1

Security Risk Analyst Jobs in Michigan (NOW HIRING)

We are seeking a qualified Insider Risk Analyst to join our Digital Information Risk team. In this ... Cybersecurity certifications such as Certification in Certified Information Systems Security ...

We are seeking a qualified Insider Risk Analyst to join our Digital Information Risk team. In this ... Cybersecurity certifications such as Certification in Certified Information Systems Security ...

We are seeking a qualified Insider Risk Analyst to join our Digital Information Risk team. In this ... Cybersecurity certifications such as Certification in Certified Information Systems Security ...

Information Security experience (preferably Third Party Risk Management and Compliance) Familiarity with SOC 1 (SSAE 16*) and SOC 2 (**AT101) reports Ability to write process, procedures, flowcharts ...

The Strategy and Risk Analyst will help drive success across all aspects of the cybersecurity ... Demonstrated ability to harness a range of security tools, applying strong critical-thinking skills ...

next page

Showing results 1-20

Security Risk Analyst information

See Michigan salary details

$9

$43

$60

How much do security risk analyst jobs pay per hour?

As of May 28, 2026, the average hourly pay for security risk analyst in Michigan is $43.94, according to ZipRecruiter salary data. Most workers in this role earn between $35.62 and $52.36 per hour, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Security Risk Analyst, and why are they important?

To thrive as a Security Risk Analyst, you need a strong background in risk assessment, information security principles, and analytical thinking, often supported by a degree in cybersecurity, IT, or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security assessment tools, and certifications like CISSP or CISM is highly valuable. Excellent communication, attention to detail, and problem-solving abilities help you translate complex risks for varied stakeholders and drive mitigation strategies. These skills and qualities are crucial for identifying vulnerabilities, minimizing threats, and maintaining organizational security and compliance.

What are some common challenges Security Risk Analysts face when collaborating with other departments?

Security Risk Analysts often work closely with IT, compliance, and business units to assess and mitigate risks. A common challenge is bridging the gap between technical security requirements and business objectives, as not all stakeholders may have a cybersecurity background. Effective communication and education are key to ensuring that risk recommendations are understood and adopted. Additionally, prioritizing risks with limited resources and balancing security with operational needs can be complex, requiring strong collaboration and negotiation skills.

What does a Security Risk Analyst do?

A Security Risk Analyst is responsible for identifying, assessing, and mitigating risks to an organization's information systems and data. They analyze security measures, conduct vulnerability assessments, and recommend strategies to protect against threats such as cyberattacks, data breaches, and unauthorized access. Their work helps ensure that a company's digital assets remain safe and compliant with industry regulations. Security Risk Analysts collaborate with IT teams and management to implement effective security policies and respond to incidents as needed.

What is the difference between Security Risk Analyst vs Security Analyst?

AspectSecurity Risk AnalystSecurity Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CISSP, CEH
Work EnvironmentRisk assessment, vulnerability analysis, policy developmentMonitoring security systems, incident response, security audits
Employer & Industry UsageFinancial, healthcare, government sectors focusing on risk mitigationIT departments across various industries focusing on security operations

While both roles focus on cybersecurity, Security Risk Analysts primarily assess and manage potential security threats and vulnerabilities, emphasizing risk mitigation strategies. Security Analysts tend to monitor security systems, respond to incidents, and ensure ongoing security measures. Both roles often require similar certifications and work environments but differ in their core responsibilities within cybersecurity teams.

What job categories do people searching Security Risk Analyst jobs in Michigan look for? The top searched job categories for Security Risk Analyst jobs in Michigan are:
Infographic showing various Security Risk Analyst job openings in Michigan as of May 2026, with employment types broken down into 67% Full Time, and 33% Temporary. Highlights an 100% In-person job distribution, with an average salary of $91,385 per year, or $43.9 per hour.

Govt. IT Security Risk Analyst

Sault Tribe

Perronville, MI • On-site

$57.94K/yr

Full-time

Posted 27 days ago


Job description

POSITION SUMMARY:

The Security Risk Analyst, under the direction of the Director of IT Security, is responsible for identifying, analyzing, and mitigating potential cyber security risks within and across all of the Tribe’s divisions including, government, health, gaming & hospitality and other enterprises. As part of the Security team, this position will participate in many cyber security activities, but will have a primary focus on risk identification and mitigation. Leading the regular functions and activities related to vulnerability identification and penetration testing, the Security Risk Analyst will analyze findings and report those to the proper IT management team members along with recommendations for mitigation.

ESSENTIAL FUNCTIONS: (includes, but is not limited to, the following)

Risk Assessment:

o Conduct comprehensive risk assessments to identify and evaluate potential security threats and vulnerabilities.

o Analyze the impact of identified risks on the organization's information systems and assets.

Vulnerability Management:

o Monitor and manage vulnerabilities in the organization's IT and data infrastructure.

o Collaborate with IT teams to prioritize and address vulnerabilities based on their severity.

Incident Response:

o Participate in testing, training or active investigations to understand the root cause of security incidents and recommend corrective actions.

Security Policy and Compliance:

o Ensure compliance with industry regulations and standards.

o Work with the Director of IT Security to update security policies and procedures to meet regulatory requirements or industry’s best practices.

Security Awareness:

o Provide education and training to employees on security best practices.

o Promote a security-conscious culture within the organization.

Security Metrics and Reporting:

o Regularly generate and present security metrics, risk analysis findings, and reports to management.

o Communicate to all stakeholders the status of security risks and mitigation efforts, and actively participate in mitigation efforts, when possible, to expedite resolution.

Security Tools and Technologies:

o Utilizing security tools and technologies to monitor and analyze network traffic, detect vulnerabilities, test systems for vulnerabilities, isolate threats and respond to security incidents.

Collaboration:

o Collaborate with cross-functional teams, including IT, legal, compliance, and department leaders to understand business operations and to address security concerns and identify potential solutions.

Continuous Improvement:

o Stay abreast of the latest security trends, technologies, and threats.

o Recommend and implement improvements to the organization's security posture.

Risk Mitigation Strategies:

o Develop and recommend risk mitigation strategies to reduce the impact of potential security risks.

CONTACTS:

Immediate peers, peers in other departments, immediate supervisor/manager, managers in other departments, executives, Board of Directors, customers and outside vendor/service providers.

PHYSICAL REQUIREMENTS:

Position medium with lifting of 50 pounds maximum. Physical factors include constant use of near vision and typing; frequent walking, sitting, kneeling, use of midrange/color vision; and occasional standing carrying, lifting, pushing/pulling, climbing, stooping, crawling, reaching, manual handling, use of hearing, smell and far vision, depth perception and field of vision, typing and bending. Working conditions include occasional exposure to extreme cold and noise. Potential hazards include frequent computer and equipment use and occasional exposure to moving mechanic parts, electric shock, client contact and medical equipment.

REQUIREMENTS:

Education: Associate’s degree in computer science, Computer Information Systems Management or Technology related field required or three years of IT experience may be considered in lieu of a degree.

Experience: Two years of experience in cybersecurity including but not limited to compliance, threat detection, vulnerability analysis, and penetration testing required in addition to the above-stated education requirements.

Certification/License: Must undergo a criminal background investigation done under the rules of the National Indian Gaming Commission. Must have a valid driver’s license and be insurable by the Sault Tribe Insurance Department. Must comply with annual driver’s license review and insurability standards with the Sault Tribe Insurance Department. Must comply with the Sault Tribe’s Drug-Free Workplace Policy which may include random drug tests.

Knowledge, Skills, and Abilities: Strong technical knowledge of common core business IT systems, infrastructure, wide-area-networks, internet communications and connectivity, websites and backup and storage systems. Skilled in network and system penetration testing, threat and vulnerability monitoring and analysis and risk analysis. Knowledge of Microsoft Active Directory, Microsoft Windows, servers and databases and communication protocols. Knowledge of IP based networks hardware and communication preferred. Knowledge of Business Continuity and Data System Security required. Knowledge of PERL, Java, HTML, MySQL, python, Web Application Programming and Linux preferred. Understanding of fundamental concepts in information security including confidentiality, integrity, and availability (CIA triad), risk assessment methodologies, threat modeling, and defense-in-depth strategies. Knowledge of current and emerging cyber threats, attack vectors, and malware trends. Understanding of threat actors, their motivations, and tactics, techniques, and procedures (TTPs). Familiarity with relevant regulatory requirements such as GDPR, HIPAA, PCI-DSS, MICS, CJIS and industry standards like ISO 27001/2. Understanding of legal and compliance frameworks applicable to data protection and privacy. Proficiency in risk assessment methodologies such as NIST SP 800-30, FAIR (Factor Analysis of Information Risk), and OCTAVE (Operationally Critical Threat, Asset, and Vulnerability Evaluation). Knowledge of vulnerability assessment tools and techniques. Understanding of common vulnerabilities and exposures (CVEs), vulnerability databases, and patch management processes. Familiarity with various security technologies including firewalls, intrusion detection/prevention systems (IDS/IPS), antivirus solutions, encryption techniques, secure network architecture, and security information and event management (SIEM) systems. Must have organizational skills and be able to plan, prioritize and manage workload to meet goals in a timely manner. Must have excellent communication skills and be able to communicate clearly in person, in writing, and by telephone and email. Strong problem-solving skills required. Must be able to establish and maintain effective communication with co-workers, supervisors and the general public. Must be able to use word processing, spreadsheet, presentation and database software. Must be able to work extended hours when needed. Must be flexible and available to work various shifts, including nights, weekends and holidays. Position requires being on-call based on business needs. Must maintain strict confidentiality. Native American preferred.
This job description outlines the general scope and level of responsibilities associated with the position. It is not intended to be an employment contract, nor does it represent a comprehensive list of all duties, responsibilities, or requirements. The Sault Ste. Marie Tribe of Chippewa Indians reserves the right to modify, add, reassign, or combine job duties or positions, in whole or in part, at any time.


Powered by ExactHire:195113