1

It Risk Manager Jobs in Michigan (NOW HIRING)

IT Governance Senior Manager

Farmington Hills, MI ยท On-site

$128K - $129K/yr

This role provides executive oversight for IT risk management, controls oversight, policy governance, audit coordination, and remediation management to ensure a strong and compliant operational ...

IT Governance Senior Manager

Farmington Hills, MI ยท On-site

$128K - $129K/yr

This role provides executive oversight for IT risk management, controls oversight, policy governance, audit coordination, and remediation management to ensure a strong and compliant operational ...

Partner with cybersecurity, technology risk, compliance, infrastructure, application, data, and operations teams to support holistic IT risk management. * Facilitate alignment across application ...

Partner with cybersecurity, technology risk, compliance, infrastructure, application, data, and operations teams to support holistic IT risk management. * Facilitate alignment across application ...

Job Title: IT Risk & Controls Manager Job Location: Detroit, MI Job Level: Mid - Senior Level Job type: Full time Industry: Financial Industry As Risk & Control manager you will be enhancing the IT ...

Internal Audit Manager - IT

Plymouth, MI ยท On-site

$96K - $127K/yr

Requirements of the Internal Audit Manager - IT * Bachelor s degree in information systems ... Contribute to the annual enterprise risk assessment and development of the risk based Internal ...

next page

Showing results 1-20

It Risk Manager information

See Michigan salary details

$44.9K

$97.2K

$148.2K

How much do it risk manager jobs pay per year?

As of Jun 19, 2026, the average yearly pay for it risk manager in Michigan is $97,232.00, according to ZipRecruiter salary data. Most workers in this role earn between $78,400.00 and $112,400.00 per year, depending on experience, location, and employer.

What are some common challenges faced by IT Risk Managers when implementing risk mitigation strategies across different departments?

IT Risk Managers often encounter challenges such as varying levels of risk awareness among departments, resistance to new controls or procedures, and balancing business objectives with security requirements. Successful risk mitigation requires clear communication, stakeholder buy-in, and tailored training to ensure all teams understand the importance of compliance. Building strong relationships and fostering a culture of shared responsibility are key to overcoming these hurdles and ensuring effective risk management across the organization.

Do risk managers make good money?

Risk managers typically earn competitive salaries that vary based on experience, industry, and location. According to industry data, median annual pay ranges from $80,000 to over $130,000, with higher earnings possible for those with certifications like FRM or CRM and extensive experience. They often work in corporate environments, analyzing and mitigating financial, operational, or cybersecurity risks.

What are the key skills and qualifications needed to thrive as an IT Risk Manager, and why are they important?

To thrive as an IT Risk Manager, you need a solid understanding of risk assessment, information security, and compliance frameworks, often backed by a bachelor's degree in information technology or related fields. Familiarity with tools such as risk management software, GRC platforms, and certifications like CISSP, CISM, or CRISC is typically required. Strong analytical thinking, communication skills, and the ability to influence stakeholders are crucial soft skills in this role. These skills ensure effective identification, mitigation, and communication of IT risks, supporting organizational resilience and compliance.

What does an IT Risk Manager do?

An IT Risk Manager is responsible for identifying, assessing, and mitigating risks that could impact an organization's information technology systems and data. They develop and implement risk management strategies, policies, and procedures to protect against cybersecurity threats, data breaches, and compliance violations. IT Risk Managers also work closely with other departments to ensure security best practices are followed and often lead risk assessments, audits, and incident response planning.

What is the difference between It Risk Manager vs Cybersecurity Analyst?

AspectIt Risk ManagerCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCISSP, Security+, CEH
Work EnvironmentOversees risk management strategies across IT systemsMonitors and responds to security threats and incidents
Industry UsageUsed in organizations with complex IT infrastructuresCommon in security-focused roles across industries

The It Risk Manager focuses on identifying and managing IT risks at an organizational level, ensuring compliance and risk mitigation strategies. In contrast, a Cybersecurity Analyst primarily monitors security threats and responds to incidents. While both roles require similar certifications and work within the IT security domain, the It Risk Manager has a broader scope related to risk management policies, whereas the Cybersecurity Analyst concentrates on threat detection and response.

How much does a risk manager get paid?

Risk managers typically earn a median annual salary of around $100,000, with salaries ranging from approximately $70,000 to over $150,000 depending on experience, industry, and location. Professionals often hold certifications like CRM or FRM and work in finance, insurance, or corporate sectors.

Are risk managers in high demand?

Risk managers are in high demand across various industries due to increasing concerns about cybersecurity, compliance, and operational risks. Employers seek professionals with skills in risk assessment, mitigation strategies, and certifications like FRM or CRM, making it a growing field with strong job prospects.

What is the role of IT risk manager?

An IT risk manager is responsible for identifying, assessing, and mitigating information technology risks within an organization. They develop security policies, implement controls, and ensure compliance with industry standards to protect digital assets and infrastructure. Strong knowledge of cybersecurity, risk management frameworks, and relevant certifications like CISSP or CISM are often required.
Infographic showing various It Risk Manager job openings in Michigan as of June 2026, with employment types broken down into 87% Full Time, 3% Part Time, and 10% Contract. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $97,232 per year, or $46.7 per hour.
Senior IT Security Risk Analyst

Senior IT Security Risk Analyst

Amerisure Mutual Insurance Company

Farmington Hills, MI โ€ข On-site

Full-time

Medical, Retirement, PTO

Posted 10 days ago


Job description

Amerisure creates exceptional value for its partners, policyholders, and employees. As a property and casualty insurance company, Amerisure's promise to our partner agencies and policyholders begins with a comprehensive line of insurance products designed to protect businesses, as well as the health and safety of every employee. With an A.M. Best "A" (Excellent) rating, Amerisure serves mid-sized commercial enterprises focused in construction, manufacturing and healthcare. Ranked as one of the top 100 Property & Casualty companies in the United States, we proudly manage nearly $1 Billion of Direct Written Premium and maintain $1.21 billion in surplus.
Amerisure is currently recruiting for a Senior IT Security Risk Analyst that can do a 3-day hybrid approach onsite in our Farmington Hills office. The ideal candidate will also possess the following skill set.
Summary Statement
The Senior IT Security Risk Analyst is responsible for leading the organization's cybersecurity governance, risk, and compliance initiatives. This role drives the design, implementation, and continuous improvement of the IT risk program, ensuring alignment with regulatory requirements (e.g., New York State Department of Financial Services, NIST CSF) and business objectives.
Essential Tasks/Major Duties
  • Perform security risk assessments of third-party vendors including AI and mobile application reviews.
  • Lead the review, update, and communication of cybersecurity policies, standards, and procedures to ensure alignment with global frameworks (e.g., NIST CSF, NYDFS, NIS2, PCI DSS).
  • Lead and maintain the IT Risk Register including metrics which provides leadership an overall view of IT risk.
  • Perform risk assessments of IT risks.
  • Map regulations to policies and controls.
  • Create risk and compliance metrics for management and compliance purposes.
  • Perform control testing and validation to ensure proper control effectiveness.
  • Support IT audits and controls around Model Audit Rule (MAR).
  • Monitor threat intelligence to determine potential impact to environment and remediation urgency.
  • Support vulnerability management program, daily security operations and identity tasks as needed.
  • Be a key advisor to leadership, translating cybersecurity risk into business impact and enabling informed decision-making.

Knowledge, Skills & Abilities
  • Bachelor's degree or equivalent combination of education and experience.
  • 5 years cybersecurity experience.
  • Advanced Cyber Risk Management domain specific professional certification required: Certified Information Systems Security Professional (CISSP); Certified Information Security Manager (CISM); Certified in Risk and Information Systems Control (CRISC); Certified Cloud Security Professional (CCSP); AWS Certified Security.
  • 2 years experience performing IT security control testing.
  • Experience reviewing SOC 2 Type 1 and Type 2 reports to articulate potential security risk.
  • Expertise in conducting third-party cyber risk assessments.
  • Proficient in NIST security domain frameworks and architectures.
  • Experience in Logicgate or another GRC tool.
  • Experience using AI driven tools to enhance automation and operational efficiency.
  • Ability to quickly diagnose security control problems and propose/implement solutions.
  • Clear and concise articulation of risk to both technical peers and non-technical stakeholders.
  • Partner with IT teams, developers, and business leaders to support security initiatives, and mentor and develop members of the security team.
  • Analyze data and security trends to anticipate and assess potential threats.
  • Stay current with regulations, evolving threats, technologies, and security protocols.

#LI-BR1
Just as we are committed to creating exceptional value for our Partners For Successยฎ agencies and policyholders, Amerisure also remains committed to being an employer of choice. We reinforce this commitment by adhering to an Employee Value Proposition that, in part, is provided through a competitive total rewards package. This package includes competitive base pay, performance-based incentive pay, comprehensive health and welfare benefits, a 401(k) savings plan with profit sharing, and generous paid time off programs. We also offer flexible work arrangements to promote work-life balance. Recognized as one of the Best and Brightestยฎ Companies to Work For in the Nation and one of Business Insurance magazine's Best Places to Work in Insurance, we provide a workplace that fosters excellence and professional growth. If you are looking for a collaborative and rewarding career, Amerisure is looking for you.
Amerisure Mutual Insurance Company is an Equal Employment Opportunity employer. Amerisure provides equal employment opportunities to all employees and applicants without regard to race, color, religion, sex (to include sexual orientation and gender identity), national origin, age, disability, genetic information, veteran status, or any other protected characteristic under applicable federal, state, or local laws. Amerisure complies with all applicable laws governing nondiscrimination in employment in all locations where the company operates. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training. Amerisure prohibits harassment or discrimination of any kind and is committed to maintaining a workplace free from unlawful harassment or discrimination. Amerisure prohibits retaliation against anyone who reports discrimination, participates in an investigation, or opposes unlawful practices. Any improper interference with an employee's ability to perform their job duties may result in disciplinary action, up to and including termination.