1

Grc Risk Analyst Jobs in Michigan (NOW HIRING)

SAP Security Architect

Dearborn, MI · On-site

$115K - $192K/yr

Maintain GRC master data , running risk analysis, audit and compliance support activities * Build and maintain MSMP Workflows and configuration of GRC notifications. * Build ruleset, creating custom ...

Knowledge of Governance, Risk, and Compliance (GRC) * Experience with IT controls testing, audits, and compliance assessments * Strong communication, analytical, and problem-solving skills

New

This is not a Security Auditor or GRC-focused role. The ideal candidate must have recent experience ... Risk Analysis * Threat Modeling * Architecture Governance Application Security (AppSec) * Secure ...

Lead Security Architect

Lansing, MI · On-site

$75 - $95/hr

This is not a Security Auditor or GRC-focused role. The ideal candidate must have recent experience ... Security Design Reviews Tiger Team Engagements Risk Analysis Threat Modeling Architecture ...

Vice President of Cybersecurity

Detroit, MI · Hybrid

$148K - $186K/yr

Governance, Risk & Compliance (GRC) * Lead cybersecurity compliance efforts for government and ... Lead executive-level incident response, cyber crisis management, and post-incident analysis

Proactively identify, analyze, and test high-risk processes and controls, documenting test procedures, findings, and evidence meticulously within our Governance, Risk, and Compliance (GRC) system.

Internal Audit Manager

Barton City, MI · On-site

$92K - $123K/yr

Leverage data analytics, dashboards, and audit tools (Workiva, GRC platforms) to enhance audit efficiency and consistency * Identify opportunities to streamline processes, reduce risk exposure, and ...

SOC Analyst, Threat hunting, Detection engineering, or Network Security engineering · 2+ years ... Risk, and Compliance (GRC) o Cloud and hosted applications o Containerization o Application ...

SOC Analyst * Threat hunting * Detection engineering * Network Security engineering * Experience in ... Governance, Risk, and Compliance (GRC) * Cloud and hosted applications * Containerization

next page

Showing results 1-20

Grc Risk Analyst information

What is the difference between Grc Risk Analyst vs Compliance Analyst?

AspectGrc Risk AnalystCompliance Analyst
CertificationsISO 31000, FRM, CRISCISO 19600, CCEP, CISA
Work EnvironmentRisk management teams, corporate officesRegulatory departments, corporate offices
Industry UsageFinance, banking, insurance, corporate riskFinancial services, healthcare, manufacturing
Job FocusIdentifying, assessing, and mitigating risks across enterpriseEnsuring compliance with laws and regulations

While both roles involve regulatory and risk considerations, a Grc Risk Analyst focuses on enterprise-wide risk management strategies, whereas a Compliance Analyst concentrates on adherence to specific laws and regulations. Both roles require similar certifications and often work in overlapping industries, but their core responsibilities differ in scope and focus.

What are GRC Risk Analysts?

GRC Risk Analysts are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization. They assess and manage risks related to business operations, ensure compliance with relevant laws and regulations, and help implement policies and controls to mitigate potential threats. These analysts work closely with management to identify vulnerabilities, develop risk management strategies, and monitor the effectiveness of compliance programs. Their goal is to protect the organization from financial, legal, and reputational harm while supporting business objectives.

What are the key skills and qualifications needed to thrive as a GRC Risk Analyst, and why are they important?

To thrive as a GRC (Governance, Risk, and Compliance) Risk Analyst, you need a solid understanding of risk management principles, regulatory requirements, and compliance frameworks, often supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (such as RSA Archer or MetricStream), risk assessment methodologies, and certifications like CRISC or CISA is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and convey findings to stakeholders. These skills are critical for ensuring organizational compliance, minimizing risk exposure, and supporting informed decision-making.

What are some common challenges a GRC Risk Analyst might face when implementing new risk management frameworks within an organization?

A GRC Risk Analyst often encounters challenges such as resistance to change from stakeholders, integrating new frameworks with existing processes, and ensuring consistent understanding across departments. Aligning risk management practices with organizational goals while adhering to regulatory requirements can also be complex. Success in this role requires strong communication skills, adaptability, and the ability to educate and collaborate with team members from diverse backgrounds.
What job categories do people searching Grc Risk Analyst jobs in Michigan look for? The top searched job categories for Grc Risk Analyst jobs in Michigan are:
What cities in Michigan are hiring for Grc Risk Analyst jobs? Cities in Michigan with the most Grc Risk Analyst job openings:
Senior Technical Risk Engineer

Senior Technical Risk Engineer

Ford Motor Company

Dearborn, MI • Remote

$96K - $162K/yr

Full-time

Medical, Dental, Life, PTO

Posted yesterday


Job description

We are seeking a Technical Risk Engineer with strong technical acumen to design, prioritize, and enable risk-reducing technical solutions across complex cloud and enterprise environments. This role emphasizes solution engineering over process engineering-using risk frameworks, policies, and controls as inputs to architect practical, automatable, and scalable technical safeguards.

The ideal candidate thinks like an engineer first and a risk professional second: someone who understands how systems fail, how controls can be enforced through code and architecture, and how risk intent is translated into resilient technical designs.

Preferred Technical Skills

  • Cloud Platforms: Google Cloud Platform (GCP)
  • Automation & API Development: Proficiency in Python or Java and Ansible for scripting, with hands-on experience in API development (RESTful) 
  • Infrastructure as Code: Terraform (required)
  • Data & Analytics: GCP BigQuery, Power BI (or similar) to visualize risk posture & evidence.
  • Backup, recovery, and resilience solution architectures

  • Isolated Recovery Environment (IRE) design and implementation in GCP

  • Supporting Knowledge (nice to have):
    • GRC and/or Security Domain expertise
    • CI/CD pipelines and policy-as-code
    • Cloud IAM, networking, and control planes
    • Observability, logging, and evidence automation
    • GRC Platforms: Archer, ServiceNow
    • ITIL-based IT Service Management (ITSM)
    • Familiarity with Agentic AI Frameworks

Required Qualifications

  • Requires a bachelor's or foreign equivalent degree in computer science, information technology or a technology related field
  • 7+ years in IT operations & engineering, security engineering, platform engineering, SRE, or technical risk roles
  • Backup, recovery, and resilience solution architecture implementations, especially IRE's.

  • Proven ability to design and influence technical solutions across teams
  • Strong understanding of how risk manifests in distributed systems, cloud platforms, and automation
  • Comfortable operating between engineering teams and risk stakeholders
  • Ability to explain complex technical risk concepts to non-technical audiences without losing fidelity

You may not check every box, or your experience may look a little different from what we've outlined, but if you think you can bring value to Ford Motor Company, we encourage you to apply!

As an established global company, we offer the benefit of choice. You can choose what your Ford future will look like: will your story span the globe, or keep you close to home? Will your career be a deep dive into what you love, or a series of new teams and new skills? Will you be a leader, a changemaker, a technical expert, a culture builder...or all of the above? No matter what you choose, we offer a work life that works for you, including:

  • Immediate medical, dental, and prescription drug coverage
  • Flexible family care, parental leave, new parent ramp-up programs, subsidized back-up child care and more
  • Vehicle discount program for employees and family members, and management leases
  • Tuition assistance
  • Established and active employee resource groups
  • Paid time off for individual and team community service
  • A generous schedule of paid holidays, including the week between Christmas and New Year's Day
  • Paid time off and the option to purchase additional vacation time.

For a detailed look at our benefits, click here: Benefit Summary 

This position is a salary grade 8

This position is a salary grade 8 and ranges from $96,720-162,120.

*Visa Sponsorship is provided for this role*

Candidates for positions with Ford Motor Company must be legally authorized to work in the United States. Verification of employment eligibility will be required at the time of hire.

We are an Equal Opportunity Employer committed to a culturally diverse workforce. All qualified applicants will receive consideration for employment without regard to race, religion, color, age, sex, national origin, sexual orientation, gender identity, disability status or protected veteran status. In the United States, If you need a reasonable accommodation for the online application process due to a disability, please call 1-888-336-0660.
 

#LI-Remote

#LI-GH2

Preferred Technical Skills

  • Cloud Platforms: Google Cloud Platform (GCP)
  • Automation & API Development: Proficiency in Python or Java and Ansible for scripting, with hands-on experience in API development (RESTful) 
  • Infrastructure as Code: Terraform (required)
  • Data & Analytics: GCP BigQuery, Power BI (or similar) to visualize risk posture & evidence.
  • Backup, recovery, and resilience solution architectures

  • Isolated Recovery Environment (IRE) design and implementation in GCP

  • Supporting Knowledge (nice to have):
    • GRC and/or Security Domain expertise
    • CI/CD pipelines and policy-as-code
    • Cloud IAM, networking, and control planes
    • Observability, logging, and evidence automation
    • GRC Platforms: Archer, ServiceNow
    • ITIL-based IT Service Management (ITSM)
    • Familiarity with Agentic AI Frameworks

Required Qualifications

  • Requires a bachelor's or foreign equivalent degree in computer science, information technology or a technology related field
  • 7+ years in IT operations & engineering, security engineering, platform engineering, SRE, or technical risk roles
  • Backup, recovery, and resilience solution architecture implementations, especially IRE's.

  • Proven ability to design and influence technical solutions across teams
  • Strong understanding of how risk manifests in distributed systems, cloud platforms, and automation
  • Comfortable operating between engineering teams and risk stakeholders
  • Ability to explain complex technical risk concepts to non-technical audiences without losing fidelity

Key Responsibilities

  • Engineer technical risk solutions that reduce operational, cyber, and resilience risk through architecture, automation, and control design.
  • Translate risk requirements, policies, and standards into implementable technical patterns, guardrails, and reference architectures.
  • Prioritize and influence solution design decisions based on risk impact, blast radius, and recovery dependencies.
  • Partner with platform, cloud, security, and SRE teams to embed risk controls directly into infrastructure and pipelines.
  • Evaluate control effectiveness using technical signals and evidence, not just procedural compliance.
  • Support initiatives such as secure cloud architecture, isolated recovery environments, identity and access hardening, and infrastructure resilience.
  • Provide technical guidance on risk tradeoffs, recovery sequencing, and dependency-aware system design.
  • Contribute to lightweight process definition where needed-but always in service of enabling better technical outcomes.

Ford logo

About Ford

Sourced by ZipRecruiter

At Ford Motor Company, we believe freedom of movement drives human progress. With our incredible plans for the future of mobility, we have a wide variety of opportunities for you to accelerate your career and help us define tomorrow's transportation.

Industry

Civil engineering construction

Company size

51 - 200 Employees

Headquarters location

Doral, FL, US

Year founded

1982