1

Senior Cyber Security Risk Analyst Jobs in Michigan

Sr. Cybersecurity Risk Analyst

Grand Rapids, MI · On-site

$96K - $124K/yr

UFP Industries is seeking a Sr. Cybersecurity Risk Analyst to lead and mature their cybersecurity risk management program. This role involves identifying and assessing cybersecurity risks, ensuring ...

Cybersecurity Risk Manager

Detroit, MI · On-site +1

$70K - $140K/yr

As a 1 Line Technology Risk - Cybersecurity team member, you will apply your knowledge of ... Deliver timely escalation of all issues requiring attention to senior management. * Work with ...

Vice President of Cybersecurity

Detroit, MI · Hybrid

$148K - $186K/yr

The Vice President of Cybersecurity serves as Eccalon's senior-most cybersecurity executive ... Governance, Risk & Compliance (GRC) * Lead cybersecurity compliance efforts for government and ...

We are seeking a qualified Insider Risk Analyst to join our Digital Information Risk team. In this ... Cybersecurity certifications such as Certification in Certified Information Systems Security ...

Must have: • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a ... As a Cyber Risk Senior Associate, you will get the opportunity to contribute to our clients ...

Serve as a senior Cyber SME across compliance, architecture, and risk domains * Lead cybersecurity assessments, gap analyses, and risk evaluations * Provide expert recommendations to executives and ...

next page

Showing results 1-20

Senior Cyber Security Risk Analyst information

What are the key skills and qualifications needed to thrive as a Senior Cyber Security Risk Analyst, and why are they important?

To thrive as a Senior Cyber Security Risk Analyst, you need in-depth knowledge of risk assessment methodologies, cyber security frameworks (such as NIST or ISO 27001), and a strong background in IT or computer science, often supported by a bachelor's degree and relevant certifications. Familiarity with risk management tools, vulnerability scanning platforms, and security information and event management (SIEM) systems is typically required. Strong analytical thinking, communication skills, and the ability to influence stakeholders are critical soft skills for excelling in this role. These competencies help ensure organizations can proactively identify, assess, and mitigate security risks, thereby protecting sensitive assets and maintaining compliance.

What is the difference between Senior Cyber Security Risk Analyst vs Cyber Security Risk Analyst?

AspectSenior Cyber Security Risk AnalystCyber Security Risk Analyst
CertificationsCCSP, CISSP, CISACCSP, CISSP, CISA
Work EnvironmentMore strategic, leadership roles, mentoringOperational, technical risk assessments
ResponsibilitiesOversees risk management programs, policy developmentPerforms risk assessments, vulnerability analysis

The main difference lies in experience and scope. Senior Cyber Security Risk Analysts typically handle strategic planning and leadership, while Cyber Security Risk Analysts focus on technical risk assessments. Both roles require similar certifications and work within the same industry environment, but the senior position involves more oversight and decision-making responsibilities.

How does a Senior Cyber Security Risk Analyst typically collaborate with other departments to manage organizational risks?

A Senior Cyber Security Risk Analyst often works closely with IT, compliance, legal, and business units to assess and mitigate cybersecurity risks across the organization. This collaboration involves conducting risk assessments, sharing findings with relevant stakeholders, and developing strategies to address vulnerabilities. Effective communication and teamwork are essential, as the analyst must translate technical risks into business impacts and ensure all departments understand their roles in risk management. Regular meetings and cross-functional projects are common, fostering a proactive security culture throughout the organization.

What does a Senior Cyber Security Risk Analyst do?

A Senior Cyber Security Risk Analyst is responsible for identifying, assessing, and mitigating potential cybersecurity threats to an organization. They analyze security risks, develop strategies to protect sensitive data, and ensure compliance with industry regulations and best practices. Their role often involves conducting risk assessments, recommending security improvements, and collaborating with IT and business teams to strengthen the organization's overall cybersecurity posture.
What are the most commonly searched types of Cyber Security Risk Analyst jobs in Michigan? The most popular types of Cyber Security Risk Analyst jobs in Michigan are:
What are popular job titles related to Senior Cyber Security Risk Analyst jobs in Michigan? For Senior Cyber Security Risk Analyst jobs in Michigan, the most frequently searched job titles are:
What job categories do people searching Senior Cyber Security Risk Analyst jobs in Michigan look for? The top searched job categories for Senior Cyber Security Risk Analyst jobs in Michigan are:
What cities in Michigan are hiring for Senior Cyber Security Risk Analyst jobs? Cities in Michigan with the most Senior Cyber Security Risk Analyst job openings:
Sr. Cybersecurity Risk Analyst

Sr. Cybersecurity Risk Analyst

UFP Industries

Grand Rapids, MI • On-site

$96K - $124K/yr

Full-time

Posted 5 days ago


UFP Industries rating

7.2

Company rating: 7.2 out of 10

Based on 83 frontline employees who took The Breakroom Quiz

332nd of 518 rated manufacturers


Job description

Job Summary:
UFP Industries is seeking a Sr. Cybersecurity Risk Analyst to lead and mature their cybersecurity risk management program. This role involves identifying and assessing cybersecurity risks, ensuring compliance with regulatory requirements, and developing risk management processes while collaborating with IT teams.
Responsibilities:
• Lead the development and ongoing maintenance of the enterprise cybersecurity risk register, including risk identification, classification, ownership, and tracking.
• Conduct and lead risk assessments for systems, applications, projects, and business initiatives.
• Develop and implement risk management processes, methodologies, and reporting metrics.
• Facilitate risk review sessions with business and IT stakeholders to ensure accountability and transparency.
• Develop and track risk mitigation and remediation plans to closure.
• Support and maintain the organization’s CMMC compliance program, including control mapping, evidence collection, and audit readiness.
• Partner with internal stakeholders (IT, Legal, HR, Plant Operations) to ensure alignment with CMMC and other regulatory requirements.
• Assist in preparing documentation and responses for assessments, audits, and regulatory inquiries.
• Monitor evolving compliance requirements and translate them into actionable internal controls.
• Develop and mature a third-party cybersecurity risk management program.
• Conduct security risk assessments of vendors, SaaS providers, Software, and external partners.
• Evaluate vendor security posture, shared responsibility models, and contractual security requirements.
• Partner with procurement and legal teams to integrate security requirements into vendor onboarding and contracting processes.
• Collaborate with IT and engineering teams to develop, implement, and maintain cybersecurity standards and secure configuration baselines.
• Ensure security requirements are embedded into system design, architecture, and operational processes.
• Provide risk-based guidance on system hardening, segmentation, and control implementation.
• Support the development of policies, standards, and procedures that are practical, enforceable, and auditable.
• Communicate risk findings, trends, and recommendations to technical and non-technical stakeholders, including leadership.
• Develop reporting for executive audiences, including risk summaries, metrics, and program maturity updates.
• Support audit committee and leadership reporting as needed.
• Stay current on cybersecurity threats, regulatory changes, and industry best practices.
• Identify opportunities to improve risk visibility, coverage, and program efficiency.
• Mentor junior analysts and contribute to the maturity of the GRC function.
Qualifications:
Required:
• Bachelor’s degree in Information Security, Computer Science, or related field (or equivalent experience).
• 5+ years of experience in cybersecurity risk, governance, or compliance roles.
• Experience building or maintaining a cybersecurity risk register and risk management processes.
• Strong understanding of security frameworks (e.g., NIST, CMMC, ISO 27001).
• Experience conducting third-party/vendor risk assessments.
• Strong analytical, problem-solving, and risk evaluation skills.
• Ability to translate technical risks into business impact.
• Strong written and verbal communication skills.
Preferred:
• Experience supporting CMMC assessments or similar regulatory compliance programs.
• Familiarity with manufacturing or operational technology (OT) environments.
• Experience developing security standards or working closely with infrastructure and engineering teams.
• Professional certifications such as CISSP, CISM, CRISC, or similar.
Company:
UFP Industries manufactures and sells variety of products used in residential and commercial construction such as wood decks and lumbers. Founded in 1955, the company is headquartered in Michigan, USA, with a team of 10001+ employees. The company is currently Late Stage.

What UFP Industries employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


UFP Industries logo

About UFP Industries

Sourced by ZipRecruiter

Universal Forest Products, Inc., is a U.S.-based global corporation that finds reward in its roots and its hard-earned success. Founded in 1955 as a supplier of lumber to the manufactured housing industry, Universal today is a multibillion-dollar holding company with subsidiaries around the globe that serve three robust markets: retail, industrial and construction. Since 1993, Universal has been publicly traded (Nasdaq: UFPI). We re headquartered in Grand Rapids, Michigan.

Industry

Wood product manufacturing

Company size

10,000+ Employees

Headquarters location

Grand Rapids, MI, US

Year founded

1955

Social media