Back to jobs
Swire Coca-Cola, USA

Cybersecurity GRC Engineer

Draper, Ut, USPosted Yesterday
onsite

Job Description

What does a Cybersecurity GRC Engineer do at Swire Coca - Cola?Swire Coca-Cola is seeking a Cybersecurity GRC Engineer to support the execution and continuous improvement of our governance, risk, and compliance (GRC) program. This role works under the direction of the GRC Manager and is responsible for performing day-to-day risk, compliance, and audit activities that ensure our cybersecurity program remains aligned with regulatory, contractual, and business requirements. The GRC Engineer plays a critical role in operationalizing cybersecurity governance by conducting risk assessments, supporting audits, maintaining control frameworks, and partnering across IT and business teams to track and remediate findings. This role requires a detail-oriented and analytical individual who can translate technical controls and risks into clear documentation and actionable insights.Responsibilities Perform cybersecurity risk assessments for systems, applications, and business processes Support third-party/vendor risk assessments and due diligence reviews Identify control gaps, document risks, and assist in developing remediation plans Maintain and update the enterprise risk register, including risk scoring and tracking Partner with control owners to validate mitigation efforts and risk status Support internal and external audits by coordinating evidence collection and responses Track audit findings, remediation activities, and validate closure Assist with security questionnaires, RFP responses, and due diligence requests Help ensure compliance with regulatory and contractual requirements Maintain and update cybersecurity policies, standards, and procedures Support mapping of controls to frameworks such as NIST CSF, ISO 27001, and CIS Assist in the development and maintenance of a unified control framework Support control testing activities and documentation of effectiveness Develop and maintain GRC metrics, dashboards, and reporting artifacts Track key risk indicators (KRIs), audit trends, and remediation progress Prepare reports and summaries for leadership and stakeholders Maintain organized documentation and evidence repositories Partner with cross-functional teams to drive risk awareness and remediation efforts Support process improvements to enhance GRC efficiency and scalability Assist in implementing and optimizing GRC tools and automation Stay current on cybersecurity risks and compliance requirements Performs other duties as assigned. Requirements Bachelor’s Degree in Cybersecurity, Information Technology, Risk Management, or related field required Relevant certifications such as Security+, CISA, CRISC, or similar preferred 3+ years of experience in cybersecurity, risk, compliance, or audit roles required Experience supporting audits, risk assessments, and compliance activities required Experience collaborating across IT and business teams required Working knowledge of NIST CSF, ISO 27001, and CIS frameworks Strong analytical, documentation, and organizational skills Ability to communicate technical concepts to non-technical stakeholders Familiarity with GRC tools such as ServiceNow GRC, Archer, Drata, Vanta, or similar preferred

See Your Match Score

Sign up and Renata will show you how this job matches your skills and experience.

Get Started Free
Cybersecurity GRC Engineer at Swire Coca-Cola, USA | Renata