1

Governance Risk And Compliance Analyst Jobs in Michigan

About the Role As a member of the Information Security team, the IS GRC - Risk & Compliance Senior Analyst will support the firm's Governance, Risk, and Compliance (GRC) program by managing security ...

268-2 IT Security Compliance Analyst

Lansing, MI ยท On-site

$95K - $95K/yr

The Compliance Analyst is responsible for completing and maintaining System Security Plans (SSPs) for new and existing systems, documented within a Governance, Risk, and Compliance (GRC) tool. This ...

268-2 IT Security Compliance Analyst

Lansing, MI ยท On-site

$95K - $95K/yr

The Compliance Analyst is responsible for completing and maintaining System Security Plans (SSPs) for new and existing systems, documented within a Governance, Risk, and Compliance (GRC) tool. This ...

268-2 IT Security Compliance Analyst

Lansing, MI ยท On-site

$95K - $95K/yr

The Compliance Analyst is responsible for completing and maintaining System Security Plans (SSPs) for new and existing systems, documented within a Governance, Risk, and Compliance (GRC) tool. This ...

The system security plans are documented in the Governance, Risk, Compliance tool. This requires ... Compliance Analysts are assigned resources for DTMB development projects. Compliance Analysts are ...

next page

Showing results 1-20

Governance Risk And Compliance Analyst information

See Michigan salary details

$13

$35

$57

How much do governance risk and compliance analyst jobs pay per hour?

As of Aug 13, 2026, the average hourly pay for governance risk and compliance analyst in Michigan is $35.29, according to ZipRecruiter salary data. Most workers in this role earn between $25.96 and $42.93 per hour, depending on experience, location, and employer.

What is the difference between Governance Risk And Compliance Analyst vs Compliance Analyst?

AspectGovernance Risk And Compliance AnalystCompliance Analyst
CertificationsISO 31000, CRISC, CISAISO 37001, CCEP, CCEP
Work EnvironmentCorporate, financial, or regulatory sectorsHealthcare, finance, manufacturing
Employer & Industry UsageUsed in organizations with complex risk management needsUsed in organizations ensuring regulatory compliance

The Governance Risk And Compliance Analyst focuses on managing overall governance frameworks, assessing risks, and ensuring compliance with policies and regulations. In contrast, the Compliance Analyst primarily concentrates on adhering to specific laws and standards. While both roles require understanding of regulations and certifications, the Governance Risk And Compliance Analyst has a broader scope involving risk management and governance strategies.

What is a Governance Risk and Compliance analyst?

A Governance, Risk, and Compliance (GRC) Analyst is a professional responsible for helping organizations manage risks, ensure compliance with laws and regulations, and implement governance frameworks. They assess internal processes, identify potential risks, and recommend strategies to mitigate those risks. GRC Analysts also develop and monitor policies to ensure that business operations align with regulatory requirements and industry standards. Their work is essential in protecting an organization from financial, legal, and reputational harm.

What are the key skills and qualifications needed to thrive as a Governance Risk and Compliance analyst, and why are they important?

To thrive as a Governance Risk and Compliance (GRC) Analyst, you need a solid understanding of risk management frameworks, regulatory requirements, and compliance standards, often supported by a degree in information security, business, or a related field. Familiarity with GRC software platforms, risk assessment tools, and certifications such as CISA or CRISC is typically required. Exceptional analytical skills, attention to detail, and strong communication abilities help you effectively interpret regulations and collaborate across departments. These competencies ensure that organizations can identify risks, maintain compliance, and build a strong foundation for operational resilience.

How does a Governance Risk and Compliance analyst typically collaborate with other departments within an organization?

GRC Analysts work closely with various departments such as IT, legal, finance, and operations to ensure that organizational policies and procedures align with regulatory requirements and internal controls. They often facilitate cross-functional meetings to assess risks, discuss compliance gaps, and implement corrective measures. Effective communication and coordination are key, as GRC Analysts must translate complex regulations into actionable steps for different teams, ensuring a unified approach to risk management and compliance throughout the organization.
What are popular job titles related to Governance Risk And Compliance Analyst jobs in Michigan? For Governance Risk And Compliance Analyst jobs in Michigan, the most frequently searched job titles are:
What job categories do people searching Governance Risk And Compliance Analyst jobs in Michigan look for? The top searched job categories for Governance Risk And Compliance Analyst jobs in Michigan are:
What cities in Michigan are hiring for Governance Risk And Compliance Analyst jobs? Cities in Michigan with the most Governance Risk And Compliance Analyst job openings:
Infographic showing various Governance Risk And Compliance Analyst job openings in Michigan as of August 2026, with employment types broken down into 1% As Needed, 81% Full Time, 12% Part Time, 1% Temporary, and 5% Contract. Highlights an 91% Physical, 4% Hybrid, and 5% Remote job distribution, with an average salary of $73,397 per year, or $35.3 per hour.

Compliance Analyst - HYBRID (Locals to Lansing, MI)

Chandra Technologies, Inc.

Lansing, MI โ€ข On-site

Other

Posted 8 days ago


Job description

Job Description:

***Crop to Crop resumes are accepted
Location Requirement:  Hybrid: Resource will be working a hybrid schedule. NO REMOTE ONLY OPTION. Will need to be onsite from day 1, two days a week. Tuesdays
and Wednesdays are required onsite days.

Local candidates ONLY. Candidate must be located within 100 miles of Lansing, MI at time of submission.

The Compliance Analyst is responsible for completing and maintaining system security plans (SSP) for new and existing systems. The system security plans are documented in the Governance, Risk, Compliance tool. This requires close coordination with IT project teams, tech leads, business and enterprise security representatives, and product owners, to establish and maintain processes and security controls for systems, and to identify security vulnerabilities and coordinate remediation plans. Compliance Analysts are assigned resources for DTMB development projects. Compliance Analysts are typically not assigned resources and are available for consult, if needed, for Commercial off the Shelf (COTS) procurement phase projects. For COTS implementation phase projects, Compliance Analysts are typically listed resources to navigate SSP/Authority to Operate (ATO) activities with Michigan Cyber Security (MCS) in order to support security requirements to Go Live.

Responsibilities

  • Create SSPs via collaboration with MDOT Automation Managers, System Owners, System Security Administrators, and project team for new applications in alignment with the Secure Application Development Life Cycle and Michigan Security Accreditation Process.
  • Maintain SSPs for existing applications requiring ATO and those facing software and/or hardware enhancements.
  • Collaborate with business representatives to establish system registration.
  • Lead and identify security testing and system scanning requirements.
  • Perform risk assessments and provide responses for security controls.
  • Continuously monitor plans of action and milestones and corrective action plans as they relate to the SSPs in collaboration with the MDOT Enterprise Information Management office.
  • Validate respective SSPs to ensure NIST control requirements are met.
  • Author recommendations associated with findings on how to improve the customerโ€™s security posture in accordance with SOM Policies, Standards, and Procedures, and NIST (National Institute of Standards and Technology) controls.
  • Lead team members and vendors with proper artifact collection to satisfy assessment requirements.
  • Coordination of scanning activities/enterprise activities with MCS, tech leads, and business areas.
  • Lead the system Data Classifications part of the SSP/ATO process. 

Required Skillset

  • 1 to 3 years of experience in the field or in a related area.
  • Has knowledge of commonly used concepts, practices, and procedures within a particular field.
  •  Experience with Keylight is a plus
  • Strong communication and customer service skills
    candidate''s official transcripts or the Cyber Security certificate. This is required.
  • A bachelor''s degree or higher with 21 semester (32 term) credits in computer science, data processing, computer information systems, data communications, networking, systems analysis, computer programming, or mathematics;  or an associate''s degree with 16 semester (24 term) credits in computer science, data processing, computer information systems, data communications, networking, systems analysis, computer programming, mathematics or equivalent; AND at least two years of experience as an application programmer, computer operator, or information technology technician.  
  • A high school diploma, or equivalent education, AND three years of experience as an application programmer, computer operator, or information technology technician. If so, please attach a copy of your official transcripts.
  • IT Certification