Jobs › Lead IT Cyber Risk & Controls Analyst
Lead IT Cyber Risk & Controls Analyst
Role at a glance
- Category
- GRC
- Work arrangement
- Hybrid
- Location
- Detroit, MI
- Salary range
- $95,000 to $135,000
- Posted
- Jul 20, 2026
Blue Cross Blue Shield of Michigan is hiring a Lead IT Cyber Risk & Controls Analyst in Detroit, MI. This is a GRC role in the governance, risk, and compliance field, with a posted range of $95,000 to $135,000. Review the full details below and apply directly with Blue Cross Blue Shield of Michigan.
Conducts IT cybersecurity risk assessments, control evaluations, and NIST CSF mapping across health plan infrastructure. Reviews third-party cloud architectures for security vulnerabilities, HIPAA compliance, and data governance controls. Delivers risk mitigation roadmaps to technology and compliance
Full responsibilities and requirements are on Blue Cross Blue Shield of Michigan's application page.
Apply for this role →Location and market context
This role is based in Detroit, MI on a hybrid schedule. Local candidates benefit from being close to Blue Cross Blue Shield of Michigan's teams and regional hiring market, while the hybrid arrangement offers some flexibility. Confirm the exact in-office expectation and any relocation support with the employer.
About cybersecurity governance roles
Cybersecurity governance connects security control frameworks to business and regulatory risk, covering policy, risk assessment, and control assurance rather than hands-on operations. Roles like this one are typically evaluated against frameworks such as NIST CSF, ISO/IEC 27001, SOC 2, and security risk and control-assurance practices.
How to position yourself for this cybersecurity governance role
Strong candidates emphasize security control frameworks, risk assessment, policy and standards, and translating technical security posture into governance and board-level reporting. In your resume and outreach, tie your experience to how Blue Cross Blue Shield of Michigan would apply NIST CSF, ISO/IEC 27001, SOC 2, and security risk and control-assurance practices, and lead with concrete outcomes rather than duties.
Similar GRC roles
More GRC jobs: All GRC roles · Browse by category & location