1

Senior Information Security Risk Analyst Jobs in Michigan

$100K - $167K/yr

Escalate repeated non‑compliance and missed timelines to senior management, clearly articulating ... Strong analytical, organizational, and stakeholder‑management skills. Preferred Qualifications

New

We're hiring an IT Compliance Analyst to support our Information Security and IT Risk Management team through audit coordination, risk tracking, control remediation, and compliance initiatives. This ...

We're hiring an IT Compliance Analyst to support our Information Security and IT Risk Management team through audit coordination, risk tracking, control remediation, and compliance initiatives. This ...

IT Compliance Analyst

Grand Rapids, MI

$90K - $90K/yr

We're hiring an IT Compliance Analyst to support our Information Security and IT Risk Management team through audit coordination, risk tracking, control remediation, and compliance initiatives. This ...

Senior Information Security Engineer

Troy, MI · Hybrid

$101K - $137K/yr

About this opportunity We are looking for a hands-on, highly technical Senior Information Security ... Analyze, configure, and troubleshoot network traffic across Layers 2 through 7 to enforce ...

We are seeking an experienced IT Risk Analyst to support cybersecurity risk management, risk assessment, governance, and mitigation initiatives within a large public organization. Required Skills * 5 ...

We are seeking an experienced IT Risk Analyst to support cybersecurity risk management, risk assessment, governance, and mitigation initiatives within a large public organization. Required Skills * 5 ...

We are seeking an experienced IT Risk Analyst to support cybersecurity risk management, risk assessment, governance, and mitigation initiatives within a large public organization. Required Skills * 5 ...

We are seeking an experienced IT Risk Analyst to support cybersecurity risk management, risk assessment, governance, and mitigation initiatives within a large public organization. Required Skills * 5 ...

We are seeking an experienced IT Risk Analyst to support cybersecurity risk management, risk assessment, governance, and mitigation initiatives within a large public organization. Required Skills * 5 ...

We are seeking an experienced IT Risk Analyst to support cybersecurity risk management, risk assessment, governance, and mitigation initiatives within a large public organization. Required Skills * 5 ...

We are seeking an experienced IT Risk Analyst to support cybersecurity risk management, risk assessment, governance, and mitigation initiatives within a large public organization. Required Skills * 5 ...

We are seeking an experienced IT Risk Analyst to support cybersecurity risk management, risk assessment, governance, and mitigation initiatives within a large public organization. Required Skills * 5 ...

We are seeking an experienced IT Risk Analyst to support cybersecurity risk management, risk assessment, governance, and mitigation initiatives within a large public organization. Required Skills * 5 ...

We are seeking an experienced IT Risk Analyst to support cybersecurity risk management, risk assessment, governance, and mitigation initiatives within a large public organization. Required Skills * 5 ...

We are seeking an experienced IT Risk Analyst to support cybersecurity risk management, risk assessment, governance, and mitigation initiatives within a large public organization. Required Skills * 5 ...

Showing results 21-40

Senior Information Security Risk Analyst information

What does a senior information security risk analyst do?

A Senior Information Security Risk Analyst is responsible for identifying, evaluating, and mitigating risks to an organization's information systems and data. They conduct risk assessments, develop security policies, and recommend measures to protect against cyber threats and vulnerabilities. Additionally, they work closely with IT and business teams to ensure compliance with regulations and industry standards, and they often play a key role in incident response and security awareness training.

What are the key skills and qualifications needed to thrive as a senior information security risk analyst?

A Senior Information Security Risk Analyst requires a deep understanding of cybersecurity frameworks, risk assessment methodologies, and regulatory compliance, usually backed by a degree in information security or a related field. Familiarity with tools like risk management software (e.g., Archer, RSA), SIEM systems, and certifications such as CISSP, CISM, or CRISC are typically expected. Exceptional analytical thinking, attention to detail, and strong communication skills set top performers apart in this role. These competencies are crucial to effectively identify, evaluate, and mitigate security risks, ensuring the organization's information assets remain protected against evolving threats.

How does a senior information security risk analyst typically collaborate with other departments to manage organizational risk?

A Senior Information Security Risk Analyst regularly works with various departments such as IT, legal, compliance, and business units to identify and address security risks. This collaboration often includes conducting risk assessments, reviewing new projects for potential vulnerabilities, and providing guidance on security best practices. Effective communication skills are essential, as the analyst must translate technical risks into business impacts and help teams implement appropriate controls. Close teamwork ensures that security is integrated into all business processes and that the organization remains compliant with relevant regulations.

What is the difference between Senior Information Security Risk Analyst vs Information Security Analyst?

AspectSenior Information Security Risk AnalystInformation Security Analyst
CertificationsCISSP, CISA, CRISCCISSP, Security+, CEH
Work EnvironmentFocus on risk assessment, policy development, and strategic planningImplementing security measures, monitoring, and incident response
Employer & Industry UsageFinancial, healthcare, and large enterprises with complex security needsVariety of industries, including tech, retail, and government

Senior Information Security Risk Analysts typically handle advanced risk assessments and strategic security planning, often requiring certifications like CISSP or CISA. Information Security Analysts focus on implementing security controls and monitoring systems. Both roles are vital in maintaining organizational security but differ in scope and seniority.

What are popular job titles related to Senior Information Security Risk Analyst jobs in Michigan?

For Senior Information Security Risk Analyst jobs in Michigan, the most frequently searched job titles are:

What job categories do people searching Senior Information Security Risk Analyst jobs in Michigan look for?

The top searched job categories for Senior Information Security Risk Analyst jobs in Michigan are:

What cities in Michigan are hiring for Senior Information Security Risk Analyst jobs?

Cities in Michigan with the most Senior Information Security Risk Analyst job openings:

Infographic showing various Senior Information Security Risk Analyst job openings in Michigan as of August 2026, with employment types broken down into 1% As Needed, 74% Full Time, 20% Part Time, 1% Temporary, and 4% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution.

Assistant Vice President - IT Security Governance & Risk Management

State Street

Hybrid

$100K - $167K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

This job post has expired 1 day ago. Applications are no longer accepted.


Job description

Role Summary

We are seeking an experienced IT Security Governance & Risk Management leader to support enterprise‑wide remediation and compliance initiatives across Alternatives Investment Services (AIS) and Insurance technology platforms.

At the AVP level, this role acts as a hands‑on execution lead and escalation point , partnering with application owners, production support, infrastructure teams, and senior leadership to ensure timely remediation of identity, access, vulnerability, and application lifecycle risks in a highly regulated environment.

The role requires strong execution discipline, governance maturity, and the ability to drive outcomes across a large, complex application portfolio.

Key Responsibilities

Identity & Access Risk Management

  • Lead remediation of aged passwords and non‑human/service accounts across a large portfolio of AIS and Insurance applications.
  • Partner with application and production support teams to drive corrective actions including password rotation, account disablement, or decommissioning.
  • Track remediation activity through enterprise change management tools and ensure committed actions are executed on schedule.
  • Validate remediation outcomes using identity and access platforms and ensure evidence is audit‑ready.
  • Maintain centralized tracking, metrics, and reporting for non‑compliant accounts.
  • Escalate repeated non‑compliance and missed timelines to senior management, clearly articulating risk and impact.

Vulnerability & Patch Governance

  • Review weekly vulnerability reports and validate trends, new findings, and remediation progress.
  • Identify carried‑over and at‑risk vulnerabilities and engage application teams to ensure timely resolution.
  • Maintain high‑quality data sets and develop management views to support leadership decision‑making.
  • Produce weekly executive‑level reporting for AIS and Insurance portfolios, including risks, trends, and remediation timelines.
  • Coordinate with infrastructure and security teams to resolve issues and remove blockers.

Multi‑Factor Authentication (MFA) Compliance

  • Track and govern MFA implementation across AIS and Insurance applications.
  • Coordinate with application teams to manage timelines, dependencies, and attestations.
  • Provide clear, concise weekly status reporting to senior leadership.
  • Highlight risks and escalate applications not meeting agreed‑upon milestones.

Policy Violations & Control Exceptions

  • Review periodic policy violation reports related to application security controls.
  • Engage application owners to obtain remediation plans and progress updates.
  • Provide guidance on remediation of common violations and control gaps.
  • Escalate non‑responsive or non‑compliant applications to senior leadership.

Application Risk Remediation

  • Drive remediation of interactive and legacy account risks in collaboration with application owners and support teams.
  • Support teams with remediation approaches to align accounts with non‑interactive access standards.
  • Maintain status tracking and escalate stalled remediation activity where required.

Application Lifecycle Risk & Resilience

  • Ensure applications using end‑of‑life or unsupported components are properly documented in enterprise lifecycle risk repositories.
  • Validate remediation timelines and support application teams with required updates.
  • Escalate applications that fail to maintain accurate lifecycle risk data.

Financial & Delivery Transparency

  • Produce and maintain governance and status reporting for key technology initiatives within AIS and Insurance.
  • Partner with delivery teams to ensure accomplishments, upcoming activities, and risks are accurately captured and communicated.
  • Support audit and regulatory inquiries through consistent, high‑quality reporting.

Required Qualifications

  • 7–10+ years of experience in IT risk management, security governance, identity and access management, or regulatory compliance .
  • Proven ability to lead remediation activities across large, complex application portfolios .
  • Strong experience producing executive‑level reporting and communicating technical risk to senior stakeholders.
  • Demonstrated ability to drive accountability, follow‑through, and escalation in matrixed environments.
  • Strong analytical, organizational, and stakeholder‑management skills.

Preferred Qualifications

  • Experience within financial services, insurance, or other highly regulated industries .
  • Familiarity with identity governance, vulnerability management, MFA programs, and application security controls.
  • Hands‑on experience with enterprise tools such as ServiceNow, identity platforms, SharePoint, and reporting/analytics tools .
  • Prior experience supporting audits, regulatory reviews, or risk committees.

Work Requirement

  • Expected to work 3 days a week in the office

Salary Range:

$100,000 - $167,500 Annual

The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.

Employees are eligible to participate in State Street’s comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans.

For a full overview, visit .

About State Street

Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.

We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.

As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.

Discover more information on jobs at StateStreet.com/careers

Read our CEO Statement

Job Application Disclosure:

It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.


State Street logo

About State Street

Sourced by ZipRecruiter

State Street is one of the largest custodian banks, asset managers and asset intelligence companies in the world. From technology to product innovation, we're making our mark on the financial services industry. For more than two centuries, we've been helping our clients safeguard and steward the investments of millions of people. We provide investment servicing, data & analytics, investment research & trading and investment management to institutional clients.

Industry

Finance and insurance

Company size

10,000+ Employees

Headquarters location

Boston, MA, US

Year founded

1792

Social media