Salt Lake City, UT

Salary
Posted
Jul 9, 2026
Location
Salt Lake City, UT
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A GRC-focused security role centered on third-party vendor risk assessments, SOC 2 and ISO 27001 compliance support, and responding to customer security questionnaires. Day-to-day work also involves security awareness training, metrics tracking, and cross-functional collaboration with teams like Legal, HR, and Engineering. Best suited to someone with 2–3 years in risk management or compliance rather than a technical/engineering security background.

Mid level · 2+ years · Salt Lake City, UT · Bachelor's required · Full-time

Must have (4)
GRCSOC 2ISO 27001NIST 800-53
Nice to have (2)
AWS, GCP or AzureCRISC, CISSP, Cisa, Sscp, Security+ or Cysa+

“or” means any one of them counts — you don't need all of them.

Posted 5 times — it's one opening, so apply once.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 40 people in the Salt Lake City, UT area plausibly meet what this posting asks for (information security analysts). range 20–65

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What won't set you apart
NIST 800-5340%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $105,091 (middle half $79,899–$134,402).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (8)

The job title carries no seniority level; the 2–3 year experience requirement and scope of responsibilities (execution of day-to-day operations, supporting senior team members) support a Mid-level classification.

Lucid Software is headquartered in South Jordan, UT (Salt Lake City CBSA). The posting describes a hybrid role, not fully remote.

The degree requirement is a hard gate: 'Bachelor's degree in information security assurance, business management, or a related field' appears in the Requirements section with no 'or equivalent experience' qualifier.

NIST 800-53, ISO 27001, and SOC 2 are listed together as examples of 'common security frameworks and principles' under Requirements — they are treated as a required familiarity gate rather than separate hard certifications.

Cloud platform familiarity (AWS, GCP, Azure) appears only under Preferred Qualifications and is listed as 'basic understanding' — marked preferred accordingly.

Security certifications (CRISC, CISSP, CISA, SSCP, CC, Security+, CySA+) are explicitly listed as preferred; CRISC is used as the primary name with the others captured as alternatives.

No compensation figures were provided in the posting.

Ignored 2 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): Third-Party Risk Management, Risk Management.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗