1

Governance Risk Compliance Manager Jobs in Chicago, IL

Job Title: Risk & Compliance Associate Location: Chicago, IL Industry: Management Consulting ... Experience with compliance technologies, governance platforms, or case management systems is a plus.

Audit, Risk & Compliance This role leads the Risk Framework function within the Risk Governance & Strategic Risk team (RG&SR). The function is responsible for enabling the Risk Management Framework ...

... the Bank's Governance, Risk & Compliance (GRC) framework, Enterprise Risk Management framework, and Sarbanes-Oxley (Sox) compliance. Responsibilities will include but are not limited to:

ServiceNow IRM Senior Developer

Chicago, IL · On-site

$55.75 - $76.50/hr

... governance standards. Key Responsibilities · Design, develop, configure, and implement ServiceNow IRM solutions including: o Policy and Compliance Management o Risk Management o Audit Management o ...

The Counsel, AI Risk & Compliance serve at the intersection of legal, technology, risk management ... governance and plays a central role in enabling innovation while helping the firm manage legal ...

Showing results 21-40

Governance Risk Compliance Manager information

See Chicago, IL salary details

$39.7K

$98K

$161.7K

How much do governance risk compliance manager jobs pay per year?

As of Sep 6, 2026, the average yearly pay for governance risk compliance manager in Chicago, IL is $97,970.00, according to ZipRecruiter salary data. Most workers in this role earn between $72,100.00 and $120,000.00 per year, depending on experience, location, and employer.

What does a Governance Risk Compliance (GRC) manager do?

A Governance Risk Compliance (GRC) Manager is responsible for developing, implementing, and overseeing policies and procedures to ensure that an organization complies with regulatory requirements and manages risks effectively. They work closely with various departments to identify potential risks, ensure proper governance frameworks are in place, and monitor compliance with relevant laws and standards. GRC Managers play a key role in maintaining ethical practices, preventing legal issues, and helping organizations achieve their business objectives securely and efficiently.

How does a Governance Risk Compliance (GRC) manager typically collaborate with other departments to ensure effective risk management?

A GRC Manager works closely with various departments such as IT, legal, finance, and operations to identify, assess, and mitigate risks across the organization. This often involves facilitating cross-departmental meetings, guiding teams through compliance requirements, and ensuring that controls are implemented effectively. Strong communication and project management skills are essential, as GRC Managers must translate complex regulatory requirements into actionable steps for different teams. This collaborative approach helps ensure that risk management strategies are integrated into daily business processes and that compliance goals are met organization-wide.

What are the key skills and qualifications needed to thrive as a Governance Risk Compliance manager, and why are they important?

To thrive as a Governance Risk Compliance Manager, you need expertise in risk assessment, regulatory frameworks, and compliance management, typically supported by a degree in business, law, or a related field. Familiarity with GRC platforms (like RSA Archer or MetricStream), internal audit tools, and relevant certifications such as CISA, CISM, or CRISC is common. Strong analytical thinking, attention to detail, and effective communication help manage complex regulations and drive organizational compliance culture. These skills ensure the organization can proactively identify risks, comply with legal requirements, and maintain operational integrity.

What is the difference between Governance Risk Compliance Manager vs Compliance Analyst?

AspectGovernance Risk Compliance ManagerCompliance Analyst
CertificationsISO 31000, CRISC, CISACCA, CCEP, or similar
Work EnvironmentStrategic, managerial, policy-focusedOperational, detail-oriented, audit-focused
Employer & Industry UsageFinancial, healthcare, corporate sectorsRegulatory agencies, corporations, consulting firms
Search & Comparison IntentUnderstanding managerial roles in governance and riskDetailing compliance procedures and analysis

The Governance Risk Compliance Manager oversees organizational policies, risk management strategies, and compliance frameworks at a strategic level. In contrast, the Compliance Analyst focuses on implementing and monitoring compliance procedures, conducting audits, and ensuring adherence to regulations. Both roles require relevant certifications and are vital in maintaining organizational integrity, but they differ in scope and responsibilities.

Is governance risk compliance a good career?

A career as a Governance, Risk, and Compliance (GRC) Manager is considered stable and in demand, as organizations seek to manage regulatory requirements, cybersecurity threats, and operational risks. The role often requires knowledge of industry standards, certifications like CISA or CISSP, and strong analytical skills, making it a valuable and growing field in many industries.

What are the most commonly searched types of Governance Risk Compliance jobs in Chicago, IL?

The most popular types of Governance Risk Compliance jobs in Chicago, IL are:

What are popular job titles related to Governance Risk Compliance Manager jobs in Chicago, IL?

For Governance Risk Compliance Manager jobs in Chicago, IL, the most frequently searched job titles are:

What job categories do people searching Governance Risk Compliance Manager jobs in Chicago, IL look for?

The top searched job categories for Governance Risk Compliance Manager jobs in Chicago, IL are:

What cities near Chicago, IL are hiring for Governance Risk Compliance Manager jobs?

Cities near Chicago, IL with the most Governance Risk Compliance Manager job openings:

Infographic showing various Governance Risk Compliance Manager job openings in Chicago, IL as of August 2026, with employment types broken down into 86% Full Time, 13% Part Time, and 1% Contract. Highlights an 88% Physical, 2% Hybrid, and 10% Remote job distribution, with an average salary of $97,970 per year, or $47.1 per hour.

Senior Risk and Compliance Analyst

Constellation Brands

Chicago, IL • On-site

$96K - $148K/yr

Full-time

Medical, Dental, Vision, Retirement, PTO

Re-posted 6 hours ago


Constellation Brands rating

7.9

Company rating: 7.9 out of 10

Based on 12 frontline employees who took The Breakroom Quiz

99th of 444 rated food and drinks producers


Job description

Job Description

Position Summary:

The Senior Risk and Compliance Analyst is a key member of the IT Governance, Risk, and Compliance (GRC) team, responsible for supporting and advancing the organization's IT risk, compliance, and third-party risk management(TPRM)programs. This role partners with stakeholders across IT, Information Security, Procurement, Legal, OT, and the business to assess technology and vendor-related risks, strengthen governance practices, and support risk-informed decision-making.

The Analyst will help lead and mature the IT Third-Party Risk Management (TPRM) program by supporting vendor risk assessments, due diligence, ongoing monitoring, remediation tracking, and continuous improvement efforts. This role also contributes to risk intake, reporting, metrics, and automation initiatives that improve visibility, consistency, and efficiency across the broader GRC program.

Responsibilities:

  • Act as anadvisor for IT GRC, providing guidance to IT and business stakeholders while advancing strategic GRC initiatives.

  • Lead and enhancethe IT third-party risk management program, encompassing vendor risk assessments, onboarding procedures, ongoing monitoring, and remediation of identified risks.

  • Collaborate with Information Security, IT,Procurement, Legaland business teams to evaluate third-party vendors, applications, and services enterprise-wide.

  • Review third-party security documentation, including SOC reports, ISO certifications, security questionnaires, policies, and other relevant evidence to assess control maturity and residual risk.

  • Partner with the Security Operations Center (SOC) to monitor emerging threats, industry developments, and incident response insights, leveraging findings to assess and refine the risk profiles of critical vendors and technology supply chain partners.

  • Supportthe end-to-end risk intake workflow,help tomaintain the IT risk registerprocess, and ensure timely escalationof technology risks.

  • Collaborate withthe IT Compliance Managers to supportrisk assessments for internal initiatives,third-party relationships, and critical business processes.

  • Contribute to the development ofsecurity metrics and dashboards, leveraging automated and manual processes to produce relevant KRIs/KPIs that measure and communicate risk exposure and program effectiveness.

  • Maintain current knowledge of industry best practices and monitor the legal and regulatory environment for developments that may require changes to policies and practices.

  • Drive automation efforts within the GRC and third-party risk programs by identifying manual or repetitive tasks and implementing technology solutions, or workflow tools to improve efficiency, consistency, and reporting.

  • Continuously seek opportunities to optimize and modernize GRC operations through technical innovation and automation.

Required Qualifications:

  • 4or moreyears of experience in Information Security, Risk Management, Audit, IT Governance, IT Compliance, orrelateddiscipline.

  • Proven ability to lead and mature an IT Third-Party Risk Management (TPRM) program, including governance, risk assessments, and continuous improvement initiatives.

  • Strong understanding of third-party risk management practices across the vendor lifecycle, including due diligence, onboarding, ongoing monitoring, remediation, and offboarding.

  • Broad, generalist understanding of information security risk and compliance-comfortable operating across risk, audit, policy, and third-party risk areas.

  • Working knowledge of industry frameworks and regulatory requirements, including NIST, ISO, CIS, PCI-DSS, SOX, GDPR, CCPA, and HIPAA.

  • High degree of ownership, self-direction, and demonstrated thought leadership.

  • Ability to analyze manual processes and implement technical solutions to enhance efficiency and accuracy.

PreferredQualifications:

  • Bachelor's degree in business administration, compliance, information systems, privacy, orrelatedfield; equivalent work or education-related experience considered.

  • One or more relevant certifications: CRISC, CISSP, CISA, CISM, CGEIT, GCCC, GSEC, GISP.

  • Proven ability to interact with key stakeholders and align priorities based on risk.

  • Familiarity with GRC platforms (e.g.,LogicGate, Optro, OneTrust,Workiva).

  • Strong written and verbal communication skills; able to present complex risk and compliance topics to both technical and non-technical audiences.

  • Proficient in Microsoft Excel, Word, and PowerPoint.

ADA Physical/Mental/Workplace Requirements:

  • Occasional lifting up to 25 lbs

  • Sitting, working at desk/personal computer for extended periods of time

  • Primary work environment is professional corporate office

  • Ability to travel commercially and internationally.

#LI-JV1

Location

Rochester, New York

Additional Locations

Chicago, Illinois, San Antonio, Texas

Job Type

Full time

Job Area

Information Technology

The salary range for this role is:

$96,700.00 - $148,100.00

This is the lowest to highest salary we in good faith believe we would pay for this role at the time of this posting. Our compensation is based on cost of labor. For remote locations or positions open to multiple locations, the pay range may reflect several US geographic markets, including the lowest geographic market minimum to the highest geographic market maximum. We may ultimately pay more or less than the posted range, and the range may be modified in the future. An employee's pay position within the salary range will be based on several factors including, but not limited to, the prevailing minimum wage for the location, relevant education, qualifications, certifications, experience, skills, seniority, geographic location, performance, shift, travel requirements, sales or revenue-based metrics, any collective bargaining agreements, and business or organizational needs. At Constellation Brands, it is not typical for an individual to be hired at the high end of the range for their role, and compensation decisions are dependent upon the facts and circumstances of each position and candidate. We offer comprehensive package of benefits including paid time off, medical/dental/vision insurance, 401(k), and any other benefits to eligible employees.

Note: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of any bonus, commission, or any other form of compensation that are allocable to a particular employee remains in the Company's sole discretion unless and until paid and may be modified at the Company's sole discretion, consistent with the law.

Equal Opportunity

Constellation Brands is committed to a continuing program of equal employment opportunity. All persons have equal employment opportunities with Constellation Brands, regardless of their sex, race, color, age, religion, creed, sexual orientation, national origin or citizenship, ancestry, physical or mental disability, medical condition (cancer or genetic characteristics), marital status, gender (including gender identity or gender expression), familial status, military or veteran status, genetic information, pregnancy, childbirth, breastfeeding, or related conditions (or any other group or category within the framework of the applicable discrimination laws and regulations).


What Constellation Brands employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom