Job Summary The Cybersecurity Vulnerability Governance Analyst is responsible for governing and overseeing the organization's Vulnerability Management Program from a risk, compliance, and ...
Job Summary The Cybersecurity Vulnerability Governance Analyst is responsible for governing and overseeing the organization's Vulnerability Management Program from a risk, compliance, and ...
Dimondale, MI - IT - DTMB - Cyber Security - CIP - IT Security Analyst 3 - Vulnerability Management
Dimondale, MI · On-site
Responsibilities : • The Security Analyst position works as a member of the Vulnerability Management Team. • The Senior Security Analyst position reviews and remediates cyber incidents and ...
Dimondale, MI - IT - DTMB - Cyber Security - CIP - IT Security Analyst 3 - Vulnerability Management
Dimondale, MI · On-site
Responsibilities : • The Security Analyst position works as a member of the Vulnerability Management Team. • The Senior Security Analyst position reviews and remediates cyber incidents and ...
IT Security Analyst 3
Dimondale, MI · On-site
Supports vulnerability management scanning and reporting tools.Conducts internal vulnerability ... Conducts data analysis of vulnerability management data, often integrated with other data sources ...
Quick apply
IT Security Analyst 3
Dimondale, MI · On-site
Supports vulnerability management scanning and reporting tools.Conducts internal vulnerability ... Conducts data analysis of vulnerability management data, often integrated with other data sources ...
IT Security Analyst 3
Dimondale, MI · On-site
Supports vulnerability management scanning and reporting tools. * Conducts internal vulnerability ... Conducts data analysis of vulnerability management data, often integrated with other data sources ...
IT Security Analyst 3
Dimondale, MI · On-site
Supports vulnerability management scanning and reporting tools. * Conducts internal vulnerability ... Conducts data analysis of vulnerability management data, often integrated with other data sources ...
IT Security Analyst 3
Dimondale, MI · Hybrid
Supports vulnerability management scanning and reporting tools. * Conducts internal vulnerability ... Conducts data analysis of vulnerability management data, often integrated with other data sources ...
IT Security Analyst 3
Dimondale, MI · Hybrid
Supports vulnerability management scanning and reporting tools. * Conducts internal vulnerability ... Conducts data analysis of vulnerability management data, often integrated with other data sources ...
Executing vulnerability and patch management tasks across infrastructure, middleware, and ... Analyzing exposure data, asset criticality, exploitability, and attack paths to help prioritize ...
Executing vulnerability and patch management tasks across infrastructure, middleware, and ... Analyzing exposure data, asset criticality, exploitability, and attack paths to help prioritize ...
Executing vulnerability and patch management tasks across infrastructure, middleware, and ... Analyzing exposure data, asset criticality, exploitability, and attack paths to help prioritize ...
Executing vulnerability and patch management tasks across infrastructure, middleware, and ... Analyzing exposure data, asset criticality, exploitability, and attack paths to help prioritize ...
CYBER SECURITY
Wyoming, MI · On-site
... vulnerability management, incident response, and healthcare security compliance. Key Responsibilities * Monitor security alerts and investigate potential security incidents * Analyze security logs ...
CYBER SECURITY
Wyoming, MI · On-site
... vulnerability management, incident response, and healthcare security compliance. Key Responsibilities * Monitor security alerts and investigate potential security incidents * Analyze security logs ...
This role will support daily security operations, vulnerability and patch management, security ... Strong analytical, problem-solving, communication, and organizational skills with the ability to ...
This role will support daily security operations, vulnerability and patch management, security ... Strong analytical, problem-solving, communication, and organizational skills with the ability to ...
Translate complex vulnerability data into business risk for non-technical stakeholders, providing cost-benefit analysis for proposed security controls. Incident Lifecycle Management: Lead the triage ...
Quick apply
Translate complex vulnerability data into business risk for non-technical stakeholders, providing cost-benefit analysis for proposed security controls. Incident Lifecycle Management: Lead the triage ...
Prioritize risk reduction and remediation tasks to support a vulnerability management program ... Conduct research, analysis, and correlation of events across a wide variety of data sources.
Prioritize risk reduction and remediation tasks to support a vulnerability management program ... Conduct research, analysis, and correlation of events across a wide variety of data sources.
Prioritize risk reduction and remediation tasks to support a vulnerability management program ... Conduct research, analysis, and correlation of events across a wide variety of data sources.
Prioritize risk reduction and remediation tasks to support a vulnerability management program ... Conduct research, analysis, and correlation of events across a wide variety of data sources.
Cyber Manager - Cloud DevSecOps
$109K - $148K/yr
... vulnerability remediation, including root-cause analysis, remediation recommendations, automated code fixes, remediation validation, and integration with existing AppSec, vulnerability management ...
Cyber Manager - Cloud DevSecOps
$109K - $148K/yr
... vulnerability remediation, including root-cause analysis, remediation recommendations, automated code fixes, remediation validation, and integration with existing AppSec, vulnerability management ...
Contribute to security monitoring, vulnerability management, incident response, identity and access management, and threat detection activities. * Analyze security events, operational data, and cyber ...
Contribute to security monitoring, vulnerability management, incident response, identity and access management, and threat detection activities. * Analyze security events, operational data, and cyber ...
$53.25 - $69.50/hr
Support vulnerability management activities and investigate security events using established procedures and analytical tools. * Work closely with users and customers to understand technical needs ...
New
$53.25 - $69.50/hr
Support vulnerability management activities and investigate security events using established procedures and analytical tools. * Work closely with users and customers to understand technical needs ...
New
Contribute to security monitoring, vulnerability management, incident response, identity and access management, and threat detection activities. * Analyze security events, operational data, and cyber ...
Contribute to security monitoring, vulnerability management, incident response, identity and access management, and threat detection activities. * Analyze security events, operational data, and cyber ...
Senior Cyber Security Analyst
Wixom, MI · On-site
$95K - $123K/yr
... and vulnerability management. * Leverage automation to streamline workflows and increase ... cause analysis. * Demonstrated experience designing and executing proactive threat hunting ...
Senior Cyber Security Analyst
Wixom, MI · On-site
$95K - $123K/yr
... and vulnerability management. * Leverage automation to streamline workflows and increase ... cause analysis. * Demonstrated experience designing and executing proactive threat hunting ...
Senior System Engineer - Detroit, MI 48239
Detroit, MI · On-site
$103K - $141K/yr
Support the decision on RAAs. • Lead or support the local Vulnerability Management meetings, providing SME for analyzing and remediating vulnerabilities according to RISE defined timelines. • ...
Senior System Engineer - Detroit, MI 48239
Detroit, MI · On-site
$103K - $141K/yr
Support the decision on RAAs. • Lead or support the local Vulnerability Management meetings, providing SME for analyzing and remediating vulnerabilities according to RISE defined timelines. • ...
This role operates and integrates AirLife's SIEM, EDR, vulnerability management, and cloud security ... Strong root cause analysis and technical troubleshooting skills. * Experience with backup and ...
This role operates and integrates AirLife's SIEM, EDR, vulnerability management, and cloud security ... Strong root cause analysis and technical troubleshooting skills. * Experience with backup and ...
Cloud Security Engineer
Birmingham, MI · On-site
... vulnerability management, and related security functions * Working knowledge of Azure Log Analytics, Kusto Query Language (KQL), PowerShell, Bash, and REST APIs. * Working knowledge of identity and ...
Cloud Security Engineer
Birmingham, MI · On-site
... vulnerability management, and related security functions * Working knowledge of Azure Log Analytics, Kusto Query Language (KQL), PowerShell, Bash, and REST APIs. * Working knowledge of identity and ...
Vulnerability Management Analyst information
See Michigan salary details
$61.5K - $69.8K
20% of jobs
$72.6K is the 25th percentile. Wages below this are outliers.
$69.8K - $78.2K
16% of jobs
$78.2K - $86.5K
1% of jobs
$86.5K - $94.8K
9% of jobs
$94.8K - $103.2K
2% of jobs
$103.2K - $111.5K
0% of jobs
The median wage is $112.6K / yr.
$111.5K - $119.9K
17% of jobs
$119.9K - $128.2K
6% of jobs
$133K is the 75th percentile. Wages above this are outliers.
$128.2K - $136.6K
7% of jobs
$136.6K - $144.9K
4% of jobs
$144.9K - $153.2K
18% of jobs
$61.5K
$109.1K
$153.2K
How much do vulnerability management analyst jobs pay per year?
What is a vulnerability management analyst?
A Vulnerability Management Analyst is responsible for identifying, assessing, and mitigating security vulnerabilities within an organization's IT infrastructure. They use scanning tools, analyze threat data, and collaborate with teams to prioritize and remediate risks. Their role is crucial in maintaining cybersecurity by ensuring systems are patched and configured securely. Additionally, they may develop reports and provide recommendations to improve security posture. This position requires knowledge of security frameworks, risk assessment, and vulnerability management tools.
What are the typical daily responsibilities of a vulnerability management analyst?
On a typical day, a Vulnerability Management Analyst reviews system scans, analyzes reports for potential vulnerabilities, and works with IT or security teams to prioritize remediation efforts. They may also track the status of vulnerabilities, ensure timely patch application, and help develop or update security policies. Collaboration with various departments is common to coordinate testing, remediation, and communicate risk summary findings. This role requires keeping up with emerging threats and sometimes participating in security audits or compliance reviews, making it both dynamic and integral to the organization's overall cybersecurity posture.
What are the key skills and qualifications needed to thrive as a vulnerability management analyst?
A Vulnerability Management Analyst requires a strong background in cybersecurity principles, risk assessment, and IT networking, often supported by a relevant degree or certifications like CompTIA Security+, CISSP, or CEH. Experience with vulnerability scanning tools (such as Nessus, Qualys, or Rapid7) and familiarity with ticketing systems or SIEM platforms is essential. Strong analytical skills, attention to detail, effective communication, and the ability to work collaboratively help individuals succeed in this role. These capabilities are vital to proactively identify, assess, and mitigate security vulnerabilities, ensuring the organization's digital assets remain secure and compliant.
What are the most commonly searched types of Vulnerability Management Analyst jobs in Michigan?
The most popular types of Vulnerability Management Analyst jobs in Michigan are:
What are popular job titles related to Vulnerability Management Analyst jobs in Michigan?
For Vulnerability Management Analyst jobs in Michigan, the most frequently searched job titles are:
What job categories do people searching Vulnerability Management Analyst jobs in Michigan look for?
The top searched job categories for Vulnerability Management Analyst jobs in Michigan are:

GRC, Vulnerability Management Analyst
Grand Rapids, MI
7.5
Based on 122 frontline employees who took The Breakroom Quiz
225th of 315 rated insurance
People enjoy working here
Good employer
Paid breaks
Recommended by parents
Respectful managers
Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Posted 17 days ago
Job description
About Acrisure
A global fintech leader, Acrisure empowers millions of ambitious businesses and individuals with the right solutions to grow boldly forward. By bringing cutting-edge technology and top-tier human support together, we connect clients with customized solutions across insurance, reinsurance, payroll, benefits, cybersecurity, mortgage services - and more.
In the last twelve years, Acrisure has grown in revenue from $38 million to nearly $5 billion, with over 19,000 colleagues in more than 20 countries. Acrisure was built on entrepreneurial spirit. Prioritizing leadership, accountability, and collaboration, we equip our teams to work at the highest levels possible.
Job Summary
The Cybersecurity Vulnerability Governance Analyst is responsible for governing and overseeing the organization's Vulnerability Management Program from a risk, compliance, and accountability perspective. This role serves as the bridge between Cybersecurity, IT Operations, Infrastructure, Cloud, Application Development, and business stakeholders to ensure vulnerabilities are appropriately evaluated, assigned, remediated, accepted, or escalated according to established policies and risk tolerance.
This position does not perform engineering work and instead, the analyst is responsible for vulnerability governance, risk reporting, metrics, exception management, policy adherence, and executive-level visibility into the organization's vulnerability posture.
Success in this role means establishing strong accountability across the organization for vulnerability remediation while providing clear visibility into cyber risk, remediation performance, and program effectiveness. The analyst enables informed risk decisions, supports regulatory compliance, and helps reduce organizational exposure by ensuring vulnerabilities are managed in accordance with enterprise risk expectations and security governance standards.
Responsibilities:
Essential Duties and Responsibilities - Vulnerability Governance
- Govern the enterprise Vulnerability Management Program to ensure alignment with cybersecurity policies, standards, and risk management requirements.
- Track vulnerabilities through their lifecycle from identification through remediation, mitigation, risk acceptance, or closure.
- Monitor vulnerability remediation performance against established service level objectives and risk-based remediation timelines.
- Facilitate regular vulnerability review meetings with infrastructure, cloud, endpoint, application, and business stakeholders.
- Coordinate remediation activities by validating ownership, accountability, and risk prioritization across responsible teams.
Risk Management and Exception Governance
- Review, document, and manage vulnerability exception requests, risk acceptances, and compensating control assessments.
- Evaluate business and technical justifications for remediation extensions and risk acceptance decisions.
- Ensure vulnerability risks are assessed and managed in accordance with enterprise risk tolerance and governance standards.
- Escalate overdue vulnerabilities, repeat offenders, and unresolved risk issues to appropriate leadership and governance forums.
- Partner with Enterprise Risk Management and Compliance teams to maintain consistent risk management practices.
Reporting, Metrics, and Compliance Oversight
- Develop and maintain vulnerability management dashboards, scorecards, and executive reporting.
- Track and report key performance indicators including remediation SLA compliance, vulnerability aging, exception volumes, and closure rates.
- Analyze vulnerability trends, recurring findings, and remediation performance across business units and technology domains.
- Support internal audits, external audits, regulatory examinations, and compliance assessments involving vulnerability management practices.
- Provide risk-based reporting and recommendations to cybersecurity leadership, governance committees, and executive stakeholders.
Program Governance and Continuous Improvement
- Establish and maintain vulnerability management standards, procedures, workflows, and governance documentation.
- Drive continuous improvement initiatives that enhance program maturity, accountability, and operational effectiveness.
- Identify recurring control gaps and process deficiencies contributing to vulnerability exposure.
- Partner with Security Operations, Security Engineering, Infrastructure, Application Development, and Cloud teams to improve remediation processes.
- Support the development of governance policies, reporting frameworks, and vulnerability management program roadmaps.
Minimum Qualifications
- Bachelor's degree in Cybersecurity, Information Security, Information Technology, Risk Management, Business Administration, or a related field.
- 3+ years of experience in cybersecurity governance, risk management, compliance, audit, or vulnerability management.
- Knowledge of vulnerability management concepts, remediation workflows, vulnerability prioritization, and risk-based decision making.
- Understanding of cybersecurity frameworks and standards including NIST, CIS Controls, ISO 27001, and COBIT.
- Experience developing executive reporting, metrics, dashboards, and performance indicators.
- Strong analytical, communication, and stakeholder management skills.
- Ability to coordinate activities across technical and non-technical teams.
Preferred Qualifications
- 5+ years of experience supporting enterprise cybersecurity governance or vulnerability management programs.
- Experience with GRC platforms such as Archer, ServiceNow, MetricStream, or similar solutions.
- Familiarity with vulnerability management platforms including Tenable, Qualys, Rapid7, Wiz, or Microsoft Defender Vulnerability Management.
- Experience supporting regulatory compliance programs including SOX, HIPAA, NYDFS, PCI-DSS, SOC 2, or ISO certifications.
- Relevant certifications such as:
- CRISC
- CISA
- CISM
- CGRC
- Security+
Candidates should be comfortable with an on-site presence to support collaboration, team leadership, and cross-functional partnership.
Why Join Us:
At Acrisure, we're building more than a business, we're building a community where people can grow, thrive, and make an impact. Our benefits are designed to support every dimension of your life, from your health and finances to your family and future.
Making a lasting impact on the communities it serves, Acrisure has pledged more than $22 million through its partnerships with Corewell Health Helen DeVos Children's Hospital in Grand Rapids, Michigan, UPMC Children's Hospital in Pittsburgh, Pennsylvania and Blythedale Children's Hospital in Valhalla, New York.
Employee Benefits
We also offer our employees a comprehensive suite of benefits and perks, including:
Physical Wellness: Comprehensive medical insurance, dental insurance, and vision insurance; life and disability insurance; fertility benefits; wellness resources; and paid sick time.
Mental Wellness: Generous paid time off and holidays; Employee Assistance Program (EAP); and a complimentary Calm app subscription.
Financial Wellness: Immediate vesting in a 401(k) plan; Health Savings Account (HSA) and Flexible Spending Account (FSA) options; commuter benefits; and employee discount programs.
Family Care: Paid maternity leave and paid paternity leave (including for adoptive parents); legal plan options; and pet insurance coverage.
... and so much more!
This list is not exhaustive of all available benefits. Eligibility and waiting periods may apply to certain offerings. Benefits may vary based on subsidiary entity and geographic location.
Acrisure is an Equal Opportunity Employer. We consider qualified applicants without regard to race, color, religion, sex, national origin, disability, or protected veteran status. Applicants may request reasonable accommodation by contacting leaves@acrisure.com.
Final candidates will be required to complete post-offer verification processes related to the role and in accordance with applicable laws.
California Residents: Learn more about our privacy practices for applicants by visiting the Acrisure California Applicant Privacy Policy.
Recruitment Fraud: Please visit here to learn more about our Recruitment Fraud Notice.
Welcome, your new opportunity awaits you.
About Acrisure
Sourced by ZipRecruiter
Industry
Insurance services
Company size
5,001 - 10,000 Employees
Headquarters location
Grand Rapids, MI, US