1

Cybersecurity Governance Risk Compliance Jobs in Michigan

Vice President of Cybersecurity

Detroit, MI ยท Hybrid

$148K - $186K/yr

Governance, Risk & Compliance (GRC) * Lead cybersecurity compliance efforts for government and regulated environments, including NIST 800-53, NIST 800-171, CMMC, and related federal frameworks

Cyber Security Architecture Manager

Detroit, MI ยท On-site

$109K - $148K/yr

... ensure compliance with security frameworks. Responsibilities : โ€ข Lead the design and ... governance, risk management, and secure AI adoption strategies. โ€ข Drive cloud security ...

Director, Information Security Promotion

Southfield, MI ยท On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Governance, Risk & Compliance (GRC) * Establish & maintain company cybersecurity policies and procedures. * Oversee regional cybersecurity governance processes and ensure adherence to enterprise ...

Contract / Requirement: * 1-3 years of experience in IT Security, Cyber Security, Compliance, or a related field. * Knowledge of NIST, System Security Plans (SSP), Governance, Risk & Compliance (GRC ...

next page

Showing results 1-20

Cybersecurity Governance Risk Compliance information

What is the difference between Cybersecurity Governance Risk Compliance vs Cybersecurity Analyst?

AspectCybersecurity Governance Risk ComplianceCybersecurity Analyst
CertificationsCISA, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentPolicy development, audits, compliance frameworksMonitoring security systems, incident response
Employer & Industry UsageOrganizations with compliance needs, regulatory bodiesIT security teams, cybersecurity firms

While Cybersecurity Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing risks, Cybersecurity Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential in a comprehensive cybersecurity strategy but differ in scope and daily responsibilities.

What are the key skills and qualifications needed to thrive as a cybersecurity governance, risk, and compliance (GRC) professional?

To thrive as a Cybersecurity GRC professional, you need a solid understanding of information security frameworks, risk management principles, and regulatory compliance, often supported by a degree in cybersecurity or related fields. Familiarity with tools like GRC platforms (e.g., Archer, ServiceNow), and certifications such as CISSP, CISM, or CRISC are highly valued. Strong analytical thinking, attention to detail, and effective communication skills help you interpret regulations and collaborate with stakeholders. These skills ensure organizations can manage cybersecurity risks proactively while meeting regulatory and industry standards.

What are some typical challenges faced by professionals in cybersecurity governance, risk, and compliance (GRC) roles?

Professionals in Cybersecurity GRC roles often navigate the challenge of keeping up with rapidly changing regulatory requirements while ensuring company policies align with both business objectives and security best practices. Balancing the need for robust security controls with operational efficiency, educating non-technical stakeholders about risk, and managing audits are common aspects of the job. Additionally, GRC professionals frequently collaborate with IT, legal, and business teams to ensure a cohesive approach to risk management and compliance. This dynamic environment requires strong communication skills, adaptability, and a commitment to continuous learning.

Is cybersecurity governance risk compliance a good career?

Cybersecurity Governance, Risk, and Compliance (GRC) is a growing field that offers opportunities in managing organizational security policies, risk assessments, and regulatory compliance. It requires knowledge of security frameworks, certifications like CISSP or CISM, and strong analytical skills. The role is in demand across various industries due to increasing cybersecurity threats and regulatory requirements.

Is cybersecurity governance risk compliance a good job?

Cybersecurity Governance, Risk, and Compliance (GRC) roles are in high demand due to increasing cybersecurity threats and regulatory requirements. These jobs typically require knowledge of security frameworks, risk management, and compliance standards, offering opportunities for career growth and specialization. They often involve collaboration across departments and may require certifications like CISSP or CISA.

What is cybersecurity governance, risk, and compliance (GRC)?

Cybersecurity Governance, Risk, and Compliance (GRC) refers to a framework used by organizations to align their IT and security strategies with business objectives, manage risks, and ensure compliance with laws and regulations. Governance involves setting policies and procedures, risk focuses on identifying and addressing threats, and compliance ensures adherence to required standards. Professionals in this field help organizations protect sensitive data, avoid regulatory penalties, and build trust with stakeholders. GRC is essential for maintaining effective cybersecurity and demonstrating due diligence.

What are popular job titles related to Cybersecurity Governance Risk Compliance jobs in Michigan?

For Cybersecurity Governance Risk Compliance jobs in Michigan, the most frequently searched job titles are:

What job categories do people searching Cybersecurity Governance Risk Compliance jobs in Michigan look for?

The top searched job categories for Cybersecurity Governance Risk Compliance jobs in Michigan are:

What cities in Michigan are hiring for Cybersecurity Governance Risk Compliance jobs?

Cities in Michigan with the most Cybersecurity Governance Risk Compliance job openings:

Infographic showing various Cybersecurity Governance Risk Compliance job openings in Michigan as of August 2026, with employment types broken down into 77% Full Time, 2% Part Time, and 21% Contract. Highlights an 92% In-person, 4% Hybrid, and 4% Remote job distribution.

Compliance and Risk Management Specialist

Epitec

Dearborn, MI โ€ข On-site

$48 - $52/hr

Contractor

Posted 5 days ago


Job description

  • Location: Dearborn, Michigan
  • Type: Contract
  • Job #105842

Compliance & Risk Management Specialist
Location
Dearborn, Michigan (Local Candidates Only)
Schedule
Monday - Friday | Standard Business Hours
Type
Contract | W2 Only
Pay Rate
$48.00 - $52.00/hour W2
Work Authorization
Must be able to work on a W2 basis. No C2C, or third-party vendors.
Relocation
Relocation assistance is not available. Local candidates only.
Duration
12 Month Long Contract (Open-ended)
Summary
We are seeking a Compliance & Risk Management Specialist to support cybersecurity governance, cryptographic key management, supplier compliance, and risk management initiatives within a complex automotive environment. This role serves as a key liaison between cybersecurity, engineering, manufacturing, procurement, suppliers, and infrastructure teams to ensure cybersecurity requirements are implemented and maintained throughout the vehicle development and manufacturing lifecycle.
The ideal candidate will have a strong background in cybersecurity compliance, PKI, key management systems, supplier audits, risk management, and security governance. Experience supporting embedded systems, connected products, or automotive cybersecurity programs is highly preferred.
Key Responsibilities
  • Define cybersecurity and cryptographic requirements for vehicle electronic control units (ECUs) and connected systems.
  • Establish and manage security controls including encryption standards, key lengths, certificate policies, rotation schedules, expiration requirements, and access controls.
  • Support and manage Public Key Infrastructure (PKI) and Key Management Systems (KMS) environments.
  • Ensure secure generation, distribution, storage, and lifecycle management of cryptographic keys and certificates.
  • Partner with engineering teams to integrate cybersecurity controls into products and manufacturing processes.
  • Conduct supplier cybersecurity audits and assessments to verify compliance with organizational security requirements.
  • Identify security gaps, document findings, and drive corrective action plans with suppliers and internal stakeholders.
  • Track supplier compliance metrics and escalate risks, issues, and non-compliance items as necessary.
  • Develop, maintain, and improve cybersecurity governance policies, standards, procedures, and controls.
  • Monitor compliance risks, cybersecurity vulnerabilities, and third-party security exposures.
  • Support third-party cybersecurity risk management programs and supplier security reviews.
  • Troubleshoot issues involving PKI, certificate management, key deployment, and manufacturing integrations.
  • Collaborate with cybersecurity, embedded software, vehicle program teams, manufacturing, procurement, suppliers, and IT infrastructure teams.
  • Maintain audit documentation, compliance records, and reporting materials for leadership and regulatory reviews.
  • Support continuous improvement initiatives related to security governance, compliance, and risk management frameworks.
Required Qualifications
  • Bachelor's degree in Cybersecurity, Information Security, Computer Engineering, Electrical Engineering, Computer Science, or related field.
  • 3+ years of experience in cybersecurity, compliance, governance, risk management, or information security.
  • Experience with Public Key Infrastructure (PKI) and certificate lifecycle management.
  • Experience working with Key Management Systems (KMS).
  • Knowledge of cryptographic technologies, encryption standards, and key management principles.
  • Experience conducting security assessments, supplier audits, or compliance reviews.
  • Strong understanding of cybersecurity governance, risk management, and security control frameworks.
  • Experience identifying, documenting, and remediating security and compliance risks.
  • Strong communication and stakeholder management skills.
  • Ability to work cross-functionally with engineering, cybersecurity, manufacturing, procurement, and supplier organizations.
  • Experience creating policies, procedures, standards, and audit documentation.
Preferred Qualifications
  • Experience supporting automotive, manufacturing, embedded systems, IoT, or connected product environments.
  • Knowledge of automotive cybersecurity standards such as ISO 21434 and UNECE R155.
  • Experience with security frameworks including NIST, ISO 27001, or similar standards.
  • Familiarity with cryptographic platforms and tools such as Thales, Entrust, HashiCorp Vault, AWS KMS, or equivalent technologies.
  • Experience supporting supplier cybersecurity programs and third-party risk management initiatives.
  • Background in embedded software, electronic control units (ECUs), or vehicle security architectures.
  • Relevant certifications such as CISSP, CISM, CRISC, Security+, or similar cybersecurity credentials.

#INDOEM
#LI-JC1