GRC, Vulnerability Management Analyst

Acrisure, LLCGrand Rapids, MI
Onsite

About The Position

The Cybersecurity Vulnerability Governance Analyst is responsible for governing and overseeing the organization's Vulnerability Management Program from a risk, compliance, and accountability perspective. This role serves as the bridge between Cybersecurity, IT Operations, Infrastructure, Cloud, Application Development, and business stakeholders to ensure vulnerabilities are appropriately evaluated, assigned, remediated, accepted, or escalated according to established policies and risk tolerance. This position does not perform engineering work and instead, the analyst is responsible for vulnerability governance, risk reporting, metrics, exception management, policy adherence, and executive-level visibility into the organization's vulnerability posture. Success in this role means establishing strong accountability across the organization for vulnerability remediation while providing clear visibility into cyber risk, remediation performance, and program effectiveness. The analyst enables informed risk decisions, supports regulatory compliance, and helps reduce organizational exposure by ensuring vulnerabilities are managed in accordance with enterprise risk expectations and security governance standards.

Requirements

  • Bachelor's degree in Cybersecurity, Information Security, Information Technology, Risk Management, Business Administration, or a related field.
  • 3+ years of experience in cybersecurity governance, risk management, compliance, audit, or vulnerability management.
  • Knowledge of vulnerability management concepts, remediation workflows, vulnerability prioritization, and risk-based decision making.
  • Understanding of cybersecurity frameworks and standards including NIST, CIS Controls, ISO 27001, and COBIT.
  • Experience developing executive reporting, metrics, dashboards, and performance indicators.
  • Strong analytical, communication, and stakeholder management skills.
  • Ability to coordinate activities across technical and non-technical teams.

Nice To Haves

  • 5+ years of experience supporting enterprise cybersecurity governance or vulnerability management programs.
  • Experience with GRC platforms such as Archer, ServiceNow, MetricStream, or similar solutions.
  • Familiarity with vulnerability management platforms including Tenable, Qualys, Rapid7, Wiz, or Microsoft Defender Vulnerability Management.
  • Experience supporting regulatory compliance programs including SOX, HIPAA, NYDFS, PCI-DSS, SOC 2, or ISO certifications.
  • Relevant certifications such as: CRISC, CISA, CISM, CGRC, Security+
  • Candidates should be comfortable with an on-site presence to support collaboration, team leadership, and cross-functional partnership.

Responsibilities

  • Govern the enterprise Vulnerability Management Program to ensure alignment with cybersecurity policies, standards, and risk management requirements.
  • Track vulnerabilities through their lifecycle from identification through remediation, mitigation, risk acceptance, or closure.
  • Monitor vulnerability remediation performance against established service level objectives and risk-based remediation timelines.
  • Facilitate regular vulnerability review meetings with infrastructure, cloud, endpoint, application, and business stakeholders.
  • Coordinate remediation activities by validating ownership, accountability, and risk prioritization across responsible teams.
  • Review, document, and manage vulnerability exception requests, risk acceptances, and compensating control assessments.
  • Evaluate business and technical justifications for remediation extensions and risk acceptance decisions.
  • Ensure vulnerability risks are assessed and managed in accordance with enterprise risk tolerance and governance standards.
  • Escalate overdue vulnerabilities, repeat offenders, and unresolved risk issues to appropriate leadership and governance forums.
  • Partner with Enterprise Risk Management and Compliance teams to maintain consistent risk management practices.
  • Develop and maintain vulnerability management dashboards, scorecards, and executive reporting.
  • Track and report key performance indicators including remediation SLA compliance, vulnerability aging, exception volumes, and closure rates.
  • Analyze vulnerability trends, recurring findings, and remediation performance across business units and technology domains.
  • Support internal audits, external audits, regulatory examinations, and compliance assessments involving vulnerability management practices.
  • Provide risk-based reporting and recommendations to cybersecurity leadership, governance committees, and executive stakeholders.
  • Establish and maintain vulnerability management standards, procedures, workflows, and governance documentation.
  • Drive continuous improvement initiatives that enhance program maturity, accountability, and operational effectiveness.
  • Identify recurring control gaps and process deficiencies contributing to vulnerability exposure.
  • Partner with Security Operations, Security Engineering, Infrastructure, Application Development, and Cloud teams to improve remediation processes.
  • Support the development of governance policies, reporting frameworks, and vulnerability management program roadmaps.

Benefits

  • Comprehensive medical insurance
  • dental insurance
  • vision insurance
  • life and disability insurance
  • fertility benefits
  • wellness resources
  • paid sick time
  • Generous paid time off and holidays
  • Employee Assistance Program (EAP)
  • complimentary Calm app subscription
  • Immediate vesting in a 401(k) plan
  • Health Savings Account (HSA) and Flexible Spending Account (FSA) options
  • commuter benefits
  • employee discount programs
  • Paid maternity leave
  • paid paternity leave (including for adoptive parents)
  • legal plan options
  • pet insurance coverage
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service