Job Description
The Senior Risk and Compliance Analyst is a key member of the IT Governance, Risk, and Compliance (GRC) team, responsible for supporting and advancing the organization’s IT risk, compliance, and third-party risk management(TPRM)programs. This role partners with stakeholders across IT, Information Security, Procurement, Legal, OT, and the business to assess technology and vendor-related risks, strengthen governance practices, and support risk-informed decision-making.
The Analyst will help lead and mature the IT Third-Party Risk Management (TPRM) program by supporting vendor risk assessments, due diligence, ongoing monitoring, remediation tracking, and continuous improvement efforts. This role also contributes to risk intake, reporting, metrics, and automation initiatives that improve visibility, consistency, and efficiency across the broader GRC program.
Lead and enhancethe IT third-party risk management program, encompassing vendor risk assessments, onboarding procedures, ongoing monitoring, and remediation of identified risks.
Collaborate with Information Security, IT,Procurement, Legaland business teams to evaluate third-party vendors, applications, and services enterprise-wide.
Review third-party security documentation, including SOC reports, ISO certifications, security questionnaires, policies, and other relevant evidence to assess control maturity and residual risk.
Partner with the Security Operations Center (SOC) to monitor emerging threats, industry developments, and incident response insights, leveraging findings to assess and refine the risk profiles of critical vendors and technology supply chain partners.
Drive automation efforts within the GRC and third-party risk programs by identifying manual or repetitive tasks and implementing technology solutions, or workflow tools to improve efficiency, consistency, and reporting.
4or moreyears of experience in Information Security, Risk Management, Audit, IT Governance, IT Compliance, orrelateddiscipline.
Proven ability to lead and mature an IT Third-Party Risk Management (TPRM) program, including governance, risk assessments, and continuous improvement initiatives.
Strong understanding of third-party risk management practices across the vendor lifecycle, including due diligence, onboarding, ongoing monitoring, remediation, and offboarding.
Broad, generalist understanding of information security risk and compliance 640comfortable operating across risk, audit, policy, and third-party risk areas.
Working knowledge of industry frameworks and regulatory requirements, including NIST, ISO, CIS, PCI-DSS, SOX, GDPR, CCPA, and HIPAA.
Bachelors degree in business administration, compliance, information systems, privacy, orrelatedfield; equivalent work or education-related experience considered.
One or more relevant certifications: CRISC, CISSP, CISA, CISM, CGEIT, GCCC, GSEC, GISP.
Familiarity with GRC platforms (e.g.,LogicGate, Optro, OneTrust,Workiva).
ADA Physical/Mental/Workplace Requirements:
Location
Rochester, New York
Additional Locations
Chicago, Illinois, San Antonio, Texas
Job Type
Full time
Job Area
Information Technology
The salary range for this role is:
$96,700.00 - $148,100.00
This is the lowest to highest salary we in good faith believe we would pay for this role at the time of this posting. Our compensation is based on cost of labor. For remote locations or positions open to multiple locations, the pay range may reflect several US geographic markets, including the lowest geographic market minimum to the highest geographic market maximum. We may ultimately pay more or less than the posted range, and the range may be modified in the future. An employees pay position within the salary range will be based on several factors including, but not limited to, the prevailing minimum wage for the location, relevant education, qualifications, certifications, experience, skills, seniority, geographic location, performance, shift, travel requirements, sales or revenue-based metrics, any collective bargaining agreements, and business or organizational needs. At Constellation Brands, it is not typical for an individual to be hired at the high end of the range for their role, and compensation decisions are dependent upon the facts and circumstances of each position and candidate. We offer comprehensive package of benefits including paid time off, medical/dental/vision insurance, 401(k), and any other benefits to eligible employees.
Note: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of any bonus, commission, or any other form of compensation that are allocable to a particular employee remains in the Companys sole discretion unless and until paid and may be modified at the Companys sole discretion, consistent with the law.