1

Grc Engineer Jobs in Michigan (NOW HIRING)

Network Security engineering * Experience in client facing environments including active ... Governance, Risk, and Compliance (GRC) * Cloud and hosted applications * Containerization

Knowledge of commonly used concepts, practices, and procedures (NIST, SSP, GRC, etc.). * Experience ... Programming, Mathematics, or related fields. * OR Associate's degree with qualifying coursework ...

268-2 IT Security Compliance Analyst

Lansing, MI · On-site

$95K - $95K/yr

... GRC) tool. This role requires close coordination with IT project teams, tech leads, business and ... A high school diploma or equivalent -- plus 3 years of experience as an application programmer ...

268-2 IT Security Compliance Analyst

Lansing, MI · On-site

$95K - $95K/yr

... GRC) tool. This role requires close coordination with IT project teams, tech leads, business and ... A high school diploma or equivalent - plus 3 years of experience as an application programmer ...

... NIST/GRC, testing/scanning, risk assessments experience Location: Lansing MI (DTMB) Duration: 12 ... AND at least two years of experience as an application programmer, computer operator, or ...

Showing results 21-40

Grc Engineer information

See Michigan salary details

$51.9K

$97.3K

$176.9K

How much do grc engineer jobs pay per year?

As of Aug 9, 2026, the average yearly pay for grc engineer in Michigan is $97,298.00, according to ZipRecruiter salary data. Most workers in this role earn between $70,200.00 and $115,500.00 per year, depending on experience, location, and employer.

What is a GRC engineer?

GRC Engineers are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization’s information security and IT frameworks. They help ensure that a company’s policies and procedures meet regulatory requirements, manage risks, and align with business objectives. GRC Engineers often implement and maintain tools, conduct risk assessments, and ensure compliance through audits and reporting. Their role is critical in minimizing risks and protecting organizational assets from security threats.

What are the key skills and qualifications needed to thrive as a GRC engineer?

To thrive as a GRC Engineer, you need a solid understanding of governance, risk management, and compliance frameworks, often supported by a degree in information security or a related field. Familiarity with GRC platforms (such as RSA Archer or ServiceNow GRC), risk assessment tools, and certifications like CISA or CISSP are highly valued. Strong analytical skills, attention to detail, and effective communication are crucial soft skills for collaborating across departments and translating complex requirements. These competencies ensure that organizations can effectively manage risk, maintain regulatory compliance, and safeguard critical information assets.

What are some common challenges faced by GRC engineers when implementing new compliance frameworks?

GRC Engineers often encounter challenges such as integrating new compliance requirements with existing IT systems, ensuring consistent documentation, and keeping up with evolving regulatory standards. Collaboration with various departments—like IT, legal, and operations—is essential to map processes accurately and address potential gaps. Proactive communication and a strong understanding of both technical and regulatory aspects help GRC Engineers overcome these hurdles and support organizational compliance effectively.

How much do GRC engineers make?

GRC (Governance, Risk, and Compliance) engineers typically earn between $80,000 and $130,000 annually, depending on experience, certifications, and location. Senior roles or those with specialized skills in cybersecurity tools and frameworks can earn higher salaries, often exceeding $150,000.

What is the difference between Grc Engineer vs Security Analyst?

AspectGrc EngineerSecurity Analyst
CertificationsISO 27001, CISSP, CISACISSP, CompTIA Security+
Work EnvironmentPolicy development, compliance, risk managementMonitoring, incident response, threat analysis
Industry UsageCorporate governance, compliance teamsSecurity operations centers, IT departments

Grc Engineers focus on establishing and maintaining governance, risk, and compliance frameworks, ensuring organizations meet regulatory standards. Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within the cybersecurity industry, Grc Engineers emphasize policy and compliance, whereas Security Analysts focus on threat detection and response.

Is GRC engineer an entry-level job?

A GRC (Governance, Risk, and Compliance) engineer is typically an intermediate to senior role that requires relevant experience and knowledge of security frameworks, compliance standards, and risk management tools. Entry-level positions in GRC may be available but usually require foundational skills, certifications, or internships to qualify for more advanced roles.
What cities in Michigan are hiring for Grc Engineer jobs? Cities in Michigan with the most Grc Engineer job openings:
Infographic showing various Grc Engineer job openings in Michigan as of August 2026, with employment types broken down into 92% Full Time, 2% Part Time, and 6% Contract. Highlights an 87% Physical, 4% Hybrid, and 9% Remote job distribution, with an average salary of $97,298 per year, or $46.8 per hour.

Cyber Security Engineer- State of MI -164083

MeganSoft

Lansing, MI • On-site

Other

This job post has expired 1 day ago. Applications are no longer accepted.


Job description

Job Title: Cyber Security Engineer- 164083

Duration: 12+ Months

location: Lansing, Michigan - Hybrid

Direct Client: State of Michigan

-2-3 professional references are required. Please attach them in a separate document
-Interview Process: In-person and virtual interviews. 1st round is virtual, 2nd round is in-person. Mix of soft skill and technical skill interviews, looking for somebody with good communication and leadership skills. Interviews will involve the manager, business relationship manager, and potentially other members of the team.
-Candidates MUST be local to Lansing, Michigan area (within 75 miles) at time of submission. This requirement is non-negotiable

Top Skills & Years of Experience:

1 to 3 years of experience in the field or in a related area.

Has knowledge of commonly used concepts, practices, and procedures within the field (NIST, SSP, GRC, etc.)

Experience with Keylight is a plus

Strong communication and customer service skills

Candidates MUST have either a bachelor's degree or higher specific to IT or a Cyber Security certification. You must attach a copy of the candidate's official transcripts or the Cyber Security certificate. This is required.

IT Security Analyst - 2

Role:

The Compliance Analyst is responsible for completing and maintaining system security plans (SSP) for new and existing systems. The system security plans are documented in the Governance, Risk, Compliance tool. This requires close coordination with IT project teams, tech leads, business and enterprise security representatives, and product owners, to establish and maintain processes and security controls for systems, and to identify security vulnerabilities and coordinate remediation plans. Compliance Analysts are assigned resources for DTMB development projects. Compliance Analysts are typically not assigned resources and are available for consult, if needed, for Commercial off the Shelf (COTS) procurement phase projects. For COTS implementation phase projects, Compliance Analysts are typically listed resources to navigate SSP/Authority to Operate (ATO) activities with Michigan Cyber Security (MCS) in order to support security requirements to Go Live.

Responsibilities:

Create SSPs via collaboration with MDOT Automation Managers, System Owners, System Security Administrators, and project team for new applications in alignment with the Secure Application Development Life Cycle and Michigan Security Accreditation Process.

Maintain SSPs for existing applications requiring ATO and those facing software and/or hardware enhancements.

Collaborate with business representatives to establish system registration.

Lead and identify security testing and system scanning requirements.

Perform risk assessments and provide responses for security controls.

Continuously monitor plans of action and milestones and corrective action plans as they relate to the SSPs in collaboration with the MDOT Enterprise Information Management office.

Validate respective SSPs to ensure NIST control requirements are met.

Author recommendations associated with findings on how to improve the customer s security posture in accordance with SOM Policies, Standards, and Procedures, and NIST (National Institute of Standards and Technology) controls.

Lead team members and vendors with proper artifact collection to satisfy assessment requirements.

Coordination of scanning activities/enterprise activities with MCS, tech leads, and business areas.

Lead the system Data Classifications part of the SSP/ATO process.

Required Skillset:

1 to 3 years of experience in the field or in a related area.

Has knowledge of commonly used concepts, practices, and procedures within a particular field.

A bachelor's degree or higher with 21 semester (32 term) credits in computer science, data processing, computer information systems, data communications, networking, systems analysis, computer programming, or mathematics;

OR