
Constellation Brands
Rochester, New York • Today
Full-time
Compensation information provided in the description
2 results (0 new)

Constellation Brands
Rochester, New York • Today
Full-time
Compensation information provided in the description


Job Description
Position Summary:
The Senior Risk and Compliance Analyst is a key member of the IT Governance, Risk, and Compliance (GRC) team, responsible for supporting and advancing the organization?s IT risk, compliance, and third-party risk management(TPRM)programs. This role partners with stakeholders across IT, Information Security, Procurement, Legal, OT, and the business to assess technology and vendor-related risks, strengthen governance practices, and support risk-informed decision-making.
The Analyst will help lead and mature the IT Third-Party Risk Management (TPRM) program by supporting vendor risk assessments, due diligence, ongoing monitoring, remediation tracking, and continuous improvement efforts. This role also contributes to risk intake, reporting, metrics, and automation initiatives that improve visibility, consistency, and efficiency across the broader GRC program.
Responsibilities:
Act as anadvisor for IT GRC, providing guidance to IT and business stakeholders while advancing strategic GRC initiatives.
Lead and enhancethe IT third-party risk management program, encompassing vendor risk assessments, onboarding procedures, ongoing monitoring, and remediation of identified risks.
Collaborate with Information Security, IT,Procurement, Legaland business teams to evaluate third-party vendors, applications, and services enterprise-wide.
Review third-party security documentation, including SOC reports, ISO certifications, security questionnaires, policies, and other relevant evidence to assess control maturity and residual risk.
Partner with the Security Operations Center (SOC) to monitor emerging threats, industry developments, and incident response insights, leveraging findings to assess and refine the risk profiles of critical vendors and technology supply chain partners.
Supportthe end-to-end risk intake workflow,help tomaintain the IT risk registerprocess, and ensure timely escalationof technology risks.
Collaborate withthe IT Compliance Managers to supportrisk assessments for internal initiatives,third-party relationships, and critical business processes.
Contribute to the development ofsecurity metrics and dashboards, leveraging automated and manual processes to produce relevant KRIs/KPIs that measure and communicate risk exposure and program effectiveness.
Maintain current knowledge of industry best practices and monitor the legal and regulatory environment for developments that may require changes to policies and practices.
Drive automation efforts within the GRC and third-party risk programs by identifying manual or repetitive tasks and implementing technology solutions, or workflow tools to improve efficiency, consistency, and reporting.
Continuously seek opportunities to optimize and modernize GRC operations through technical innovation and automation.
Required Qualifications:
4or moreyears of experience in Information Security, Risk Management, Audit, IT Governance, IT Compliance, orrelateddiscipline.
Proven ability to lead and mature an IT Third-Party Risk Management (TPRM) program, including governance, risk assessments, and continuous improvement initiatives.
Strong understanding of third-party risk management practices across the vendor lifecycle, including due diligence, onboarding, ongoing monitoring, remediation, and offboarding.
Broad, generalist understanding of information security risk and compliance?comfortable operating across risk, audit, policy, and third-party risk areas.
Working knowledge of industry frameworks and regulatory requirements, including NIST, ISO, CIS, PCI-DSS, SOX, GDPR, CCPA, and HIPAA.
High degree of ownership, self-direction, and demonstrated thought leadership.
Ability to analyze manual processes and implement technical solutions to enhance efficiency and accuracy.
PreferredQualifications:
Bachelor?s degree in business administration, compliance, information systems, privacy, orrelatedfield; equivalent work or education-related experience considered.
One or more relevant certifications: CRISC, CISSP, CISA, CISM, CGEIT, GCCC, GSEC, GISP.
Proven ability to interact with key stakeholders and align priorities based on risk.
Familiarity with GRC platforms (e.g.,LogicGate, Optro, OneTrust,Workiva).
Strong written and verbal communication skills; able to present complex risk and compliance topics to both technical and non-technical audiences.
Proficient in Microsoft Excel, Word, and PowerPoint.
ADA Physical/Mental/Workplace Requirements:
Occasional lifting up to 25 lbs
Sitting, working at desk/personal computer for extended periods of time
Primary work environment is professional corporate office
Ability to travel commercially and internationally.
#LI-JV1
Location
Rochester, New YorkAdditional Locations
Chicago, Illinois, San Antonio, TexasJob Type
Full timeJob Area
Information TechnologyThe salary range for this role is:
$96,700.00 - $148,100.00This is the lowest to highest salary we in good faith believe we would pay for this role at the time of this posting. Our compensation is based on cost of labor. For remote locations or positions open to multiple locations, the pay range may reflect several US geographic markets, including the lowest geographic market minimum to the highest geographic market maximum. We may ultimately pay more or less than the posted range, and the range may be modified in the future. An employee?s pay position within the salary range will be based on several factors including, but not limited to, the prevailing minimum wage for the location, relevant education, qualifications, certifications, experience, skills, seniority, geographic location, performance, shift, travel requirements, sales or revenue-based metrics, any collective bargaining agreements, and business or organizational needs. At Constellation Brands, it is not typical for an individual to be hired at the high end of the range for their role, and compensation decisions are dependent upon the facts and circumstances of each position and candidate. We offer comprehensive package of benefits including paid time off, medical/dental/vision insurance, 401(k), and any other benefits to eligible employees.
Note: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of any bonus, commission, or any other form of compensation that are allocable to a particular employee remains in the Company\'s sole discretion unless and until paid and may be modified at the Company?s sole discretion, consistent with the law.
Equal Opportunity
Constellation Brands is committed to a continuing program of equal employment opportunity. All persons have equal employment opportunities with Constellation Brands, regardless of their sex, race, color, age, religion, creed, sexual orientation, national origin or citizenship, ancestry, physical or mental disability, medical condition (cancer or genetic characteristics), marital status, gender (including gender identity or gender expression), familial status, military or veteran status, genetic information, pregnancy, childbirth, breastfeeding, or related conditions (or any other group or category within the framework of the applicable discrimination laws and regulations).
🔢 Crunching numbers...
Florida
•
2d ago
IT Enterprise Risk Analyst - Perm - Tampa, FL/Hybrid - $90000- $95000 The final salary or hourly wage, as applicable, paid to each candidate/applicant for this position is ultimately dependent on a variety of factors, including, but not limited to, the candidate's/applicant's qualifications, skills, and level of experience as well as the geographical location of the position. Applicants must be legally authorized to work in the United States. Visa sponsorship not available. Our client is seek
Easy Apply
Full-time
USD 90,000.00 - 95,000.00 per year
No location provided
•
Today
Principal/Senior Consultant, Governance, Risk & Compliance Practice: Cybersecurity, Governance, Risk & Compliance Employment Type: Full-Time Location: Remote, United States Travel: Occasional travel to client locations for assessments, workshops, interviews, and other project activities Position Summary Pellera Technologies is seeking an experienced Principal / Senior GRC Consultant, to join our growing Cybersecurity Services practice. This is an opportunity for a seasoned cybersecurity, audi
Full-time
California
•
Today
Our Mission At Palo Alto Networks , we're united by a shared mission-to protect our digital way of life. We thrive at the intersection of innovation and impact, solving real-world problems with cutting-edge technology and bold thinking. Here, everyone has a voice, and every idea counts. If you're ready to do the most meaningful work of your career alongside people who are just as passionate as you are, you're in the right place. Who We Are In order to be the cybersecurity partner of choice, w
Full-time
USD 167,600.00 - 271,150.00 per year
Remote
•
Today
Job Title: Sr. GRC Analyst Experience: 9+ Years Employment Type: Contrac Location: Remote We are looking for a detail-oriented Governance, Risk & Compliance (GRC) Analyst to support information security governance, risk management, compliance assessments, audits, and security control activities. The ideal candidate will have hands-on experience with frameworks such as ISO 27001, NIST, SOC 2, PCI-DSS, and GDPR. Key ResponsibilitiesConduct IT security, enterprise, and third-party/vendor risk asses
Easy Apply
Contract, Third Party
55