1

Governance Risk Compliance Jobs in Rochester Hills, MI

About the Role As a member of the Information Security team, the IS GRC - Risk & Compliance Senior Analyst will support the firm's Governance, Risk, and Compliance (GRC) program by managing security ...

AI Governance Manager

Detroit, MI · On-site

$99K - $297K/yr

Responsibilities - Leading the development and implementation of governance frameworks to manage risk and compliance for clients - Analyzing complex regulatory landscapes to provide strategic advice ...

next page

Showing results 1-20

Governance Risk Compliance information

See Rochester Hills, MI salary details

$29K

$63.3K

$103.1K

How much do governance risk compliance jobs pay per year?

As of Aug 8, 2026, the average yearly pay for governance risk compliance in Rochester Hills, MI is $63,264.00, according to ZipRecruiter salary data. Most workers in this role earn between $45,100.00 and $79,600.00 per year, depending on experience, location, and employer.

What are jobs in governance risk compliance?

Governance risk compliance (GRC) is a method for managing and strategizing an organization's regulations regarding governance, financial or physical risk, and regulatory compliance. It aligns the IT aspects with business objectives and works to improve the efficiency of a company. There are GRC consultants and GRC analysts who provide an assessment of a business’s GRC, identify risks, analyze the data, develop policies to benefit the workplace, and consult on the best choice of action. Your duties may involve optimizing GRC systems, implementing tactics to lower risk, providing internal audits, assisting with cybersecurity, creating routine reports, and ensuring regulatory compliance.

What is the work of governance risk compliance?

Governance, Risk, and Compliance (GRC) professionals develop and implement policies to ensure organizations adhere to legal and regulatory requirements, manage risks, and maintain ethical standards. They analyze business processes, conduct audits, and use tools like risk management software to identify vulnerabilities and ensure compliance across departments.

What is governance risk compliance?

Governance, Risk, and Compliance (GRC) is a coordinated strategy that organizations use to manage overall governance, enterprise risk management, and compliance with regulations and standards. GRC professionals help organizations align their business objectives with risk management practices and regulatory requirements. This role involves identifying potential risks, implementing policies to mitigate those risks, and ensuring that the organization adheres to legal, ethical, and internal standards. Effective GRC management can improve decision-making, optimize processes, and protect the organization from financial or reputational harm.

How does a governance risk compliance professional typically collaborate with other departments within an organization?

GRC professionals work closely with a variety of departments, including IT, legal, finance, and operations, to ensure that organizational policies and regulatory requirements are consistently met. Collaboration often involves leading risk assessments, facilitating compliance training, and coordinating audits to identify and mitigate potential risks. Effective communication and relationship-building are key, as GRC teams must translate complex regulations into actionable steps for different business units. This cross-functional approach helps embed a culture of compliance and risk awareness throughout the organization.

What is the difference between Governance Risk Compliance vs Risk Analyst?

AspectGovernance Risk ComplianceRisk Analyst
CertificationsCRISC, CISA, CISSPCFA, FRM, CRISC
Work EnvironmentCorporate, regulated industriesFinancial, consulting firms
Employer & Industry UsageFinancial institutions, healthcare, governmentBanking, investment firms, insurance

Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing enterprise-wide risks. Risk Analysts primarily assess specific financial or operational risks through data analysis. While both roles involve risk management, Governance Risk Compliance has a broader scope related to organizational compliance and governance frameworks, whereas Risk Analysts concentrate on analyzing and quantifying particular risks.

What are the key skills and qualifications needed to thrive as a governance risk compliance professional?

To thrive as a Governance Risk Compliance professional, you need a solid understanding of regulatory frameworks, risk management principles, and policy development, often supported by a degree in business, law, or information security. Familiarity with GRC software platforms, compliance management systems, and certifications like CISA, CRISC, or CISSP is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills set top performers apart in this field. These competencies are essential for ensuring organizational compliance, minimizing risks, and maintaining robust corporate governance.
What cities near Rochester Hills, MI are hiring for Governance Risk Compliance jobs? Cities near Rochester Hills, MI with the most Governance Risk Compliance job openings:
Infographic showing various Governance Risk Compliance job openings in Rochester Hills, MI as of August 2026, with employment types broken down into 1% As Needed, 84% Full Time, 11% Part Time, and 4% Contract. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution, with an average salary of $63,264 per year, or $30.4 per hour.

GRC Analyst

Saanvi Technologies

Southfield, MI • On-site

Contractor

Posted 9 days ago


Job description

About the Role

As a member of the Information Security team, the IS GRC – Risk & Compliance Senior Analyst will support the firm's Governance, Risk, and Compliance (GRC) program by managing security risks, maintaining the risk register, conducting risk assessments, coordinating control testing, and supporting audit activities. The role partners closely with IT leadership, business stakeholders, and third-party vendors to ensure security and compliance objectives are achieved.


Key Responsibilities

Security Risk Management

  • Support the CISO with annual and periodic security risk assessments.
  • Manage and maintain the enterprise risk register.
  • Conduct security risk assessments and evaluate risk and control effectiveness.
  • Track remediation activities through closure and report status to leadership.
  • Interview SMEs and gather information for risk assessments.
  • Develop and support risk mitigation strategies with cross-functional teams.
  • Conduct third-party security risk assessments, including review of:
    • Security questionnaires
    • Supporting documentation
    • Independent audit reports
  • Identify vendor security gaps, assign risk ratings, and recommend mitigations.

Control Framework & Compliance Testing

  • Design, execute, and monitor security control testing.
  • Ensure compliance with contractual, regulatory, and internal security requirements.
  • Partner with IT and business control owners.
  • Prepare audit evidence and documentation for internal and external audits.
  • Report metrics and compliance status to the IS GRC Manager, Director, and CISO.
  • Improve and automate GRC processes where possible.
  • Perform additional responsibilities as assigned.

Required Qualifications

  • Bachelor's degree in Information Technology or a related field (or equivalent experience).
  • 3+ years of professional experience.
  • Experience in one or more of the following:
    • Information Security
    • Governance, Risk & Compliance (GRC)
    • IT Risk
    • Information Technology
    • Audit
  • Experience with security frameworks or regulations such as:
    • ISO 27001
    • SOC 2
    • PCI DSS
    • HIPAA
    • Other global security/compliance standards
  • Strong experience in:
    • Risk assessments
    • Risk registers
    • Control testing
    • Security compliance
    • Third-party/vendor risk management
  • Excellent analytical, communication, and documentation skills.
  • Experience with Microsoft Office Suite.
  • ServiceNow experience is preferred.

Preferred Certifications

  • CISSP (Preferred)
  • CISA (Preferred)
  • CRISC (Nice to have)
  • Willingness to pursue security certifications is highly valued.

Additional Information

  • Core business hours: 8:30 AM – 5:30 PM (Monday–Friday).
  • Occasional work outside standard business hours may be required.
  • Hybrid work schedule:
    • Onsite: Tuesday, Wednesday & Thursday
    • Remote: Monday & Friday
  • No relocation assistance or benefits are provided for this contract position.
Thanking you 
Jeevan@saanvi.us

Saanvi Technologies logo

About Saanvi Technologies

Sourced by ZipRecruiter

Saanvi Technologies is a staffing company that specializes in providing IT professionals to businesses. Our employees are experts in their field, and have the skills and experience necessary to help businesses grow and succeed. Saanvi Technologies is dedicated to helping businesses achieve their goals, and they have a proven track record of success. Our employees are qualified and reliable, and they always go above and beyond to meet the needs of their customers.

Company size

51 - 200 Employees

Headquarters location

Farmington, MI, US

Social media