Senior Risk and Compliance Analyst

Constellation Brands
San Antonio, NY
Job Description
Role Overview

The Senior Risk and Compliance Analyst is a key member of the IT Governance, Risk, and Compliance (GRC) team, responsible for supporting and advancing the organization’s IT risk, compliance, and third-party risk management (TPRM) programs. This role partners with stakeholders across IT, Information Security, Procurement, Legal, OT, and the business to assess technology and vendor-related risks, strengthen governance practices, and support risk-informed decision-making.

What You Will Do

The Analyst will help lead and mature the IT Third-Party Risk Management (TPRM) program by supporting vendor risk assessments, due diligence, ongoing monitoring, remediation tracking, and continuous improvement efforts. This role also contributes to risk intake, reporting, metrics, and automation initiatives that improve visibility, consistency, and efficiency across the broader GRC program.

Why It Might Be a Fit

The ideal candidate will have a strong understanding of third-party risk management practices across the vendor lifecycle, including due diligence, onboarding, ongoing monitoring, remediation, and offboarding. They will also have a broad, generalist understanding of information security risk and compliance—comfortable operating across risk, audit, policy, and third-party risk areas.

Requirements

  • 4 or more years of experience in Information Security, Risk Management, Audit, IT Governance, IT Compliance, or related discipline.
  • Proven ability to lead and mature an IT Third-Party Risk Management (TPRM) program, including governance, risk assessments, and continuous improvement initiatives.
  • Strong understanding of third-party risk management practices across the vendor lifecycle, including due diligence, onboarding, ongoing monitoring, remediation, and offboarding.
  • Broad, generalist understanding of information security risk and compliance—comfortable operating across risk, audit, policy, and third-party risk areas.
  • Working knowledge of industry frameworks and regulatory requirements, including NIST, ISO, CIS, PCI-DSS, SOX, GDPR, CCPA, and HIPAA.
  • High degree of ownership, self-direction, and demonstrated thought leadership.
  • Ability to analyze manual processes and implement technical solutions to enhance efficiency and accuracy.

Benefits

  • Paid time off
  • Medical/dental/vision insurance
  • 401(k)
  • Comprehensive package of benefits
]]>