1

Governance Risk Compliance Jobs in Michigan (NOW HIRING)

Maintain security documentation within Governance, Risk, and Compliance (GRC) tools. Required Qualifications * 1-3 years of experience in Information Security, Cybersecurity, IT Compliance, Risk ...

The system security plans are documented in the Governance, Risk, Compliance tool. This requires close coordination with IT project teams, tech leads, business and enterprise security representatives ...

New

AI Governance Manager

Detroit, MI · On-site

$99K - $297K/yr

Responsibilities - Leading the development and implementation of governance frameworks to manage risk and compliance for clients - Analyzing complex regulatory landscapes to provide strategic advice ...

AI Governance Sr Associate

Detroit, MI · On-site

$72K - $212K/yr

In this role, you will be part of our Risk and Compliance team, where you will leverage your skills ... Applying risk governance methodologies to enhance internal controls and mitigate risks ...

Be Seen First

Senior IT Auditor

Detroit, MI · On-site

$43 - $49/hr

Top 3 Required Skills/Experience * 4-5 years of experience in IT Compliance, IT Assessments, and/or IT Audit, with knowledge of Governance, Risk, and Compliance (GRC). * Knowledge of security and ...

New

Showing results 21-40

Governance Risk Compliance information

See Michigan salary details

$27.5K

$59.9K

$97.6K

How much do governance risk compliance jobs pay per year?

As of Aug 8, 2026, the average yearly pay for governance risk compliance in Michigan is $59,906.00, according to ZipRecruiter salary data. Most workers in this role earn between $42,700.00 and $75,400.00 per year, depending on experience, location, and employer.

What are jobs in governance risk compliance?

Governance risk compliance (GRC) is a method for managing and strategizing an organization's regulations regarding governance, financial or physical risk, and regulatory compliance. It aligns the IT aspects with business objectives and works to improve the efficiency of a company. There are GRC consultants and GRC analysts who provide an assessment of a business’s GRC, identify risks, analyze the data, develop policies to benefit the workplace, and consult on the best choice of action. Your duties may involve optimizing GRC systems, implementing tactics to lower risk, providing internal audits, assisting with cybersecurity, creating routine reports, and ensuring regulatory compliance.

What is the work of governance risk compliance?

Governance, Risk, and Compliance (GRC) professionals develop and implement policies to ensure organizations adhere to legal and regulatory requirements, manage risks, and maintain ethical standards. They analyze business processes, conduct audits, and use tools like risk management software to identify vulnerabilities and ensure compliance across departments.

What is governance risk compliance?

Governance, Risk, and Compliance (GRC) is a coordinated strategy that organizations use to manage overall governance, enterprise risk management, and compliance with regulations and standards. GRC professionals help organizations align their business objectives with risk management practices and regulatory requirements. This role involves identifying potential risks, implementing policies to mitigate those risks, and ensuring that the organization adheres to legal, ethical, and internal standards. Effective GRC management can improve decision-making, optimize processes, and protect the organization from financial or reputational harm.

How does a governance risk compliance professional typically collaborate with other departments within an organization?

GRC professionals work closely with a variety of departments, including IT, legal, finance, and operations, to ensure that organizational policies and regulatory requirements are consistently met. Collaboration often involves leading risk assessments, facilitating compliance training, and coordinating audits to identify and mitigate potential risks. Effective communication and relationship-building are key, as GRC teams must translate complex regulations into actionable steps for different business units. This cross-functional approach helps embed a culture of compliance and risk awareness throughout the organization.

What is the difference between Governance Risk Compliance vs Risk Analyst?

AspectGovernance Risk ComplianceRisk Analyst
CertificationsCRISC, CISA, CISSPCFA, FRM, CRISC
Work EnvironmentCorporate, regulated industriesFinancial, consulting firms
Employer & Industry UsageFinancial institutions, healthcare, governmentBanking, investment firms, insurance

Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing enterprise-wide risks. Risk Analysts primarily assess specific financial or operational risks through data analysis. While both roles involve risk management, Governance Risk Compliance has a broader scope related to organizational compliance and governance frameworks, whereas Risk Analysts concentrate on analyzing and quantifying particular risks.

What are the key skills and qualifications needed to thrive as a governance risk compliance professional?

To thrive as a Governance Risk Compliance professional, you need a solid understanding of regulatory frameworks, risk management principles, and policy development, often supported by a degree in business, law, or information security. Familiarity with GRC software platforms, compliance management systems, and certifications like CISA, CRISC, or CISSP is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills set top performers apart in this field. These competencies are essential for ensuring organizational compliance, minimizing risks, and maintaining robust corporate governance.
What are the most commonly searched types of Governance Risk Compliance jobs in Michigan? The most popular types of Governance Risk Compliance jobs in Michigan are:
What are popular job titles related to Governance Risk Compliance jobs in Michigan? For Governance Risk Compliance jobs in Michigan, the most frequently searched job titles are:
What job categories do people searching Governance Risk Compliance jobs in Michigan look for? The top searched job categories for Governance Risk Compliance jobs in Michigan are:
What cities in Michigan are hiring for Governance Risk Compliance jobs? Cities in Michigan with the most Governance Risk Compliance job openings:
Infographic showing various Governance Risk Compliance job openings in Michigan as of August 2026, with employment types broken down into 1% As Needed, 84% Full Time, 11% Part Time, and 4% Contract. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution, with an average salary of $59,906 per year, or $28.8 per hour.

IT Security Analyst

SystemDomain, Inc.

Lansing, MI • On-site

Other

Posted 4 days ago


Job description

Job Title: IT Security Analyst II (Compliance & GRC)

Location: Lansing, MI (Hybrid as Required)
Job Type: Contract
Duration: Long-Term

Job Summary

We are seeking an experienced IT Security Analyst II to support enterprise security compliance initiatives by developing, maintaining, and validating System Security Plans (SSPs) and assisting with the Authority to Operate (ATO) process. The ideal candidate will collaborate with project teams, business stakeholders, cybersecurity teams, and technical staff to ensure applications and systems comply with NIST standards, State security policies, and governance requirements.

Key Responsibilities
  • Develop, maintain, and update System Security Plans (SSPs) for new and existing enterprise applications.

  • Coordinate with Automation Managers, System Owners, Security Administrators, Product Owners, and project teams throughout the Secure SDLC.

  • Support Authority to Operate (ATO) activities and security accreditation processes.

  • Conduct security risk assessments and document security control implementations.

  • Perform security compliance reviews and validate adherence to NIST security controls.

  • Coordinate vulnerability assessments, security scans, and remediation activities with cybersecurity teams.

  • Monitor Plans of Action & Milestones (POA&M) and corrective action plans.

  • Assist with system registration and data classification activities.

  • Collect and review security artifacts required for compliance audits and assessments.

  • Collaborate with vendors, technical leads, and business stakeholders to satisfy security documentation requirements.

  • Identify security gaps and recommend remediation strategies to improve the organization's security posture.

  • Ensure compliance with State security policies, standards, and best practices.

  • Maintain security documentation within Governance, Risk, and Compliance (GRC) tools.


Required Qualifications
  • 1-3 years of experience in Information Security, Cybersecurity, IT Compliance, Risk Management, or Governance.

  • Experience creating or maintaining System Security Plans (SSPs).

  • Knowledge of NIST Cybersecurity Framework and NIST 800-53 security controls.

  • Understanding of Authority to Operate (ATO) processes.

  • Experience performing security risk assessments and compliance reviews.

  • Knowledge of vulnerability management and security scanning processes.

  • Strong analytical, documentation, and problem-solving skills.

  • Excellent written and verbal communication skills.

  • Ability to collaborate effectively with technical and business teams.


Preferred Skills
  • Experience with Governance, Risk & Compliance (GRC) platforms.

  • Knowledge of Secure Software Development Lifecycle (Secure SDLC).

  • Familiarity with vulnerability scanning tools.

  • Experience with enterprise security documentation and audit preparation.

  • Understanding of data classification and security governance.

  • Experience supporting government or public sector security compliance initiatives.


Education
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Computer Information Systems, Networking, Mathematics, or a related discipline.

  • Associate degree in a related technical field with at least two (2) years of relevant IT experience.

  • High School Diploma/GED with at least three (3) years of relevant IT experience.

  • Relevant IT certifications may be considered in lieu of educational requirements.


Desired Certifications
  • Security+

  • CISSP (Preferred)

  • CISM

  • CISA

  • CAP

  • GSEC

  • Certified Cybersecurity (CC)