1

Security Risk Manager Jobs in Detroit, MI (NOW HIRING)

Information Security experience (preferably Third Party Risk Management and Compliance) Familiarity with SOC 1 (SSAE 16*) and SOC 2 (**AT101) reports Ability to write process, procedures, flowcharts ...

... security, risk, and compliance initiatives. The successful candidate will work closely with cybersecurity professionals, business stakeholders, project managers, and engineering teams to develop ...

Primary responsibilities include applications security, risk assessment, validation of security pen test results, problem resolution, system documentation, and system security management and support.

Job Title: IT Risk & Controls Manager Job Location: Detroit, MI Job Level: Mid - Senior Level Job ... Knowledge of security related standards and guidelines Understanding of SOX from a high level - do ...

next page

Showing results 1-20

Security Risk Manager information

See Detroit, MI salary details

$12

$23

$47

How much do security risk manager jobs pay per hour?

As of Jun 9, 2026, the average hourly pay for security risk manager in Detroit, MI is $23.77, according to ZipRecruiter salary data. Most workers in this role earn between $16.73 and $26.83 per hour, depending on experience, location, and employer.

What is the difference between Security Risk Manager vs Security Analyst?

AspectSecurity Risk ManagerSecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CISSP (optional)
Work EnvironmentStrategic, managerial, policy-focusedOperational, monitoring, incident response
Employer & Industry UsageOrganizations with risk management frameworksIT departments, cybersecurity teams

The Security Risk Manager focuses on identifying, assessing, and mitigating security risks at a strategic level, often managing policies and frameworks. In contrast, the Security Analyst handles day-to-day security monitoring, incident response, and vulnerability assessments. Both roles require cybersecurity certifications, but the Risk Manager's role is more strategic, while the Analyst's role is more technical and operational.

What are some common challenges Security Risk Managers face when implementing new security policies within an organization?

Security Risk Managers often encounter challenges such as resistance to change from employees, balancing security needs with business operations, and ensuring compliance with industry regulations. Gaining buy-in from various stakeholders requires strong communication and education efforts, as some team members may perceive new protocols as disruptive. Additionally, Security Risk Managers must continuously assess evolving threats while adapting policies to keep the organization protected without hindering productivity.

What are the key skills and qualifications needed to thrive as a Security Risk Manager, and why are they important?

To thrive as a Security Risk Manager, you need a solid understanding of risk assessment, security protocols, and regulatory compliance, typically supported by a degree in cybersecurity, information security, or a related field. Familiarity with risk management frameworks (like ISO 27001 or NIST), security information and event management (SIEM) systems, and certifications such as CISSP or CISM are commonly required. Strong analytical thinking, communication, and leadership skills help you effectively identify vulnerabilities and collaborate with stakeholders. These competencies are crucial for proactively managing threats, ensuring organizational resilience, and maintaining regulatory compliance.

What does a Security Risk Manager do?

A Security Risk Manager is responsible for identifying, assessing, and mitigating security risks that could impact an organization. They develop and implement risk management policies, conduct security audits, and ensure compliance with relevant laws and standards. Security Risk Managers work closely with other departments to create strategies that protect assets, data, and personnel from potential threats. Their role is critical in helping organizations minimize losses and maintain business continuity.
Infographic showing various Security Risk Manager job openings in Detroit, MI as of June 2026, with employment types broken down into 1% As Needed, 61% Full Time, 35% Part Time, 1% Temporary, and 2% Contract. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $49,443 per year, or $23.8 per hour.
Director, Product Security

Director, Product Security

Fifth Third Bank

Detroit, MI • On-site

Full-time

Posted 4 days ago


Fifth Third Bank rating

7.5

Company rating: 7.5 out of 10

Based on 109 frontline employees who took The Breakroom Quiz

87th of 141 rated banks


Job description

Job Summary:
Fifth Third Bank is a financial institution dedicated to improving the lives of its customers and communities. The Director, Product Security will lead the design and implementation of the Secure Software Development Lifecycle and Product Security program, ensuring security practices are embedded across application and platform development processes.
Responsibilities:
• Leading a small team of product security specialists
• Driving cross-functional alignment across Engineering, Architecture, and Security
• Ensuring consistent application of security controls at scale
• Providing a clear, auditable view of application security risk and control effectiveness
• Drive implementation of a world class enterprise Product Security and Secure SDLC control framework within the existing IT Target Operating Model.
• Develop and track Product Security KPIs/KRIs, including control adoption, coverage, and risk trends
• Ensure alignment of security controls across Application, API, Data, and Platform Security teams
• Partner with Enterprise Architecture to operationalize a scalable threat modeling practice
• Oversee execution of threat modeling and design security reviews for high-risk applications and APIs
• Promote adoption of secure design patterns and reference architectures
• Integrate security signals from AppSec, API Security, and EVM to produce holistic application risk views
• Identify systemic vulnerabilities and repeat risk patterns across the application portfolio
• Drive risk-based prioritization by providing inputs into Agile backlogs and delivery planning
• Define product incident response process into existing Bank incident response processes.
• Facilitate collaboration across Application Security, API Security, Data Security, Platform Security, EVM, First Line Business Controls and the Chief Software Engineering organization.
• Remove organizational impediments that limit adoption of secure development practices
• Challenge existing processes and identify opportunities for efficiency, consistency, and scalability improvements
• Provide audit-ready evidence of secure SDLC control effectiveness
• Align Product Security practices with regulatory expectations (e.g., GLBA, FFIEC, PCI)
• Ensure risk is identified, assessed, monitored, and reported appropriately
• Evaluate and improve Product Security processes to increase effectiveness and reduce friction
• Drive adoption of automation, reusable patterns, and scalable security practices
• Act as a leader of the Product Security craft, defining future direction and best practices
• Directly a small team of specialized Product Security professionals.
• Provide coaching, performance management, and career development for direct reports
• Foster a culture of continuous learning, collaboration, and accountability for security outcomes
• Lead through player-coach engagement, contributing directly to program execution while guiding team direction
• Influence and mentor engineers and security practitioners across multiple teams without direct authority
• Support hiring, development, and capability growth as the Product Security function matures.
Qualifications:
Required:
• Typically, will have at least 6-10 years of combined people leadership and hands-on experience in their particular craft.
• Bachelor’s or advanced degree in Computer Science/Information Systems or equivalent combination of education and experiences.
• Deep understanding of secure SDLC practices, application security, and threat modeling methodologies.
• Knowledge of modern application architectures (cloud-native, APIs, microservices, containers).
• Familiarity with vulnerability management processes and enterprise remediation practices.
• Understanding of regulatory expectations for security controls and audit evidence in financial services.
• Knowledge of enterprise architecture frameworks and secure design principles.
• Ability to operate effectively as a player-coach, balancing leadership and hands-on execution.
• Strong ability to influence across organizational boundaries without direct authority.
• Proven ability to translate technical vulnerabilities into business risk and engineering priorities.
• Strong analytical skills to identify systemic issues across large application portfolios.
• Ability to drive risk-based prioritization within Agile delivery models.
• Excellent communication, presentation, and interpersonal skills to engage both technical and executive audiences.
• Demonstrated ability to communicate complex information in a simplified way and meet fast paced deadlines.
• Critical Thinking and creative problem solving.
• Ability to establish credibility as a technical and strategic leader across multiple domains.
• Ability to balance security rigor with delivery speed, minimizing friction.
• Capability to remove organizational impediments and enable cross-team collaboration.
• Ability to scale security practices across a large, complex enterprise environment.
• Demonstrated ability to build trust and create a safe, collaborative, and effective working environment.
Company:
Fifth Third Bancorp is a financial services company that specializes in small business, retail banking, and investments. It is a sub-organization of Fifth Third Bank. Founded in 1858, the company is headquartered in Cincinnati, USA, with a team of 10001+ employees. The company is currently Late Stage.

What Fifth Third Bank employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Fifth Third Bank logo

About Fifth Third Bank

Sourced by ZipRecruiter

Fifth Third Bank, National Association established in 1858, is a diversified financial services company headquartered in Cincinnati, Ohio. Fifth Third is among the largest money managers in the Midwest. It operates four main businesses: Commercial Banking, Branch Banking, Consumer Lending, and Wealth & Asset Management.

Industry

Finance and insurance

Company size

10,000+ Employees

Headquarters location

Cincinnati, OH, US

Year founded

1858