1

Governance Risk Compliance Jobs in Rochester, NY

Core responsibilities include compliance training, risk assessments, testing and monitoring, policy governance, complaint management, regulatory change management, and issue remediation. The CCO also ...

Senior SAP Security Analyst

Rochester, NY

$94K - $123K/yr

... BW), Governance Risk Compliance (GRC), SAP BusinessObjects BI (BOBJ), and Solution Manager. * Develop SAP security solutions and/or configuration changes to meet ongoing end user requirements.

Senior Cyber Security Manager

Fairport, NY

$105K - $142K/yr

Improve access governance and reduce identity-related risk * Risk & Compliance: ISO 27001, NIS2, GDPR, EU AI Act, DORA where applicable, internal audit * Translate regulatory and framework ...

Senior Cyber Security Manager

Fairport, NY · On-site

$105K - $142K/yr

Improve access governance and reduce identity-related risk * Risk & Compliance: ISO 27001, NIS2, GDPR, EU AI Act, DORA where applicable, internal audit * Translate regulatory and framework ...

Senior Cyber Security Manager

Fairport, NY · On-site

$105K - $142K/yr

Improve access governance and reduce identity-related risk * Risk & Compliance: ISO 27001, NIS2, GDPR, EU AI Act, DORA where applicable, internal audit * Translate regulatory and framework ...

next page

Showing results 1-20

Governance Risk Compliance information

See Rochester, NY salary details

$31.1K

$67.8K

$110.5K

How much do governance risk compliance jobs pay per year?

As of Aug 28, 2026, the average yearly pay for governance risk compliance in Rochester, NY is $67,815.00, according to ZipRecruiter salary data. Most workers in this role earn between $48,300.00 and $85,300.00 per year, depending on experience, location, and employer.

What is governance risk compliance?

Governance, Risk, and Compliance (GRC) is a coordinated strategy that organizations use to manage overall governance, enterprise risk management, and compliance with regulations and standards. GRC professionals help organizations align their business objectives with risk management practices and regulatory requirements. This role involves identifying potential risks, implementing policies to mitigate those risks, and ensuring that the organization adheres to legal, ethical, and internal standards. Effective GRC management can improve decision-making, optimize processes, and protect the organization from financial or reputational harm.

What are jobs in governance risk compliance?

Governance risk compliance (GRC) is a method for managing and strategizing an organization's regulations regarding governance, financial or physical risk, and regulatory compliance. It aligns the IT aspects with business objectives and works to improve the efficiency of a company. There are GRC consultants and GRC analysts who provide an assessment of a business’s GRC, identify risks, analyze the data, develop policies to benefit the workplace, and consult on the best choice of action. Your duties may involve optimizing GRC systems, implementing tactics to lower risk, providing internal audits, assisting with cybersecurity, creating routine reports, and ensuring regulatory compliance.

What are the key skills and qualifications needed to thrive as a governance risk compliance professional?

To thrive as a Governance Risk Compliance professional, you need a solid understanding of regulatory frameworks, risk management principles, and policy development, often supported by a degree in business, law, or information security. Familiarity with GRC software platforms, compliance management systems, and certifications like CISA, CRISC, or CISSP is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills set top performers apart in this field. These competencies are essential for ensuring organizational compliance, minimizing risks, and maintaining robust corporate governance.

How does a governance risk compliance professional typically collaborate with other departments within an organization?

GRC professionals work closely with a variety of departments, including IT, legal, finance, and operations, to ensure that organizational policies and regulatory requirements are consistently met. Collaboration often involves leading risk assessments, facilitating compliance training, and coordinating audits to identify and mitigate potential risks. Effective communication and relationship-building are key, as GRC teams must translate complex regulations into actionable steps for different business units. This cross-functional approach helps embed a culture of compliance and risk awareness throughout the organization.

What is the difference between Governance Risk Compliance vs Risk Analyst?

AspectGovernance Risk ComplianceRisk Analyst
CertificationsCRISC, CISA, CISSPCFA, FRM, CRISC
Work EnvironmentCorporate, regulated industriesFinancial, consulting firms
Employer & Industry UsageFinancial institutions, healthcare, governmentBanking, investment firms, insurance

Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing enterprise-wide risks. Risk Analysts primarily assess specific financial or operational risks through data analysis. While both roles involve risk management, Governance Risk Compliance has a broader scope related to organizational compliance and governance frameworks, whereas Risk Analysts concentrate on analyzing and quantifying particular risks.

What is the work of governance risk compliance?

Governance, Risk, and Compliance (GRC) professionals develop and implement policies to ensure organizations adhere to legal and regulatory requirements, manage risks, and maintain ethical standards. They analyze business processes, conduct audits, and use tools like risk management software to identify vulnerabilities and ensure compliance across departments.

What are the most commonly searched types of Governance Risk Compliance jobs in Rochester, NY?

The most popular types of Governance Risk Compliance jobs in Rochester, NY are:

What are popular job titles related to Governance Risk Compliance jobs in Rochester, NY?

For Governance Risk Compliance jobs in Rochester, NY, the most frequently searched job titles are:

What job categories do people searching Governance Risk Compliance jobs in Rochester, NY look for?

The top searched job categories for Governance Risk Compliance jobs in Rochester, NY are:

What cities near Rochester, NY are hiring for Governance Risk Compliance jobs?

Cities near Rochester, NY with the most Governance Risk Compliance job openings:

Infographic showing various Governance Risk Compliance job openings in Rochester, NY as of August 2026, with employment types broken down into 1% As Needed, 77% Full Time, 15% Part Time, and 7% Contract. Highlights an 88% Physical, 3% Hybrid, and 9% Remote job distribution, with an average salary of $67,815 per year, or $32.6 per hour.

Senior Risk and Compliance Analyst

Rochester, NY • On-site


Constellation Brands
Manufacturing • 1 - 5K employees

7.9

Company rating: 7.9 out of 10

Based on 12 frontline employees who took The Breakroom Quiz

97th of 443 rated food and drinks producers

People enjoy working here

Good employer

Paid breaks


$97 - $148/hr

Other

Medical, Dental, Vision, Retirement, PTO

Posted 9 days ago


Job description

## Senior Risk and Compliance AnalystApplylocations: Rochester, New York: Chicago, Illinois: San Antonio, Texastime type: Full timeposted on: Posted Todayjob requisition id: R-39327**Job Description**Position Summary:The Senior Risk and Compliance Analyst is a key member of the IT Governance, Risk, and Compliance (GRC) team, responsible for supporting and advancing the organization’s IT risk, compliance, and third-party risk management (TPRM) programs. This role partners with stakeholders across IT, Information Security, Procurement, Legal, OT, and the business to assess technology and vendor-related risks, strengthen governance practices, and support risk-informed decision-making.The Analyst will help lead and mature the IT Third-Party Risk Management (TPRM) program by supporting vendor risk assessments, due diligence, ongoing monitoring, remediation tracking, and continuous improvement efforts. This role also contributes to risk intake, reporting, metrics, and automation initiatives that improve visibility, consistency, and efficiency across the broader GRC program.Responsibilities:* Act as an advisor for IT GRC, providing guidance to IT and business stakeholders while advancing strategic GRC initiatives.* Lead and enhance the IT third-party risk management program, encompassing vendor risk assessments, onboarding procedures, ongoing monitoring, and remediation of identified risks.* Collaborate with Information Security, IT, Procurement, Legal and business teams to evaluate third-party vendors, applications, and services enterprise-wide.* Review third-party security documentation, including SOC reports, ISO certifications, security questionnaires, policies, and other relevant evidence to assess control maturity and residual risk.* Partner with the Security Operations Center (SOC) to monitor emerging threats, industry developments, and incident response insights, leveraging findings to assess and refine the risk profiles of critical vendors and technology supply chain partners.* Support the end-to-end risk intake workflow, help to maintain the IT risk register process, and ensure timely escalation of technology risks.* Collaborate with the IT Compliance Managers to support risk assessments for internal initiatives, third-party relationships, and critical business processes.* Contribute to the development of security metrics and dashboards, leveraging automated and manual processes to produce relevant KRIs/KPIs that measure and communicate risk exposure and program effectiveness.* Maintain current knowledge of industry best practices and monitor the legal and regulatory environment for developments that may require changes to policies and practices.* Drive automation efforts within the GRC and third-party risk programs by identifying manual or repetitive tasks and implementing technology solutions, or workflow tools to improve efficiency, consistency, and reporting.* Continuously seek opportunities to optimize and modernize GRC operations through technical innovation and automation.Required Qualifications:* 4 or more years of experience in Information Security, Risk Management, Audit, IT Governance, IT Compliance, or related discipline.* Proven ability to lead and mature an IT Third-Party Risk Management (TPRM) program, including governance, risk assessments, and continuous improvement initiatives.* Strong understanding of third-party risk management practices across the vendor lifecycle, including due diligence, onboarding, ongoing monitoring, remediation, and offboarding.* Broad, generalist understanding of information security risk and compliance—comfortable operating across risk, audit, policy, and third-party risk areas.* Working knowledge of industry frameworks and regulatory requirements, including NIST, ISO, CIS, PCI-DSS, SOX, GDPR, CCPA, and HIPAA.* High degree of ownership, self-direction, and demonstrated thought leadership.* Ability to analyze manual processes and implement technical solutions to enhance efficiency and accuracy.Preferred Qualifications:* Bachelor’s degree in business administration, compliance, information systems, privacy, or related field; equivalent work or education-related experience considered.* One or more relevant certifications: CRISC, CISSP, CISA, CISM, CGEIT, GCCC, GSEC, GISP.* Proven ability to interact with key stakeholders and align priorities based on risk.* Familiarity with GRC platforms (e.g., LogicGate, Optro, OneTrust, Workiva).* Strong written and verbal communication skills; able to present complex risk and compliance topics to both technical and non-technical audiences.* Proficient in Microsoft Excel, Word, and PowerPoint.ADA Physical/Mental/Workplace Requirements:* Occasional lifting up to 25 lbs* Sitting, working at desk/personal computer for extended periods of time* Primary work environment is professional corporate office* Ability to travel commercially and internationally.#LI-JV1**Location**Rochester, New York**Additional Locations**Chicago, Illinois, San Antonio, Texas**Job Type**Full time**Job Area**Information Technology**The salary range for this role is:**$96,700.00 - $148,100.00This is the lowest to highest salary we in good faith believe we would pay for this role at the time of this posting. Our compensation is based on cost of labor. For remote locations or positions open to multiple locations, the pay range may reflect several US geographic markets, including the lowest geographic market minimum to the highest geographic market maximum. We may ultimately pay more or less than the posted range, and the range may be modified in the future. An employee’s pay position within the salary range will be based on several factors including, but not limited to, the prevailing minimum wage for the location, relevant education, qualifications, certifications, experience, skills, seniority, geographic location, performance, shift, travel requirements, sales or revenue-based metrics, any collective bargaining agreements, and business or organizational needs. At Constellation Brands, it is not typical for an individual to be hired at the high end of the range for their role, and compensation decisions are dependent upon the facts and circumstances of each position and candidate. We offer comprehensive package of benefits including paid time off, medical/dental/vision insurance, 401(k), and any other benefits to eligible employees.Note: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of any bonus, commission, or any other form of compensation that are allocable to a particular employee remains in the Company's sole discretion unless and until paid and may be modified at the Company’s sole discretion, consistent with the law. #J-18808-Ljbffr


What Constellation Brands employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom