organizational goals, and work with USANA business units to ensure policies are understood and enforced
- Design and continually update security awareness training programs to educate employees on best practices, security policies, and compliance requirements
- Oversee PCI compliance initiatives and collaborate with internal teams to ensure adherence to PCI-DSS requirements
- Develop, maintain, and report on key cybersecurity metrics to track the effectiveness of security programs
- Manage the cybersecurity aspects of vendor risk, conducting due diligence, risk assessments, and contract reviews for third-party vendors.
- Identify and mitigate risks associated with adopting and implementing AI technologies within the organization.
- Work closely with the data privacy team to ensure alignment between cybersecurity and data protection requirements, including GDPR, CCPA, and other privacy regulations.
- Collaborate with legal counsel on regulatory compliance and security matters, ensuring legal obligations are met and that risk management strategies are in place
- Bachelor’s degree in Cybersecurity, Information Technology, or a related field
- 5-7 years of experience in cybersecurity governance, risk management, and compliance
- Proven experience in conducting risk assessments, developing security policies, and managing security awareness training
- Experience working with regulatory frameworks such as PCI-DSS, GDPR, CCPA, and SOX
- Strong understanding of cybersecurity frameworks (e.g., NIST, ISO 27001, PCI-DSS)
- Knowledge of AI risks and emerging technologies in cybersecurity
- Experience managing vendor risk, including third-party assessments
- CGRC or equivalent certification is preferred
- Masters Degree
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Job stats:
1
0
0
Categories:
Compliance Jobs
Leadership Jobs
Tags: CCPA CGRC Compliance GDPR Governance ISO 27001 NIST Privacy Risk assessment Risk management SOX
Perks/benefits: 401(k) matching Career development Fitness / gym Health care Insurance Medical leave Parental leave
Region:
North America
Country:
United States
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Information Systems Security Officer jobsInformation System Security Officer jobsSenior Cloud Security Engineer jobsInformation Security Manager jobsSenior Network Security Engineer jobsSenior Cybersecurity Engineer jobsInformation Security Specialist jobsSecurity Consultant jobsSenior Information Security Analyst jobsSenior Penetration Tester jobsSecurity Specialist jobsCyber Security Specialist jobsIT Security Engineer jobsSenior Cyber Security Engineer jobsChief Information Security Officer jobsIT Security Analyst jobsPrincipal Security Engineer jobsInformation System Security Officer (ISSO) jobsStaff Security Engineer jobsCloud Security Architect jobsCyber Security Architect jobsSecurity Operations Analyst jobsSenior Information Security Engineer jobsSystems Administrator jobsThreat Intelligence Analyst jobs
GDPR jobsSaaS jobsForensics jobsEncryption jobsMalware jobsTop Secret jobsEDR jobsSDLC jobsSplunk jobsRMF jobsSQL jobsIDS jobsIPS jobsBash jobsCompTIA jobsIntrusion detection jobsDoDD 8570 jobsDocker jobsThreat detection jobsFinance jobsITIL jobsOWASP jobsTCP/IP jobsTerraform jobsActive Directory jobs
VPN jobsCRISC jobsGIAC jobsUNIX jobsClearance Required jobsIT infrastructure jobsBanking jobsSANS jobsJavaScript jobsPolygraph jobsAnsible jobsHIPAA jobsJira jobsDNS jobsMITRE ATT&CK jobsSOX jobsOSCP jobsCCSP jobsData Analytics jobsMachine Learning jobsSOC 2 jobsSecurity strategy jobsSOAR jobsGCIH jobsCISO jobs