1

Cybersecurity Governance Risk Compliance Jobs in Michigan

The system security plans are documented in the Governance, Risk, Compliance tool. This requires close coordination with IT project teams, tech leads, business and enterprise security representatives ...

About the Role As a member of the Information Security team, the IS GRC - Risk & Compliance Senior Analyst will support the firm's Governance, Risk, and Compliance (GRC) program by managing security ...

Working closely with the Global Manager - Governance, Risk & Compliance, the IT Systems Administrator will also support cybersecurity operations through vulnerability management, endpoint security ...

IT Security Analyst 164083

Lansing, MI · Hybrid

$27.59 - $47.59/hr

... cybersecurity, compliance, governance, risk management, or a related field. · Knowledge of System ... Security Plans (SSPs), security governance, and compliance processes. · Familiarity with ...

New

... a collection of cybersecurity capabilities, including security strategy, governance, risk ... compliance requirements. * Support the execution of cybersecurity threat and risk assessments ...

Showing results 21-40

Cybersecurity Governance Risk Compliance information

What is the difference between Cybersecurity Governance Risk Compliance vs Cybersecurity Analyst?

AspectCybersecurity Governance Risk ComplianceCybersecurity Analyst
CertificationsCISA, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentPolicy development, audits, compliance frameworksMonitoring security systems, incident response
Employer & Industry UsageOrganizations with compliance needs, regulatory bodiesIT security teams, cybersecurity firms

While Cybersecurity Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing risks, Cybersecurity Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential in a comprehensive cybersecurity strategy but differ in scope and daily responsibilities.

What are the key skills and qualifications needed to thrive as a cybersecurity governance, risk, and compliance (GRC) professional?

To thrive as a Cybersecurity GRC professional, you need a solid understanding of information security frameworks, risk management principles, and regulatory compliance, often supported by a degree in cybersecurity or related fields. Familiarity with tools like GRC platforms (e.g., Archer, ServiceNow), and certifications such as CISSP, CISM, or CRISC are highly valued. Strong analytical thinking, attention to detail, and effective communication skills help you interpret regulations and collaborate with stakeholders. These skills ensure organizations can manage cybersecurity risks proactively while meeting regulatory and industry standards.

What are some typical challenges faced by professionals in cybersecurity governance, risk, and compliance (GRC) roles?

Professionals in Cybersecurity GRC roles often navigate the challenge of keeping up with rapidly changing regulatory requirements while ensuring company policies align with both business objectives and security best practices. Balancing the need for robust security controls with operational efficiency, educating non-technical stakeholders about risk, and managing audits are common aspects of the job. Additionally, GRC professionals frequently collaborate with IT, legal, and business teams to ensure a cohesive approach to risk management and compliance. This dynamic environment requires strong communication skills, adaptability, and a commitment to continuous learning.

Is cybersecurity governance risk compliance a good career?

Cybersecurity Governance, Risk, and Compliance (GRC) is a growing field that offers opportunities in managing organizational security policies, risk assessments, and regulatory compliance. It requires knowledge of security frameworks, certifications like CISSP or CISM, and strong analytical skills. The role is in demand across various industries due to increasing cybersecurity threats and regulatory requirements.

Is cybersecurity governance risk compliance a good job?

Cybersecurity Governance, Risk, and Compliance (GRC) roles are in high demand due to increasing cybersecurity threats and regulatory requirements. These jobs typically require knowledge of security frameworks, risk management, and compliance standards, offering opportunities for career growth and specialization. They often involve collaboration across departments and may require certifications like CISSP or CISA.

What is cybersecurity governance, risk, and compliance (GRC)?

Cybersecurity Governance, Risk, and Compliance (GRC) refers to a framework used by organizations to align their IT and security strategies with business objectives, manage risks, and ensure compliance with laws and regulations. Governance involves setting policies and procedures, risk focuses on identifying and addressing threats, and compliance ensures adherence to required standards. Professionals in this field help organizations protect sensitive data, avoid regulatory penalties, and build trust with stakeholders. GRC is essential for maintaining effective cybersecurity and demonstrating due diligence.
What are popular job titles related to Cybersecurity Governance Risk Compliance jobs in Michigan? For Cybersecurity Governance Risk Compliance jobs in Michigan, the most frequently searched job titles are:
What job categories do people searching Cybersecurity Governance Risk Compliance jobs in Michigan look for? The top searched job categories for Cybersecurity Governance Risk Compliance jobs in Michigan are:
What cities in Michigan are hiring for Cybersecurity Governance Risk Compliance jobs? Cities in Michigan with the most Cybersecurity Governance Risk Compliance job openings:
Infographic showing various Cybersecurity Governance Risk Compliance job openings in Michigan as of August 2026, with employment types broken down into 67% Full Time, and 33% Contract. Highlights an 100% In-person job distribution.

IT Security Compliance Analyst

Quantam

Lansing, MI • On-site

Full-time

Medical, Retirement, PTO

Posted 4 days ago


Job description

Overview:
Quantam Solutions provides IT solutions and consulting for various clients. We offer competitive hourly wages, health benefits, paid time off, and a 401(k) plan. We are currently seeking a Compliance Analyst. The work schedule is hybrid with two days onsite and three days remote.
Overview:
The Compliance Analyst is responsible for completing and maintaining system security plans (SSP) for new and existing systems. The system security plans are documented in the Governance, Risk, Compliance tool. This requires close coordination with IT project teams, tech leads, business and enterprise security representatives, and product owners, to establish and maintain processes and security controls for systems, and to identify security vulnerabilities and coordinate remediation plans.
Responsibilities:
  • Create SSPs via collaboration with Automation Managers, System Owners, System Security Administrators, and project team for new applications in alignment with the Secure Application Life Cycle and Michigan Security Accreditation Process.
  • Maintain SSPs for existing applications requiring ATO and those facing software and/or hardware enhancements.
  • Collaborate with business representatives to establish system registration.
  • Lead and identify security testing and system scanning requirements.
  • Perform risk assessments and provide responses for security controls.
  • Continuously monitor plans of action and milestones and corrective action plans as they relate to the SSPs in collaboration with the Enterprise Information Management office.
  • Validate respective SSPs to ensure NIST control requirements are met.
  • Author recommendations associated with findings on how to improve the customer's security posture in accordance with Policies, Standards, and Procedures, and NIST (National Institute of Standards and Technology) controls.
  • Lead team members and vendors with proper artifact collection to satisfy assessment requirements.
  • Coordination of scanning activities/enterprise activities with MCS, tech leads, and business areas.
  • Lead the system Data Classifications part of the SSP/ATO process.

Qualifications:
  • 1 to 3 years of experience in the field or in a related area.
  • Has knowledge of commonly used concepts, practices, and procedures within a particular field.
  • A bachelor's degree or higher in related field or an associate's degree in related field; AND at least two years of experience as an application programmer, computer operator, or information technology technician.

Skills:
Governance, Risk & Compliance,System Security Plans,NIST,Risk Assessment,Vulnerability Management