Senior Risk and Compliance Analyst

Posted 3 Days Ago
Be an Early Applicant
3 Locations
In-Office
97K-148K Annually
Senior level
Food • Marketing Tech
The Role
Lead and mature IT GRC and third-party risk management programs: perform vendor risk assessments and due diligence, monitor remediation, maintain risk intake and registers, develop metrics and automation, collaborate with InfoSec, Procurement, Legal, SOC, and business stakeholders to strengthen governance and risk-informed decisions.
Summary Generated by Built In

Job Description

Position Summary: 

The Senior Risk and Compliance Analyst is a key member of the IT Governance, Risk, and Compliance (GRC) team, responsible for supporting and advancing the organization’s IT risk, compliance, and third-party risk management (TPRM) programs. This role partners with stakeholders across IT, Information Security, Procurement, Legal, OT, and the business to assess technology and vendor-related risks, strengthen governance practices, and support risk-informed decision-making. 

 

The Analyst will help lead and mature the IT Third-Party Risk Management (TPRM) program by supporting vendor risk assessments, due diligence, ongoing monitoring, remediation tracking, and continuous improvement efforts. This role also contributes to risk intake, reporting, metrics, and automation initiatives that improve visibility, consistency, and efficiency across the broader GRC program. 

 

Responsibilities:  

  • Act as an advisor for IT GRC, providing guidance to IT and business stakeholders while advancing strategic GRC initiatives. 

  • Lead and enhance the IT third-party risk management program, encompassing vendor risk assessments, onboarding procedures, ongoing monitoring, and remediation of identified risks. 

  • Collaborate with Information Security, IT, Procurement, Legal and business teams to evaluate third-party vendors, applications, and services enterprise-wide. 

  • Review third-party security documentation, including SOC reports, ISO certifications, security questionnaires, policies, and other relevant evidence to assess control maturity and residual risk. 

  • Partner with the Security Operations Center (SOC) to monitor emerging threats, industry developments, and incident response insights, leveraging findings to assess and refine the risk profiles of critical vendors and technology supply chain partners. 

  • Support the end-to-end risk intake workflow, help to maintain the IT risk register process, and ensure timely escalation of technology risks. 

  • Collaborate with the IT Compliance Managers to support risk assessments for internal initiatives, third-party relationships, and critical business processes. 

  • Contribute to the development of security metrics and dashboards, leveraging automated and manual processes to produce relevant KRIs/KPIs that measure and communicate risk exposure and program effectiveness. 

  • Maintain current knowledge of industry best practices and monitor the legal and regulatory environment for developments that may require changes to policies and practices. 

  • Drive automation efforts within the GRC and third-party risk programs by identifying manual or repetitive tasks and implementing technology solutions, or workflow tools to improve efficiency, consistency, and reporting. 

  • Continuously seek opportunities to optimize and modernize GRC operations through technical innovation and automation. 

 

Required Qualifications: 

  • 4 or more years of experience in Information Security, Risk Management, Audit, IT Governance, IT Compliance, or related discipline. 

  • Proven ability to lead and mature an IT Third-Party Risk Management (TPRM) program, including governance, risk assessments, and continuous improvement initiatives. 

  • Strong understanding of third-party risk management practices across the vendor lifecycle, including due diligence, onboarding, ongoing monitoring, remediation, and offboarding. 

  • Broad, generalist understanding of information security risk and compliance—comfortable operating across risk, audit, policy, and third-party risk areas. 

  • Working knowledge of industry frameworks and regulatory requirements, including NIST, ISO, CIS, PCI-DSS, SOX, GDPR, CCPA, and HIPAA. 

  • High degree of ownership, self-direction, and demonstrated thought leadership. 

  • Ability to analyze manual processes and implement technical solutions to enhance efficiency and accuracy. 

 

Preferred Qualifications: 

  • Bachelor’s degree in business administration, compliance, information systems, privacy, or related field; equivalent work or education-related experience considered. 

  • One or more relevant certifications: CRISC, CISSP, CISA, CISM, CGEIT, GCCC, GSEC, GISP. 

  • Proven ability to interact with key stakeholders and align priorities based on risk. 

  • Familiarity with GRC platforms (e.g., LogicGate, Optro, OneTrust, Workiva). 

  • Strong written and verbal communication skills; able to present complex risk and compliance topics to both technical and non-technical audiences. 

  • Proficient in Microsoft Excel, Word, and PowerPoint. 

 

 

ADA Physical/Mental/Workplace Requirements: 

  • Occasional lifting up to 25 lbs 

  • Sitting, working at desk/personal computer for extended periods of time 

  • Primary work environment is professional corporate office 

  • Ability to travel commercially and internationally. 

#LI-JV1

Location

Rochester, New York

Additional Locations

Chicago, Illinois, San Antonio, Texas

Job Type

Full time

Job Area

Information Technology

The salary range for this role is:

$96,700.00 - $148,100.00

This is the lowest to highest salary we in good faith believe we would pay for this role at the time of this posting.  Our compensation is based on cost of labor. For remote locations or positions open to multiple locations, the pay range may reflect several US geographic markets, including the lowest geographic market minimum to the highest geographic market maximum. We may ultimately pay more or less than the posted range, and the range may be modified in the future. An employee’s pay position within the salary range will be based on several factors including, but not limited to, the prevailing minimum wage for the location, relevant education, qualifications, certifications, experience, skills, seniority, geographic location, performance, shift, travel requirements, sales or revenue-based metrics, any collective bargaining agreements, and business or organizational needs.  At Constellation Brands, it is not typical for an individual to be hired at the high end of the range for their role, and compensation decisions are dependent upon the facts and circumstances of each position and candidate. We offer comprehensive package of benefits including paid time off, medical/dental/vision insurance, 401(k), and any other benefits to eligible employees.

Note: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of any bonus, commission, or any other form of compensation that are allocable to a particular employee remains in the Company's sole discretion unless and until paid and may be modified at the Company’s sole discretion, consistent with the law.

Equal Opportunity

Constellation Brands is committed to a continuing program of equal employment opportunity. All persons have equal employment opportunities with Constellation Brands, regardless of their sex, race, color, age, religion, creed, sexual orientation, national origin or citizenship, ancestry, physical or mental disability, medical condition (cancer or genetic characteristics), marital status, gender (including gender identity or gender expression), familial status, military or veteran status, genetic information, pregnancy, childbirth, breastfeeding, or related conditions (or any other group or category within the framework of the applicable discrimination laws and regulations).

Skills Required

  • 4 or more years of experience in Information Security, Risk Management, Audit, IT Governance, IT Compliance, or related discipline.
  • Proven ability to lead and mature an IT Third-Party Risk Management (TPRM) program, including governance, risk assessments, and continuous improvement initiatives.
  • Strong understanding of third-party risk management practices across the vendor lifecycle, including due diligence, onboarding, ongoing monitoring, remediation, and offboarding.
  • Broad, generalist understanding of information security risk and compliance across risk, audit, policy, and third-party risk areas.
  • Working knowledge of industry frameworks and regulatory requirements (NIST, ISO, CIS, PCI-DSS, SOX, GDPR, CCPA, HIPAA).
  • High degree of ownership, self-direction, and demonstrated thought leadership.
  • Ability to analyze manual processes and implement technical solutions to enhance efficiency and accuracy.
  • Bachelor's degree in business administration, compliance, information systems, privacy, or related field (or equivalent experience).
  • Relevant certifications (CRISC, CISSP, CISA, CISM, CGEIT, GCCC, GSEC, GISP).
  • Proven ability to interact with key stakeholders and align priorities based on risk.
  • Familiarity with GRC platforms (e.g., LogicGate, Optro, OneTrust, Workiva).
  • Strong written and verbal communication skills; ability to present complex risk and compliance topics to technical and non-technical audiences.
  • Proficient in Microsoft Excel, Word, and PowerPoint.

Constellation Brands Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Constellation Brands and has not been reviewed or approved by Constellation Brands.

  • Healthcare Strength Healthcare coverage is described as comprehensive, spanning medical, dental, and vision offerings alongside wellness resources. Additional supports such as telemedicine and mental-health programs are positioned as part of the overall package.
  • Retirement Support Retirement benefits appear comparatively strong, with a 401(k) match structure and an added non-elective contribution described in the materials. Profit sharing and employee stock purchase access are also included in the broader financial-security toolkit.
  • Leave & Time Off Breadth Paid time off is framed as generous, covering vacation, holidays, and sick time, with some roles citing substantial starting PTO. Work–life supports such as flexible or hybrid arrangements and summer hours are also part of the offering for eligible roles.

Constellation Brands Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Victor, NY
5,837 Employees
Year Founded: 1945

What We Do

Constellation Brands (NYSE: STZ) is a leading international producer and marketer of beer, wine, and spirits with operations in the U.S., Mexico, New Zealand, and Italy. Our mission is to build brands that people love because we believe elevating human connections is Worth Reaching For. It’s worth our dedication, hard work, and calculated risks to anticipate market trends and deliver more for our consumers, shareholders, employees, and industry. This dedication is what has driven us to become one of the fastest-growing, large CPG companies in the U.S. at retail, and it drives our pursuit to deliver what’s next. Every day, people reach for our high-end, iconic imported beer brands such as those in the Corona brand family like the flagship Corona Extra, Modelo Especial and the flavorful lineup of Modelo Cheladas, Pacifico, and Victoria; our fine wine and craft spirits brands, including The Prisoner Wine Company, Robert Mondavi Winery, Casa Noble Tequila, and High West Whiskey; and our premium wine brands such as Kim Crawford and Meiomi. As an agriculture-based company, we have a long history of operating sustainably and responsibly. Our ESG strategy is embedded into our business and our work focuses on serving as good stewards of the environment, enhancing social equity within our industry and communities, and promoting responsible beverage alcohol consumption. These commitments ground our aspirations beyond driving the bottom line as we work to create a future that is truly Worth Reaching For. To learn more, visit www.cbrands.com and follow us on Twitter, Instagram, and LinkedIn

Similar Jobs

Hybrid
Chicago, IL, USA
100 Employees
70K-120K Annually

HealthPartners Logo HealthPartners

Compliance Analyst

Healthtech • Information Technology
In-Office or Remote
2 Locations
5537 Employees

TransUnion Logo TransUnion

Vice President, Global Network Engineering

Big Data • Fintech • Information Technology • Business Intelligence • Financial Services • Cybersecurity • Big Data Analytics
Hybrid
Chicago, IL, USA
13000 Employees
194K-407K Annually

TransUnion Logo TransUnion

Vice President, Global Operations Management & AIOps

Big Data • Fintech • Information Technology • Business Intelligence • Financial Services • Cybersecurity • Big Data Analytics
Hybrid
Chicago, IL, USA
13000 Employees
194K-407K Annually

Similar Companies Hiring

PRIMA Thumbnail
Travel • Software • Marketing Tech • Hospitality • eCommerce
US
15 Employees
Amalgamated Sugar Thumbnail
Food • Greentech • Agriculture • Industrial • Manufacturing
Boise, Idaho
768 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account