yoinka

Senior Risk and Compliance Analyst

Constellation Brands

Rochester New YorkSeniorH-1B sponsor company
Sign in to applyVerified 1h ago
Location
Rochester New York
Work model
On-Site
Level
Senior
H-1B history
2 approvals (FY2023)
Posted
1d ago

About this role

Job Description

Position Summary:   The Senior Risk and Compliance Analyst is a key member of the IT Governance, Risk, and Compliance (GRC) team, responsible for supporting and advancing the organization’s IT risk, compliance, and third-party risk management   (TPRM)   programs. This role partners with stakeholders across IT, Information Security, Procurement, Legal, OT, and the business to assess technology and vendor-related risks, strengthen governance practices, and support risk-informed decision-making.     The Analyst will help lead and mature the IT Third-Party Risk Management (TPRM) program by supporting vendor risk assessments, due diligence, ongoing monitoring, remediation tracking, and continuous improvement efforts. This role also contributes to risk intake, reporting, metrics, and automation initiatives that improve visibility, consistency, and efficiency across the broader GRC program.

Responsibilities

Act as a n   advisor for IT GRC, providing guidance to IT and business stakeholders while advancing strategic GRC initiatives.   Lead and enhance   the IT third-party risk management program, encompassing vendor risk assessments, onboarding procedures, ongoing monitoring, and remediation of identified risks.   Collaborate with Information Security, IT,   Procurement, Legal   and business teams to evaluate third-party vendors, applications, and services enterprise-wide.   Review third-party security documentation, including SOC reports, ISO certifications, security questionnaires, policies, and other relevant evidence to assess control maturity and residual risk.   Partner with the Security Operations Center (SOC) to monitor emerging threats, industry developments, and incident response insights, leveraging findings to assess and refine the risk profiles of critical vendors and technology supply chain partners .   Support   the end-to-end risk intake workflow,   help to   maintain the IT risk register   process , and ensure timely escalation   of technology risks .   Collaborate with   the IT Compliance Managers to support   risk assessments for internal initiatives,   third-party relationships , and critical business processes.   Contribute to the development of   security metrics and dashboards, leveraging automated and manual processes to produce relevant KRIs/KPIs that measure and communicate risk exposure and program effectiveness.   Maintain current knowledge of industry best practices and monitor the legal and regulatory environment for developments that may require changes to policies and practices.   Drive automation efforts within the GRC and third-party risk programs by identifying manual or repetitive tasks and implementing technology solutions, or workflow tools to improve efficiency, consistency, and reporting.   Continuously seek opportunities to optimize and modernize GRC operations through technical innovation and automation.

Required Qualifications

4   or more   years of experience in Information Security, Risk Management, Audit, IT Governance, IT Compliance, or   related   discipline.   Proven ability to lead and mature an IT Third-Party Risk Management (TPRM) program, including governance, risk assessments, and continuous improvement initiatives.   Strong understanding of third-party risk management practices across the vendor lifecycle, including due diligence, onboarding, ongoing monitoring, remediation, and offboarding.   Broad, generalist understanding of information security risk and compliance—comfortable operating across risk, audit, policy, and third-party risk areas.   Working knowledge of industry frameworks and regulatory requirements, including NIST, ISO, CIS, PCI-DSS, SOX, GDPR, CCPA, and HIPAA.   High degree of ownership, self-direction, and demonstrated thought leadership.   Ability to analyze manual processes and implement technical solutions to enhance efficiency and accuracy.     Preferred   Qualifications:

Senior Risk and Compliance Analyst at Constellation Brands, Rochester New York | Yoinka