POSITION SUMMARY The Security Engineer - Governance, Risk & Compliance is responsible for establishing and maturing AirLife's information security risk management and compliance posture. This role ...
POSITION SUMMARY The Security Engineer - Governance, Risk & Compliance is responsible for establishing and maturing AirLife's information security risk management and compliance posture. This role ...
You will lead cyber governance, risk, compliance, data privacy, and develop and implement an evergreen enterprise-wide cyber awareness program to ensure effective risk oversight, regulatory adherence ...
You will lead cyber governance, risk, compliance, data privacy, and develop and implement an evergreen enterprise-wide cyber awareness program to ensure effective risk oversight, regulatory adherence ...
You will lead cyber governance, risk, compliance, data privacy, and develop and implement an evergreen enterprise-wide cyber awareness program to ensure effective risk oversight, regulatory adherence ...
You will lead cyber governance, risk, compliance, data privacy, and develop and implement an evergreen enterprise-wide cyber awareness program to ensure effective risk oversight, regulatory adherence ...
GRC Analyst
Southfield, MI · On-site
About the Role As a member of the Information Security team, the IS GRC - Risk & Compliance Senior Analyst will support the firm's Governance, Risk, and Compliance (GRC) program by managing security ...
Quick apply
GRC Analyst
Southfield, MI · On-site
About the Role As a member of the Information Security team, the IS GRC - Risk & Compliance Senior Analyst will support the firm's Governance, Risk, and Compliance (GRC) program by managing security ...
Developing AI-enabled capabilities that accelerate governance, risk, and compliance and cyber operations, including evidence summarization, control testing assist, policy question-and-answer ...
Developing AI-enabled capabilities that accelerate governance, risk, and compliance and cyber operations, including evidence summarization, control testing assist, policy question-and-answer ...
This position will provide operational and administrative support for Human Resources risk management, compliance, governance, investigations, and audit activities. This role assists with compliance ...
This position will provide operational and administrative support for Human Resources risk management, compliance, governance, investigations, and audit activities. This role assists with compliance ...
This position will provide operational and administrative support for Human Resources risk management, compliance, governance, investigations, and audit activities. This role assists with compliance ...
This position will provide operational and administrative support for Human Resources risk management, compliance, governance, investigations, and audit activities. This role assists with compliance ...
Job Summary The Cybersecurity Vulnerability Governance Analyst is responsible for governing and overseeing the organization's Vulnerability Management Program from a risk, compliance, and ...
Job Summary The Cybersecurity Vulnerability Governance Analyst is responsible for governing and overseeing the organization's Vulnerability Management Program from a risk, compliance, and ...
Risk Analyst
Lansing, MI · On-site +1
$87K - $110K/yr
Document risks, findings, recommendations, and remediation plans while maintaining accurate records within governance, risk, and compliance platforms * Serve as a trusted advisor to stakeholders by ...
Risk Analyst
Lansing, MI · On-site +1
$87K - $110K/yr
Document risks, findings, recommendations, and remediation plans while maintaining accurate records within governance, risk, and compliance platforms * Serve as a trusted advisor to stakeholders by ...
IT Security Analyst
Lansing, MI · On-site
Knowledge of NIST, System Security Plans (SSP), Governance, Risk & Compliance (GRC), and security controls. * Experience performing risk assessments, vulnerability remediation, and compliance ...
IT Security Analyst
Lansing, MI · On-site
Knowledge of NIST, System Security Plans (SSP), Governance, Risk & Compliance (GRC), and security controls. * Experience performing risk assessments, vulnerability remediation, and compliance ...
IT Security Analyst
Lansing, MI · On-site
Knowledge of NIST, System Security Plans (SSP), Governance, Risk & Compliance (GRC), and security controls.Experience performing risk assessments, vulnerability remediation, and compliance activities.
Quick apply
IT Security Analyst
Lansing, MI · On-site
Knowledge of NIST, System Security Plans (SSP), Governance, Risk & Compliance (GRC), and security controls.Experience performing risk assessments, vulnerability remediation, and compliance activities.
IT Security Analyst 2
Lansing, MI · On-site
Knowledge of NIST, System Security Plans (SSP), Governance, Risk & Compliance (GRC), and security controls. * Experience performing risk assessments, vulnerability remediation, and compliance ...
IT Security Analyst 2
Lansing, MI · On-site
Knowledge of NIST, System Security Plans (SSP), Governance, Risk & Compliance (GRC), and security controls. * Experience performing risk assessments, vulnerability remediation, and compliance ...
IT Security Analyst
Lansing, MI · Hybrid
Knowledge of NIST, System Security Plans (SSP), Governance, Risk & Compliance (GRC), and security controls. * Experience performing risk assessments, vulnerability remediation, and compliance ...
IT Security Analyst
Lansing, MI · Hybrid
Knowledge of NIST, System Security Plans (SSP), Governance, Risk & Compliance (GRC), and security controls. * Experience performing risk assessments, vulnerability remediation, and compliance ...
Vice President of Cybersecurity
Detroit, MI · Hybrid
$148K - $186K/yr
Governance, Risk & Compliance (GRC) * Lead cybersecurity compliance efforts for government and regulated environments, including NIST 800-53, NIST 800-171, CMMC, and related federal frameworks
Vice President of Cybersecurity
Detroit, MI · Hybrid
$148K - $186K/yr
Governance, Risk & Compliance (GRC) * Lead cybersecurity compliance efforts for government and regulated environments, including NIST 800-53, NIST 800-171, CMMC, and related federal frameworks
Lead the Company's data privacy program, including privacy governance, risk assessments, data ... Establish compliance monitoring, auditing, and reporting processes, including executive dashboards ...
Lead the Company's data privacy program, including privacy governance, risk assessments, data ... Establish compliance monitoring, auditing, and reporting processes, including executive dashboards ...
IT Security Specialist I- Governance Analyst : Detroit, MI (Onsite)(Only local)
Detroit, MI · On-site
At least 3-5 years of work experience in IT compliance, IT Assessments and/or IT audit experience as well as knowledge and understanding of governance, risk, compliance * Knowledge of security and ...
Quick apply
IT Security Specialist I- Governance Analyst : Detroit, MI (Onsite)(Only local)
Detroit, MI · On-site
At least 3-5 years of work experience in IT compliance, IT Assessments and/or IT audit experience as well as knowledge and understanding of governance, risk, compliance * Knowledge of security and ...
The Associate General Counsel - Litigation, Compliance & Risk Management leads legal matters involving litigation, regulatory compliance, corporate governance, risk management, employment-related ...
The Associate General Counsel - Litigation, Compliance & Risk Management leads legal matters involving litigation, regulatory compliance, corporate governance, risk management, employment-related ...
The Associate General Counsel - Litigation, Compliance & Risk Management leads legal matters involving litigation, regulatory compliance, corporate governance, risk management, employment-related ...
The Associate General Counsel - Litigation, Compliance & Risk Management leads legal matters involving litigation, regulatory compliance, corporate governance, risk management, employment-related ...
Data Security Specialist
East Lansing, MI · On-site
Analysis of user activity involving sensitive data, tune DLP policies, and help mature DLP processes and procedures Qualifications: * 2+ years of experience in data governance, risk, compliance, or a ...
Data Security Specialist
East Lansing, MI · On-site
Analysis of user activity involving sensitive data, tune DLP policies, and help mature DLP processes and procedures Qualifications: * 2+ years of experience in data governance, risk, compliance, or a ...
GRC Analyst
Detroit, MI · On-site
Required : • At least three to five years of work experience in IT compliance, IT Assessments, and/or IT audit experience as well as knowledge and understanding of governance, risk, compliance • ...
GRC Analyst
Detroit, MI · On-site
Required : • At least three to five years of work experience in IT compliance, IT Assessments, and/or IT audit experience as well as knowledge and understanding of governance, risk, compliance • ...
Overnight Governance Risk Compliance information
What is an overnight governance risk compliance role?
What are the key skills and qualifications needed to thrive as an overnight governance risk compliance professional?
What are some common challenges faced by professionals working overnight in governance, risk, and compliance roles?
What is the difference between Overnight Governance Risk Compliance vs Overnight Compliance Analyst?
| Aspect | Overnight Governance Risk Compliance | Overnight Compliance Analyst |
|---|---|---|
| Certifications | GRC certifications, such as CRISC or CISA | Compliance certifications, such as CAMS or CCEP |
| Work Environment | Financial institutions, 24/7 operations, risk-focused | Financial firms, monitoring compliance, reporting |
| Employer & Industry Usage | Banking, investment firms, regulatory bodies | Banking, asset management, financial services |
Overnight Governance Risk Compliance professionals focus on managing and monitoring risk, governance, and compliance frameworks during overnight shifts, often dealing with high-level policies and regulatory adherence. Overnight Compliance Analysts primarily review daily compliance activities, ensure adherence to regulations, and handle reporting tasks. While both roles require compliance knowledge, GRC roles emphasize risk management strategies, whereas Compliance Analysts focus on operational compliance tasks during overnight hours.
What are the most commonly searched types of Governance Risk Compliance jobs in Michigan?
The most popular types of Governance Risk Compliance jobs in Michigan are:
What cities in Michigan are hiring for Overnight Governance Risk Compliance jobs?
Cities in Michigan with the most Overnight Governance Risk Compliance job openings:
Full-time
Medical, Dental, Vision, Retirement, PTO
Posted 17 days ago
Job description
COMPANY DESCRIPTION
At AirLife, we are dedicated to improving the quality of every breath. Excellence with Every Breath is not just a tag line, but the way we work and take care of our customers. With a mindset to evolve, innovate, and grow, we are a premier manufacturer of the highest-quality and market-leading breathing consumables. This growth philosophy has positioned us to increase our global footprint and business reach, impacting even more people around the world. Our expanding family of the most trusted brands offers a product portfolio that spans the continuum of care from first responder to home care, with safety, patient comfort, and clinical performance in mind. Collective expertise allows us to provide quality products and experiences to our patients, customers, and our people. Our values of Customer first, Differentiate with our People, Bias for Action, Continuous Improvement and Accountability define who we are and how we work. Join us!
POSITION SUMMARY
The Security Engineer – Governance, Risk & Compliance is responsible for establishing and maturing AirLife's information security risk management and compliance posture. This role evaluates, quantifies, and helps mitigate security risks across IT infrastructure and business systems, while ensuring AirLife's cybersecurity practices remain aligned to applicable regulatory frameworks, industry standards, and internal policies. Operating in a medical device manufacturing environment with FDA and ISO regulatory obligations and a PE ownership structure with specific cybersecurity reporting requirements, this role brings both technical security knowledge and a compliance mindset to a rapidly maturing IT security program. The Security Engineer – GRC plays a critical role in AirLife's ability to satisfy external auditors, insurance underwriters, and PE sponsor security benchmarking requirements.
POSITION QUALIFICATIONS
Knowledge, Skills & Abilities:
- Strong working knowledge of security risk management frameworks and methodologies, including NIST CSF, NIST SP 800-30/37, ISO 27001, and CIS Controls.
- Understanding of regulatory compliance requirements relevant to medical device manufacturing, including FDA 21 CFR Part 820 / QMSR and ISO 13485, and their implications for IT General Controls (ITGC) and computer system validation.
- Experience with IT General Controls frameworks and audit support, including SOX-adjacent controls applicable to PE-backed manufacturing companies.
- Knowledge of data privacy regulations, including GDPR and applicable US state privacy laws, and their operational IT implications.
- Experience conducting risk assessments, gap analyses, and security control reviews; ability to document, prioritize, and track findings through to remediation.
- Experience developing and maintaining security policies, standards, procedures, and control evidence libraries.
- Familiarity with vulnerability management programs, including scanning tooling, remediation tracking, and risk-based prioritization.
- Experience administering security awareness training programs, including phishing simulation and completion tracking (KnowBe4 experience preferred).
- Ability to work with MDR/MSSP providers to ensure managed detection capabilities align with AirLife's compliance posture (Arctic Wolf experience a plus).
- Strong written communication skills; ability to clearly document findings, prepare audit evidence packages, and present risk posture to non-technical audiences including executives and external auditors.
- Proficiency with project and task management tools; Smartsheet experience preferred.
- Industry-recognized GRC or cybersecurity certification(s) preferred (CISA, CRISC, CompTIA Security+, SSCP, or equivalent).
Level of Experience:
Minimum 4–6 years of IT experience with 3+ years in a cybersecurity role with a GRC, compliance, or risk management focus. Experience in a regulated manufacturing, medical device, or life sciences environment strongly preferred.
Level of Education:
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field, or equivalent experience. GRC-relevant certification(s) preferred.
Travel:
Up to 20% as required by the business.
ESSENTIAL DUTIES AND RESPONSIBILITIES
- Develop, implement, and maintain AirLife's information security policies, standards, and procedures, ensuring they remain current, compliant with applicable frameworks, and operationally effective for the teams they govern.
- Conduct and facilitate periodic security risk assessments and gap analyses across IT infrastructure, business applications, and operational technology, documenting findings, quantifying risk, and recommending prioritized remediation measures to IT leadership.
- Own AirLife's security compliance posture across applicable frameworks (NIST CSF, CIS Controls, ISO 27001, GDPR), including control documentation, evidence collection, ongoing compliance monitoring, and management of compliance calendars.
- Support IT General Controls (ITGC) compliance, including access control review coordination, change management process documentation, and preparation and management of audit evidence packages for internal and external auditors.
- Partner with QA/RA and Legal & Compliance to ensure IT security controls are appropriately aligned to AirLife's 21 CFR Part 820 / QMSR and ISO 13485 obligations, particularly as they relate to computer system validation and access control in regulated processes.
- Own and administer AirLife's security awareness and compliance training program, including planning and coordinating KnowBe4 phishing simulation and training campaigns, tracking completion rates across departments, and reporting to IT leadership on compliance status.
- Maintain and improve AirLife's vulnerability management program, including scheduling assessments, tracking and prioritizing remediation, and reporting vulnerability posture and trends to IT leadership.
- Support Frazier Partners' cybersecurity benchmarking and reporting requirements; coordinate with Lockton for cyber insurance assessment preparation and supply requested security metrics, documentation, and evidence as required.
- Collaborate with Arctic Wolf and other managed security service providers to ensure managed services are operating in alignment with AirLife's compliance posture, risk appetite, and applicable regulatory requirements.
- Maintain, test, and continuously improve the IT Cyber Incident Response Playbook; support the planning and facilitation of tabletop exercises; assist in incident response coordination and post-incident review when security events occur.
- Serve as the IT security subject matter expert for IT-related internal and external audits: prepare evidence packages, coordinate audit interviews, manage finding responses, and own remediation tracking through closure (including all enterprise applications and segregation-of-duties findings).
- Build and maintain a comprehensive GRC documentation library, including the risk register, control matrix, policy library, compliance calendar, and audit history, ensuring currency and accessibility for authorized stakeholders.
OTHER RESPONSIBILITIES
- Uphold and embody AirLife's values in all aspects of work.
- Demonstrate accuracy and thoroughness in daily work; look for ways to improve and promote quality & safety.
- Inspire the trust of others; treat people with respect and dignity and embrace the value of diversity.
- Use time efficiently; perform job accurately, thoroughly, and conserve Company resources to improve profits.
- Contribute to building and maintaining a positive team environment.
- Assure all policies and guidelines are implemented and followed.
QUALITY POLICY
At AirLife, Quality is our promise. It is our commitment to customer satisfaction and our dedication to product excellence in an evolving global healthcare market. This promise is kept through a continuously improving and effective Quality Management System and compliance to Regulatory Requirements.
DEIA STATEMENT
At AirLife, we are committed to building a diverse workforce and an inclusive workplace that reflects the communities and customers we serve. We believe our philosophy on Diversity, Equity, Inclusion, and Advancement (DEIA) encourages excellence and equips us to serve an evolving global marketplace.
Please note: The responsibilities outlined above are not exhaustive and may evolve over time. The role holder may be required to undertake additional duties as reasonably expected to meet the needs of the company.
Benefits
AirLife offers a comprehensive benefits package, including medical, dental, and vision coverage, 401(k), paid time off, paid holidays, bereavement leave, Employee Assistance Program resources, and medical leave benefits, subject to applicable eligibility requirements. Certain positions may also be eligible for bonus, commission, or other incentive compensation.
About AirLife
Sourced by ZipRecruiter
Industry
Medical equipment and supplies manufacturing
Company size
5,001 - 10,000 Employees
Headquarters location
Grand Rapids, MI, US
Year founded
1981