Salt Lake City, UTremote

Salary
Posted
Jul 14, 2026
Location
Salt Lake City, UT
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A mid-level GRC-focused security role centered on vendor risk assessments, compliance audit support (SOC 2 and ISO 27001), and responding to customer security questionnaires. Day-to-day work includes tracking compliance evidence, delivering security awareness training, maintaining metrics, and collaborating with non-technical and technical teams to close control gaps. Suits candidates with a background in third-party risk management and familiarity with common security frameworks.

Mid level · 3+ years · Remote · Bachelor's required · Full-time

Must have (4)
GRC · 3+ yrsSOC 2ISO 27001NIST 800-53
Nice to have (3)
AWS, GCP or AzureCRISC, CISSP, Cisa, Sscp, Security+ or Cysa+AI tools

“or” means any one of them counts — you don't need all of them.

Posted 5 times — it's one opening, so apply once.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 5,500 people nationally plausibly meet what this posting asks for (information security analysts). range 2,300–8,300

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What won't set you apart
NIST 800-5340%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (8)

The role is hybrid/remote-eligible per Lucid's stated hybrid policy; the primary office is in South Jordan, UT (Salt Lake City metro).

The 3+ years requirement is explicitly tied to 'third party risk management, GRC, customer due diligence, etc.' — captured as both overall years minimum and the years demanded on those skills.

NIST 800-53, ISO 27001, and SOC 2 are listed together under Requirements as examples of 'common security frameworks'; all three are treated as hard gates since they appear in the required section.

Cloud platform familiarity (AWS, GCP, Azure) appears only under Preferred Qualifications.

Certifications (CRISC, CISSP, CISA, SSCP, CC, Security+, CySA+) are explicitly listed as preferred; CC is omitted as a named alternative because it is ambiguous without further context, but the others are captured.

AI tools for workflow automation is listed under Preferred Qualifications with no specific product named.

Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): Third-Party Risk Management.

This posting reads as a fully-remote role, so it was scored against the national candidate pool rather than a single metro.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗