1

Vulnerability Management Jobs in Michigan (NOW HIRING)

Cyber Security manager

Lansing, MI · On-site

$112K - $152K/yr

Familiarity and work experience leveraging NIST Moderate Controls (addressing Vulnerability Management & Asset Management) * Familiarity and work experience leveraging CIS Controls (addressing ...

SIEM - IBM QRadar Vulnerability Management - Qualys Scanning Asset Management Remedy Networking Cisco Firewalls - Checkpoint Load Balancer F5 Experience Required: 5+ years with a SIEM (QRadar ...

Server Engineer

Southfield, MI · On-site +1

$45 - $55/hr

You will partner closely with infrastructure, cybersecurity, vulnerability management, application, cloud, and program teams to ensure our server platforms remain secure, resilient, compliant, and ...

Safety Cyber Manager

Auburn Hills, MI · On-site

$109K - $148K/yr

Steer technical decisions for safety mechanism, secure boot, secure update, PKI architecture, and defense-in-depth strategies; oversee safety validation, penetration testing, vulnerability management ...

Roush is looking for a Cyber Security Architect to design, implement, and manage enterprise security controls across Microsoft 365, EDR tools, Vulnerability Management, and Data Loss Prevention (DLP ...

Roush is looking for a Cyber Security Architect to design, implement, and manage enterprise security controls across Microsoft 365, EDR tools, Vulnerability Management, and Data Loss Prevention (DLP ...

This role will support daily security operations, vulnerability and patch management, security monitoring, incident response, and audit activities while partnering with technical teams to strengthen ...

New

Roush is looking for a Cyber Security Architect to design, implement, and manage enterprise security controls across Microsoft 365, EDR tools, Vulnerability Management, and Data Loss Prevention (DLP ...

next page

Showing results 1-20

Vulnerability Management information

See Michigan salary details

$4

$53

$74

How much do vulnerability management jobs pay per hour?

As of Aug 17, 2026, the average hourly pay for vulnerability management in Michigan is $53.93, according to ZipRecruiter salary data. Most workers in this role earn between $44.54 and $63.96 per hour, depending on experience, location, and employer.

What are the common challenges faced in a vulnerability management role?

Professionals in Vulnerability Management often encounter challenges such as rapidly evolving threat landscapes, prioritizing remediation efforts among numerous vulnerabilities, and ensuring continuous communication between technical and non-technical stakeholders. They may also need to adapt to changing regulatory requirements and work within tight deadlines to protect the organization from emerging risks. As part of this role, you'll collaborate regularly with IT, security, and business teams to ensure remediation steps are effectively implemented. Continuous learning and adaptability are important, as technologies and attack vectors change frequently in this field. Being proactive and detail-oriented will help you address these challenges and advance your career in cybersecurity.

What does a vulnerability management do?

A vulnerability management professional is responsible for identifying, assessing, and prioritizing security vulnerabilities in an organization's systems and networks. They use tools like vulnerability scanners and follow best practices to mitigate risks, often working closely with security teams and maintaining documentation for compliance. This role requires technical knowledge of cybersecurity principles and may involve certifications such as CISSP or CompTIA Security+.

What are the key skills and qualifications needed to thrive in a vulnerability management position?

To thrive in Vulnerability Management, you need a strong understanding of cybersecurity principles, network protocols, and risk assessment, typically supported by a relevant degree and experience in information security. Familiarity with vulnerability scanning tools (such as Nessus or Qualys), security frameworks, and industry certifications like CISSP or CompTIA Security+ is highly valued. Exceptional analytical thinking, communication skills, and an ability to work collaboratively across IT and business teams help professionals excel in this field. These competencies are crucial to effectively identifying, prioritizing, and mitigating security risks in dynamic organizational environments.

Is vulnerability management a good career?

Vulnerability management is a valuable cybersecurity role focused on identifying and mitigating security weaknesses in systems. It requires knowledge of security tools, risk assessment, and often certifications like CISSP or CompTIA Security+; the field offers strong job growth and demand for skilled professionals.

What is vulnerability management?

A Vulnerability Management job involves identifying, assessing, prioritizing, and mitigating security vulnerabilities in an organization's systems, networks, and applications. Professionals in this role use tools like vulnerability scanners and threat intelligence to detect weaknesses and coordinate remediation efforts with IT and security teams. They also establish policies, monitor security risks, and ensure compliance with industry standards. The goal is to reduce the organization's exposure to cyber threats and improve overall security posture.

What are the most commonly searched types of Vulnerability Management jobs in Michigan?

The most popular types of Vulnerability Management jobs in Michigan are:

What are popular job titles related to Vulnerability Management jobs in Michigan?

For Vulnerability Management jobs in Michigan, the most frequently searched job titles are:

What cities in Michigan are hiring for Vulnerability Management jobs?

Cities in Michigan with the most Vulnerability Management job openings:

Infographic showing various Vulnerability Management job openings in Michigan as of August 2026, with employment types broken down into 77% Full Time, and 23% Contract. Highlights an 96% In-person, and 4% Remote job distribution, with an average salary of $112,168 per year, or $53.9 per hour.

GRC, Vulnerability Management Analyst

Acrisure

Grand Rapids, MI

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 3 days ago

New


Job description

About Acrisure

A global fintech leader, Acrisure empowers millions of ambitious businesses and individuals with the right solutions to grow boldly forward. By bringing cutting-edge technology and top-tier human support together, we connect clients with customized solutions across insurance, reinsurance, payroll, benefits, cybersecurity, mortgage services - and more.

In the last twelve years, Acrisure has grown in revenue from $38 million to nearly $5 billion, with over 19,000 colleagues in more than 20 countries. Acrisure was built on entrepreneurial spirit. Prioritizing leadership, accountability, and collaboration, we equip our teams to work at the highest levels possible.

Job Summary

The Cybersecurity Vulnerability Governance Analyst is responsible for governing and overseeing the organization's Vulnerability Management Program from a risk, compliance, and accountability perspective. This role serves as the bridge between Cybersecurity, IT Operations, Infrastructure, Cloud, Application Development, and business stakeholders to ensure vulnerabilities are appropriately evaluated, assigned, remediated, accepted, or escalated according to established policies and risk tolerance.

This position does not perform engineering work and instead, the analyst is responsible for vulnerability governance, risk reporting, metrics, exception management, policy adherence, and executive-level visibility into the organization's vulnerability posture.

Success in this role means establishing strong accountability across the organization for vulnerability remediation while providing clear visibility into cyber risk, remediation performance, and program effectiveness. The analyst enables informed risk decisions, supports regulatory compliance, and helps reduce organizational exposure by ensuring vulnerabilities are managed in accordance with enterprise risk expectations and security governance standards.

Responsibilities:

Essential Duties and Responsibilities - Vulnerability Governance

  • Govern the enterprise Vulnerability Management Program to ensure alignment with cybersecurity policies, standards, and risk management requirements.
  • Track vulnerabilities through their lifecycle from identification through remediation, mitigation, risk acceptance, or closure.
  • Monitor vulnerability remediation performance against established service level objectives and risk-based remediation timelines.
  • Facilitate regular vulnerability review meetings with infrastructure, cloud, endpoint, application, and business stakeholders.
  • Coordinate remediation activities by validating ownership, accountability, and risk prioritization across responsible teams.

Risk Management and Exception Governance

  • Review, document, and manage vulnerability exception requests, risk acceptances, and compensating control assessments.
  • Evaluate business and technical justifications for remediation extensions and risk acceptance decisions.
  • Ensure vulnerability risks are assessed and managed in accordance with enterprise risk tolerance and governance standards.
  • Escalate overdue vulnerabilities, repeat offenders, and unresolved risk issues to appropriate leadership and governance forums.
  • Partner with Enterprise Risk Management and Compliance teams to maintain consistent risk management practices.

Reporting, Metrics, and Compliance Oversight

  • Develop and maintain vulnerability management dashboards, scorecards, and executive reporting.
  • Track and report key performance indicators including remediation SLA compliance, vulnerability aging, exception volumes, and closure rates.
  • Analyze vulnerability trends, recurring findings, and remediation performance across business units and technology domains.
  • Support internal audits, external audits, regulatory examinations, and compliance assessments involving vulnerability management practices.
  • Provide risk-based reporting and recommendations to cybersecurity leadership, governance committees, and executive stakeholders.

Program Governance and Continuous Improvement

  • Establish and maintain vulnerability management standards, procedures, workflows, and governance documentation.
  • Drive continuous improvement initiatives that enhance program maturity, accountability, and operational effectiveness.
  • Identify recurring control gaps and process deficiencies contributing to vulnerability exposure.
  • Partner with Security Operations, Security Engineering, Infrastructure, Application Development, and Cloud teams to improve remediation processes.
  • Support the development of governance policies, reporting frameworks, and vulnerability management program roadmaps.

Minimum Qualifications

  • Bachelor's degree in Cybersecurity, Information Security, Information Technology, Risk Management, Business Administration, or a related field.
  • 3+ years of experience in cybersecurity governance, risk management, compliance, audit, or vulnerability management.
  • Knowledge of vulnerability management concepts, remediation workflows, vulnerability prioritization, and risk-based decision making.
  • Understanding of cybersecurity frameworks and standards including NIST, CIS Controls, ISO 27001, and COBIT.
  • Experience developing executive reporting, metrics, dashboards, and performance indicators.
  • Strong analytical, communication, and stakeholder management skills.
  • Ability to coordinate activities across technical and non-technical teams.

Preferred Qualifications

  • 5+ years of experience supporting enterprise cybersecurity governance or vulnerability management programs.
  • Experience with GRC platforms such as Archer, ServiceNow, MetricStream, or similar solutions.
  • Familiarity with vulnerability management platforms including Tenable, Qualys, Rapid7, Wiz, or Microsoft Defender Vulnerability Management.
  • Experience supporting regulatory compliance programs including SOX, HIPAA, NYDFS, PCI-DSS, SOC 2, or ISO certifications.
  • Relevant certifications such as:
  • CRISC
  • CISA
  • CISM
  • CGRC
  • Security+

Candidates should be comfortable with an on-site presence to support collaboration, team leadership, and cross-functional partnership.

Why Join Us:

At Acrisure, we're building more than a business, we're building a community where people can grow, thrive, and make an impact. Our benefits are designed to support every dimension of your life, from your health and finances to your family and future.

Making a lasting impact on the communities it serves, Acrisure has pledged more than $22 million through its partnerships with Corewell Health Helen DeVos Children's Hospital in Grand Rapids, Michigan, UPMC Children's Hospital in Pittsburgh, Pennsylvania and Blythedale Children's Hospital in Valhalla, New York.

Employee Benefits

We also offer our employees a comprehensive suite of benefits and perks, including:

  • Physical Wellness: Comprehensive medical insurance, dental insurance, and vision insurance; life and disability insurance; fertility benefits; wellness resources; and paid sick time.

  • Mental Wellness: Generous paid time off and holidays; Employee Assistance Program (EAP); and a complimentary Calm app subscription.

  • Financial Wellness: Immediate vesting in a 401(k) plan; Health Savings Account (HSA) and Flexible Spending Account (FSA) options; commuter benefits; and employee discount programs.

  • Family Care: Paid maternity leave and paid paternity leave (including for adoptive parents); legal plan options; and pet insurance coverage.

  • ... and so much more!

This list is not exhaustive of all available benefits. Eligibility and waiting periods may apply to certain offerings. Benefits may vary based on subsidiary entity and geographic location.

Acrisure is an Equal Opportunity Employer. We consider qualified applicants without regard to race, color, religion, sex, national origin, disability, or protected veteran status. Applicants may request reasonable accommodation by contacting leaves@acrisure.com.

Final candidates will be required to complete post-offer verification processes related to the role and in accordance with applicable laws.

California Residents: Learn more about our privacy practices for applicants by visiting the Acrisure California Applicant Privacy Policy.

Recruitment Fraud: Please visit here to learn more about our Recruitment Fraud Notice.

Welcome, your new opportunity awaits you.