1

Grc Third Party Risk Analyst Jobs in Michigan (NOW HIRING)

Third-Party Risk Management (TPRM) * 10+ years of demonstrated deep technical expertise in ... Proven experience with ServiceNow Security and GRC modules, with a strong understanding of platform ...

Third-Party Risk Management (TPRM) * 10+ years of demonstrated deep technical expertise in ... Proven experience with ServiceNow Security and GRC modules, with a strong understanding of platform ...

... third-party systems. - Ensure data quality, reporting, and dashboards align with risk and ... GRC programs. - Troubleshoot, resolve, and optimize system issues related to IRM modules. This is a ...

... Third-Party Risk Management workstreams in partnership with architects and product owners ... Experience with Performance Analytics, Predictive Intelligence, Now Assist, or generative ...

... Third-Party Risk Management workstreams in partnership with architects and product owners ... Experience with Performance Analytics, Predictive Intelligence, Now Assist, or generative ...

Solutions Architect, Commercial

Detroit, MI · On-site

$62.25 - $82.25/hr

... Third Party Risk Association's Innovator Award, Exiger's technology has been recognized by leading analyst evaluations and 50+ awards. Learn more at Exiger.com and follow Exiger on LinkedIn . At ...

... third-party risk management, and audit and regulatory compliance analysis. This role sets strategic direction, ensures regulatory compliance, and fosters a culture of continuous improvement across ...

Showing results 41-60

Grc Third Party Risk Analyst information

What are some typical challenges a GRC Third Party Risk Analyst may encounter when assessing vendors?

As a GRC Third Party Risk Analyst, you may face challenges such as obtaining timely and complete responses from vendors, especially when dealing with large or international organizations. Navigating varying levels of vendor maturity in risk management practices can also be difficult. Additionally, balancing the need for thorough risk assessments with fast-paced business timelines requires strong communication and prioritization skills. Collaborating closely with procurement, legal, and IT teams is essential to ensure all risks are properly identified and managed.

What are the key skills and qualifications needed to thrive as a GRC Third Party Risk Analyst, and why are they important?

To thrive as a GRC Third Party Risk Analyst, you need a strong understanding of risk management frameworks, compliance regulations, and vendor risk assessment methodologies, typically supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (like Archer or ServiceNow), third-party risk management tools, and certifications such as CISA or CRISC is highly beneficial. Strong analytical thinking, attention to detail, and effective communication skills are essential soft skills for this role. These competencies ensure that organizations can accurately assess and mitigate third-party risks, maintaining compliance and protecting sensitive data.

What is a GRC Third Party Risk Analyst?

A GRC Third Party Risk Analyst is a professional who assesses and manages the risks associated with an organization’s external vendors, suppliers, or partners. Their role involves evaluating third-party compliance with regulatory standards and internal policies, identifying potential risks such as data breaches or non-compliance, and recommending mitigation strategies. They use frameworks like GRC (Governance, Risk, and Compliance) to help ensure that third-party relationships do not compromise the organization's security or reputation. This role often collaborates with procurement, legal, and IT teams to maintain robust risk management processes.

What is the difference between Grc Third Party Risk Analyst vs Grc Vendor Risk Analyst?

AspectGrc Third Party Risk AnalystGrc Vendor Risk Analyst
CertificationsCertifications like CRISC, CISA often preferredSame certifications commonly required
Work EnvironmentFocuses on third-party relationships and risk assessmentsPrimarily evaluates vendor-specific risks and compliance
Industry UsageUsed across finance, healthcare, and tech sectorsCommonly found in industries with extensive vendor networks

The Grc Third Party Risk Analyst and Grc Vendor Risk Analyst roles overlap significantly in certifications and work environment. The main difference lies in scope: the Third Party Risk Analyst assesses overall third-party relationships, while the Vendor Risk Analyst concentrates specifically on individual vendors. Both roles are vital for managing third-party risks in various industries.

What job categories do people searching Grc Third Party Risk Analyst jobs in Michigan look for? The top searched job categories for Grc Third Party Risk Analyst jobs in Michigan are:
What cities in Michigan are hiring for Grc Third Party Risk Analyst jobs? Cities in Michigan with the most Grc Third Party Risk Analyst job openings:
Infographic showing various Grc Third Party Risk Analyst job openings in Michigan as of August 2026, with employment types broken down into 1% As Needed, 84% Full Time, 12% Part Time, and 3% Contract. Highlights an 88% Physical, 4% Hybrid, and 8% Remote job distribution.

Senior Manager - ServiceNow

Deloitte

Detroit, MI • On-site

Full-time

Re-posted 19 days ago


Deloitte rating

8.2

Company rating: 8.2 out of 10

Based on 92 frontline employees who took The Breakroom Quiz

45th of 150 rated financial services


Job description

Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.

Recruiting for this role ends on 12/31/2026.

Work you'll do

As a ServiceNow Senior Manager on the Cyber Strategy & Transformation team, you will be responsible for...

  • Develop and execute strategies for integrated risk management (IRM), governance, risk, and compliance (GRC), and Security Operations (SecOps) leveraging the ServiceNow platform.
  • Design and implement enterprise risk and compliance frameworks aligned with industry standards (e.g., ISO 27001, NIST, COBIT, PCI, HIPAA) using ServiceNow GRC and SecOps modules.
  • Oversee the delivery of ServiceNow-based cyber risk solutions, ensuring alignment with best practices and evolving client needs.
  • Lead the assessment, configuration, and deployment of ServiceNow IRM, GRC, and SecOps modules, including ITSM, ITAM, CMDB, and automation workflows.
  • Drive continuous improvement by applying industry-leading practices and ServiceNow capabilities to enhance cyber risk management and service delivery.
  • Serve as a trusted advisor to executive stakeholders, translating business requirements into effective ServiceNow technical solutions.
  • Contribute to practice development by creating go-to-market strategies and innovative ServiceNow-based solutions for client cyber risk challenges.
  • Provide thought leadership on ServiceNow GRC and SecOps trends and evaluate emerging requirements and technologies.
  • Lead and mentor global teams to ensure high-quality delivery of ServiceNow cyber risk management services.

The team

Our Cyber Strategy & Transformation offering develops and transforms cyber programs in line with a client's strategic objectives, regulatory requirements, and risk appetite. It keeps the enterprise a step ahead of the evolving threat landscape and gives stakeholders confidence in the organization's cyber posture. Includes design of the cyber organization, governance, and risk assessments.

Qualifications

Required:

  • BA/BS Degree in Computer Science, Cyber Security, Information Security, Engineering, Information Technology, Finance, Business or related field
  • 10+ years of hands-on experience on Tech Risk technology solution designs and architect, including but not limited to:
    • IT Operations Management (ITOM)
    • IT Asset Management (ITAM)
    • Integrated Risk Management (IRM)
    • Security Operations (SecOps)
    • Third-Party Risk Management (TPRM)
  • 10+ years of demonstrated deep technical expertise in ServiceNow, typically evidenced by advanced ServiceNow certifications (e.g., Certified Application Developer, Certified Implementation Specialist, Certified Technical Architect, Certified Master Architect) and hands-on experience designing, configuring, and integrating complex ServiceNow solutions.
  • 10+ years of experience leading ServiceNow implementations including solution design and technical architecture
  • Previous consulting or Big 4 experience
  • Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
  • Limited immigration sponsorship may be available.

Preferred:

  • ServiceNow Certified Master Architect (CMA) / ServiceNow Certified Technical Architect (CTA)
  • Proven experience with ServiceNow Security and GRC modules, with a strong understanding of platform capabilities and best practices.
  • Exceptional documentation, presentation, and communication skills-both verbal and written-with the ability to collaborate effectively across geographically dispersed teams.
  • Demonstrated adaptability in prioritizing and executing tasks, working closely with clients to identify and resolve key constraints, risks, and issues.
  • Strong problem-solving, critical thinking, and logical structuring abilities.
  • Hands-on experience defining epics and user stories, creating UI mock-ups, and a proactive, "roll-up-the-sleeves" approach to driving results.
  • Expertise in developing business and technical design specifications for ServiceNow platform implementations.
  • Skilled at leading technical design meetings, reviewing proposed solutions with stakeholders, and ensuring alignment with client objectives.
#CyberServiceNow

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $163,400 to $322,100.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

Qualifications:

Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.

Recruiting for this role ends on 12/31/2026.

Work you'll do

As a ServiceNow Senior Manager on the Cyber Strategy & Transformation team, you will be responsible for...

  • Develop and execute strategies for integrated risk management (IRM), governance, risk, and compliance (GRC), and Security Operations (SecOps) leveraging the ServiceNow platform.
  • Design and implement enterprise risk and compliance frameworks aligned with industry standards (e.g., ISO 27001, NIST, COBIT, PCI, HIPAA) using ServiceNow GRC and SecOps modules.
  • Oversee the delivery of ServiceNow-based cyber risk solutions, ensuring alignment with best practices and evolving client needs.
  • Lead the assessment, configuration, and deployment of ServiceNow IRM, GRC, and SecOps modules, including ITSM, ITAM, CMDB, and automation workflows.
  • Drive continuous improvement by applying industry-leading practices and ServiceNow capabilities to enhance cyber risk management and service delivery.
  • Serve as a trusted advisor to executive stakeholders, translating business requirements into effective ServiceNow technical solutions.
  • Contribute to practice development by creating go-to-market strategies and innovative ServiceNow-based solutions for client cyber risk challenges.
  • Provide thought leadership on ServiceNow GRC and SecOps trends and evaluate emerging requirements and technologies.
  • Lead and mentor global teams to ensure high-quality delivery of ServiceNow cyber risk management services.

The team

Our Cyber Strategy & Transformation offering develops and transforms cyber programs in line with a client's strategic objectives, regulatory requirements, and risk appetite. It keeps the enterprise a step ahead of the evolving threat landscape and gives stakeholders confidence in the organization's cyber posture. Includes design of the cyber organization, governance, and risk assessments.

Qualifications

Required:

  • BA/BS Degree in Computer Science, Cyber Security, Information Security, Engineering, Information Technology, Finance, Business or related field
  • 10+ years of hands-on experience on Tech Risk technology solution designs and architect, including but not limited to:
    • IT Operations Management (ITOM)
    • IT Asset Management (ITAM)
    • Integrated Risk Management (IRM)
    • Security Operations (SecOps)
    • Third-Party Risk Management (TPRM)
  • 10+ years of demonstrated deep technical expertise in ServiceNow, typically evidenced by advanced ServiceNow certifications (e.g., Certified Application Developer, Certified Implementation Specialist, Certified Technical Architect, Certified Master Architect) and hands-on experience designing, configuring, and integrating complex ServiceNow solutions.
  • 10+ years of experience leading ServiceNow implementations including solution design and technical architecture
  • Previous consulting or Big 4 experience
  • Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
  • Limited immigration sponsorship may be available.

Preferred:

  • ServiceNow Certified Master Architect (CMA) / ServiceNow Certified Technical Architect (CTA)
  • Proven experience with ServiceNow Security and GRC modules, with a strong understanding of platform capabilities and best practices.
  • Exceptional documentation, presentation, and communication skills-both verbal and written-with the ability to collaborate effectively across geographically dispersed teams.
  • Demonstrated adaptability in prioritizing and executing tasks, working closely with clients to identify and resolve key constraints, risks, and issues.
  • Strong problem-solving, critical thinking, and logical structuring abilities.
  • Hands-on experience defining epics and user stories, creating UI mock-ups, and a proactive, "roll-up-the-sleeves" approach to driving results.
  • Expertise in developing business and technical design specifications for ServiceNow platform implementations.
  • Skilled at leading technical design meetings, reviewing proposed solutions with stakeholders, and ensuring alignment with client objectives.
#CyberServiceNow

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $163,400 to $322,100.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

Education:Bachelor's DegreeEmployment Type:

What Deloitte employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom