Constellation Brands

Senior Risk and Compliance Analyst

Constellation Brands$96K — $148K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 4+ years in Information Security, Risk Management, Audit, IT Governance, or related field.
  • Experience leading IT Third-Party Risk Management (TPRM) programs.
  • Strong knowledge of vendor risk management practices across the lifecycle.
  • Generalist understanding of information security risk and compliance.
  • Familiarity with frameworks and regulations like NIST, ISO, PCI-DSS, and GDPR.
  • High level of self-direction and thought leadership.
  • Ability to analyze and enhance manual processes with technical solutions.

Responsibilities

  • Advise IT and business stakeholders on GRC initiatives.
  • Lead and improve the TPRM program with vendor assessments and monitoring.
  • Collaborate with cross-functional teams to evaluate third-party vendors.
  • Review third-party security documentation to assess risk maturity.
  • Work with the Security Operations Center on emerging threats and risk assessments.
  • Support the risk intake process and maintain the risk register.
  • Develop security metrics and dashboards to communicate risk exposure.

Benefits

  • Paid time off.
  • Medical, dental, and vision insurance.
  • 401(k) plan.
  • Support for professional certifications and training.
  • Comprehensive benefits package for eligible employees.
Full Job Description

Job Description

Position Summary:

The Senior Risk and Compliance Analyst is a key member of the IT Governance, Risk, and Compliance (GRC) team, responsible for supporting and advancing the organization’s IT risk, compliance, and third-party risk management(TPRM)programs. This role partners with stakeholders across IT, Information Security, Procurement, Legal, OT, and the business to assess technology and vendor-related risks, strengthen governance practices, and support risk-informed decision-making.

The Analyst will help lead and mature the IT Third-Party Risk Management (TPRM) program by supporting vendor risk assessments, due diligence, ongoing monitoring, remediation tracking, and continuous improvement efforts. This role also contributes to risk intake, reporting, metrics, and automation initiatives that improve visibility, consistency, and efficiency across the broader GRC program.

Responsibilities:

  • Act as anadvisor for IT GRC, providing guidance to IT and business stakeholders while advancing strategic GRC initiatives.

  • Lead and enhancethe IT third-party risk management program, encompassing vendor risk assessments, onboarding procedures, ongoing monitoring, and remediation of identified risks.

  • Collaborate with Information Security, IT,Procurement, Legaland business teams to evaluate third-party vendors, applications, and services enterprise-wide.

  • Review third-party security documentation, including SOC reports, ISO certifications, security questionnaires, policies, and other relevant evidence to assess control maturity and residual risk.

  • Partner with the Security Operations Center (SOC) to monitor emerging threats, industry developments, and incident response insights, leveraging findings to assess and refine the risk profiles of critical vendors and technology supply chain partners.

  • Supportthe end-to-end risk intake workflow,help tomaintain the IT risk registerprocess, and ensure timely escalationof technology risks.

  • Collaborate withthe IT Compliance Managers to supportrisk assessments for internal initiatives,third-party relationships, and critical business processes.

  • Contribute to the development ofsecurity metrics and dashboards, leveraging automated and manual processes to produce relevant KRIs/KPIs that measure and communicate risk exposure and program effectiveness.

  • Maintain current knowledge of industry best practices and monitor the legal and regulatory environment for developments that may require changes to policies and practices.

  • Drive automation efforts within the GRC and third-party risk programs by identifying manual or repetitive tasks and implementing technology solutions, or workflow tools to improve efficiency, consistency, and reporting.

  • Continuously seek opportunities to optimize and modernize GRC operations through technical innovation and automation.

Required Qualifications:

  • 4or moreyears of experience in Information Security, Risk Management, Audit, IT Governance, IT Compliance, orrelateddiscipline.

  • Proven ability to lead and mature an IT Third-Party Risk Management (TPRM) program, including governance, risk assessments, and continuous improvement initiatives.

  • Strong understanding of third-party risk management practices across the vendor lifecycle, including due diligence, onboarding, ongoing monitoring, remediation, and offboarding.

  • Broad, generalist understanding of information security risk and compliance 640comfortable operating across risk, audit, policy, and third-party risk areas.

  • Working knowledge of industry frameworks and regulatory requirements, including NIST, ISO, CIS, PCI-DSS, SOX, GDPR, CCPA, and HIPAA.

  • High degree of ownership, self-direction, and demonstrated thought leadership.

  • Ability to analyze manual processes and implement technical solutions to enhance efficiency and accuracy.

PreferredQualifications:

  • Bachelors degree in business administration, compliance, information systems, privacy, orrelatedfield; equivalent work or education-related experience considered.

  • One or more relevant certifications: CRISC, CISSP, CISA, CISM, CGEIT, GCCC, GSEC, GISP.

  • Proven ability to interact with key stakeholders and align priorities based on risk.

  • Familiarity with GRC platforms (e.g.,LogicGate, Optro, OneTrust,Workiva).

  • Strong written and verbal communication skills; able to present complex risk and compliance topics to both technical and non-technical audiences.

  • Proficient in Microsoft Excel, Word, and PowerPoint.

ADA Physical/Mental/Workplace Requirements:

  • Occasional lifting up to 25 lbs

  • Sitting, working at desk/personal computer for extended periods of time

  • Primary work environment is professional corporate office

  • Ability to travel commercially and internationally.

#LI-JV1

Location

Rochester, New York

Additional Locations

Chicago, Illinois, San Antonio, Texas

Job Type

Full time

Job Area

Information Technology

The salary range for this role is:

$96,700.00 - $148,100.00

This is the lowest to highest salary we in good faith believe we would pay for this role at the time of this posting. Our compensation is based on cost of labor. For remote locations or positions open to multiple locations, the pay range may reflect several US geographic markets, including the lowest geographic market minimum to the highest geographic market maximum. We may ultimately pay more or less than the posted range, and the range may be modified in the future. An employees pay position within the salary range will be based on several factors including, but not limited to, the prevailing minimum wage for the location, relevant education, qualifications, certifications, experience, skills, seniority, geographic location, performance, shift, travel requirements, sales or revenue-based metrics, any collective bargaining agreements, and business or organizational needs. At Constellation Brands, it is not typical for an individual to be hired at the high end of the range for their role, and compensation decisions are dependent upon the facts and circumstances of each position and candidate. We offer comprehensive package of benefits including paid time off, medical/dental/vision insurance, 401(k), and any other benefits to eligible employees.

Note: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of any bonus, commission, or any other form of compensation that are allocable to a particular employee remains in the Companys sole discretion unless and until paid and may be modified at the Companys sole discretion, consistent with the law.

About Constellation Brands

Constellation Brands Canada is the producer and marketer of wine and related products in Canada. The Company's leading wine brands include Jackson-Triggs and Inniskillin, maker of the world's leading Icewine. The Company's products are produced at a family of estate wineries located in the provinces of British Columbia, Ontario, Quebec and New Brunswick.

Constellation Brands Careers

Join the vibrant team at Constellation Brands, a leading international producer and marketer of beer, wine, and spirits. As a company renowned for its commitment to quality, innovation, and growth, there has never been a better time to explore the job opportunities available within our expansive network.

Work You’ll Do

At Constellation Brands, you’ll engage in work that not only supports some of the most well-known beverage brands in the world but also drives industry leadership and market innovation. Our team is dedicated to fostering a culture of diversity and inclusion, where the unique skills and perspectives of our employees are celebrated.

Lead with Innovation and Growth

Step into a role at Constellation Brands and lead projects that redefine the beverage industry. Our commitment to innovation is evident in every bottle and business strategy. With positions ranging from marketing to logistics, your professional growth is limitless. Harness your leadership potential and help us continue to set industry standards.

Join a Diverse and Inclusive Team

Constellation Brands is not just a company; it’s a community. By joining our team, you’ll work alongside professionals who are leaders in their fields and committed to diversity and inclusion. We believe that a diverse team is a strong team, and we continuously strive to foster an inclusive environment where all employees can thrive.

Internship and Employment Opportunities

Whether you’re a seasoned professional or a recent graduate, Constellation Brands offers a range of employment and internship opportunities that can help propel your career to new heights. Gain hands-on experience, benefit from our diversity training, and build a network of industry contacts all within a supportive and dynamic environment.

Benefits and Career Development

Constellation Brands values the health and well-being of its employees. We offer competitive benefits packages that support both your professional and personal life. Additionally, our career development programs are designed to help you hone your skills and advance within the company. From leadership training to professional networking events, we provide the tools necessary for your success.

Explore Job Opportunities

Ready to take the next step in your career? Explore the various positions available at Constellation Brands. From supply chain experts to creative marketing professionals, we are hiring across multiple disciplines. Check out our current job listings and find the position that best matches your skills and career ambitions.

Stay Connected

Keep up to date with the latest from Constellation Brands by following our careers blog. Discover insider perspectives, industry-leading insights, and tips that you can apply to your next interview or resume update.

Join Our Team

Search open positions that align with your skills and interests. At Constellation Brands, we look for passionate, curious, and innovative team players who are ready to make a significant impact.

SEARCH CONSTELLATION BRANDS JOBS

Embark on a rewarding career journey with Constellation Brands, where your work contributes to the legacy of some of the most celebrated brands in the alcohol industry. Let your ambition lead you here.
Learn more about Constellation Brands
Size
10,000 employees
Market Cap
$42.6 billion
Industry
Net Income
$2 billion
Founded
1945
5 Year Trend
+3.8%
Revenue
$8.5 billion
NASDAQ

Similar Jobs

More Jobs at Constellation Brands

More Information Technology Jobs

Find similar Senior Risk and Compliance Analyst jobs: