Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Information Security GRC Analyst III, Controls Assurance

$120k - $160k

Fanatics Inc.

About Us

Fanatics is building a leading global digital sports platform. We ignite the passions of global sports fans and maximize the presence and reach for our hundreds of sports partners globally by offering products and services across Fanatics Commerce, Fanatics Collectibles, and Fanatics Betting & Gaming, allowing sports fans to Buy, Collect, and Bet. Through the Fanatics platform, sports fans can buy licensed fan gear, jerseys, lifestyle and streetwear products, headwear, and hardgoods; collect physical and digital trading cards, sports memorabilia, and other digital assets; and bet as the company builds its Sportsbook and iGaming platform. Fanatics has an established database of over 100 million global sports fans; a global partner network with approximately 900 sports properties, including major national and international professional sports leagues, players associations, teams, colleges, college conferences and retail partners, 2,500 athletes and celebrities, and 200 exclusive athletes; and over 2,000 retail locations, including its Lids retail stores. Our more than 22,000 employees are committed to relentlessly enhancing the fan experience and delighting sports fans globally. The Role The Information Security GRC Analyst III, Controls Assurance (Fanatics Corporate) sits at the center of how Fanatics proves its security controls actually work, testing across PCI DSS, SOX ITGC, SOC reporting, and our internal NIST-aligned control baselines. This is a Corporate-level role with direct exposure across the full Fanatics portfolio: you will work daily with business units, IT teams, Security Operations, and InfoSec GRC counterparts across our subsidiaries and brands, giving you a rare, enterprise-wide view of how a global, multi-brand organization operates and secures itself. Working in partnership with the designated owner of each control set, you will execute assigned control testing, collect and evaluate evidence, support user access reviews and control exception administration, and contribute to findings tracking and control reporting. Control effectiveness is rarely a clean pass or fail; you will need to read the intent behind a control, work through the grey areas, and take a practical, risk-based approach to compensating controls, tailored to how each subsidiary or brand actually does business. Strong communication is central to the role: you will explain technical and non-technical control requirements clearly and consistently to control owners, and use that clarity to influence timely, positive adoption of controls and remediation. Control baselines and framework control sets are established and owned within the GRC team, so this is a controls assurance role rather than a program build-out or control design role. A substantial portion of the work is recurring and deadline-driven, including access review cycles, evidence collection, and assessment calendars. What You'll Do Execute assigned control tests in partnership with control set owners, including: sample selection, evidence requests, walkthroughs, and documented conclusions on operating effectiveness. Communicate control requirements, testing results, and rationale clearly and consistently to control owners across technical and non-technical audiences, and use that clarity to influence timely, positive adoption of controls and remediation. Prepare workpapers that withstand assessor review without rework. Evaluate evidence critically, identifying artifacts that do not substantiate the control. Support QSA, audit, and service auditor engagements, including evidence request lists and walkthrough preparation. Support user access review campaigns: population scoping, reviewer assignments, completion monitoring, and verification that revocations were executed. Collect and quality-check evidence for framework cycles, resolving gaps before assessor fieldwork. Support the control exception process: intake, routing, compensating controls, expiry tracking, and re-review. Apply practical, risk-based judgment to grey-area control questions, including whether a compensating control adequately addresses the underlying risk given how a specific subsidiary or brand operates. Identify opportunities to reduce manual evidence collection. Help maintain the control library: owners, test procedures, evidence requirements, testing frequency, and system mappings. Support cross-framework mapping, including mapping internal baseline controls to the external requirements they satisfy. Support findings tracking and remediation follow-up, retesting closed items rather than accepting closure on assertion. Contribute to control reporting and metrics, and to workflow upkeep in the designated GRC platform. Partner day-to-day with business units, IT teams, Security Operations, and InfoSec GRC counterparts across Fanatics' subsidiaries and brands, understanding how each operates in order to apply controls appropriately. Build sufficient depth across control sets to provide backup coverage during leave, peak workload, or overlapping cycles. What We're Looking For Four years + in IT audit, IT control testing, information security GRC, or a related discipline; Big Four or regional firm IT audit experience applies directly. Demonstrated experience executing control tests to a defined procedure, including sampling, evidence evaluation, and documented conclusions. Experience with user access reviews, either administering campaigns or testing them as a control. Exposure to at least one of PCI DSS, SOX ITGC, SOC, or an internal security control baseline. Experience driving a recurring process across stakeholders outside a direct reporting line, with a record of following items to completion. Curiosity and adaptability to understand how Fanatics' different subsidiaries and brands operate, and how that context shapes how a control should be applied and assessed for effectiveness. Working knowledge of core control domains: access management and access reviews, privileged access, change management, SDLC, logging and monitoring, encryption, vulnerability and patch management, backup and recovery, and cloud platform fundamentals. Excellent written and verbal communication, with the ability to explain technical and non-technical control concepts clearly and consistently to control owners, and to influence stakeholders toward timely, positive adoption of controls and remediation, even without direct authority over them. Effective use of approved AI tools in day-to-day work, with sound judgment about where AI output can and cannot be relied upon in an audit context. Organizational discipline, persistence, and judgment about when to escalate. Detail-oriented, with sound judgment for navigating grey areas in control descriptions and a practical, risk-based approach to evaluating compensating controls rather than a strict pass/fail mindset. Bachelor's degree in information security, cybersecurity, information systems, accounting, or a related field, or equivalent practical experience. Preferred: CISA certification. Preferred: exposure to two or more of PCI DSS, SOX ITGC, and SOC, including familiarity with PCI DSS v4.0.1, and testing against NIST 800-53 or the NIST Cybersecurity Framework. Preferred: familiarity with an enterprise GRC or IRM platform The salary range represents base pay only and does not include short-term or long-term incentive compensation. This salary range is specific to New York City and may not be applicable to other locations. When determining base pay, as part of a final compensation package, we consider several factors such as location, experience, qualifications, and training. For information about our benefits, please visit NYC Salary Range $120,000—$160,000 USD By submitting your application, you agree to our terms of service and acknowledge you have read our Candidate Privacy Policy.

Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Information Security GRC Analyst III, Controls Assurance in New York, NY vacancy
  • $134.16k - $213.6k

     ...About the Team: The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s...  ...by proactively managing information security risks and maintaining effective controls. Our mission is to reduce...  ...while operating a robust assurance program that builds trust... 
    Suggested
    Remote job
    Full time
    Contract work
    Work experience placement
    Local area

    Plaid

    New York, NY
    a month ago
  •  ...performs business functions. Information Risk Governance (“IRG”) provides...  ...to information and cyber security risk by maintaining and improving...  ...Operations Center (SOC) Analyst is responsible for monitoring...  ...system, Firewalls, Network Access Control (NAC), Network Detection &... 
    Suggested
    Work at office
    Work from home
    Flexible hours
    2 days per week

    SUMITOMO MITSUI TRUST BANK, LIMITED

    New York, NY
    26 days ago
  •  ...performs business functions. Information Risk Governance (“IRG”)...  ...oversight to information and cyber security risk by maintaining and...  ...The Information Security Risk Analyst is responsible for supporting...  ...components such as domain controllers, DHCP, DNS, and Active Directory... 
    Suggested
    Work at office
    Work from home
    Flexible hours
    2 days per week

    SUMITOMO MITSUI TRUST BANK, LIMITED

    New York, NY
    26 days ago
  • $75k - $85k

     ...IT Security Analyst Who is Gen II? Gen II is a leading fund administration...  ...Support the Chief Information Security Officer in developing an IT security assurance program Develop general...  ...documentation describing security controls, system specifications, and operating... 
    Suggested
    Full time
    Work at office
    Flexible hours
    1 day per week

    Gen Ii Careers

    New York, NY
    a month ago
  • $118.68k - $175.8k

     ...and Amsterdam. Team: The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s...  ...by proactively managing information security risks and maintaining effective controls. Our mission is to reduce...  ...while operating a robust assurance program that builds trust... 
    Suggested
    Remote job
    Full time
    Work experience placement
    Local area

    Plaid

    New York, NY
    a month ago
  • $99.2k - $148.8k

    DescriptionThe Applications Analyst III supervises and provides technical guidance to the...  ...2. Assists in planning, organizing and controlling the activities of the section. 3. May work...  ..., diverse work experience in ITEpic Security Certification and experience required.Employer... 
    Traineeship
    Work experience placement
    Local area
    Remote work

    Mount Sinai Health System

    New York, NY
    2 days ago
  •  ...Division” which performs business functions. Information Risk Governance (“IRG”) provides oversight to information and cyber security risk by maintaining and improving branch...  ...Overview: The Third Party Information Security Analyst supports the Bank’s Third Party Risk... 
    Work at office
    Work from home
    Flexible hours
    2 days per week

    SUMITOMO MITSUI TRUST BANK, LIMITED

    New York, NY
    26 days ago
  • $145k - $170k

    CLEAR is building THE secure identity company of the future. Our mission is to make experiences...  ...is seeking a Senior Security Operations Analyst III to join our SOC team to help strengthen...  ...judgment to validate findings and make informed decisionsSolving complex security... 
    Casual work
    Work at office
    Flexible hours

    Secure Identity

    New York, NY
    1 day ago
  •  ...technology environment supporting enterprise security, data protection, and governance...  ...technology groups to strengthen how sensitive information is classified, protected, monitored, and...  ..., with a focus on aligning security controls to enterprise standards, regulatory expectations... 
    Contract work

    Axiom Path

    New York, NY
    5 days ago
  • $90k - $105k

     ...? The Vestwell Corporate Information Technology team is looking...  ...detail-oriented Information Security compliance analyst to be responsible for monitoring...  ...include reviewing our SOC controls and comparing them to...  ...Governance, Risk and Compliance (GRC) solution. Manage... 
    Contract work
    For subcontractor
    Work at office
    Local area

    Vestwell

    New York, NY
    14 days ago
  • Job-ID31409788Reference25-31660Title : SOC Analyst Location : New York City, Boston MA, Atlanta GA Shift : 3PM to 12AM EST Mon -...  ...rotationDescription: The SOC Analyst serves as the first line of defense for information security operationsmonitoring, investigating, and responding to... 
    Shift work

    Axelon

    New York, NY
    1 day ago
  •  ...Your Role Overview: Risk and Control Analyst is accountable for engaging in the proactive...  ...business operation environment and assure that measures are being taken to...  ...including exposure to technology risk, information/cyber security risk, vendor risk and/or model risk... 
    Work at office
    Remote work
    Flexible hours

    Network Temp Inc

    New York, NY
    a month ago
  •  ...seeking a Manager to join Technology Assurance - SAP Security & Controls in our Audit practice....  ...opportunities for improvement in the areas of GRC, security and controlsSupervise Managers...  ...The attached link contains further information regarding KPMG's compliance with federal... 
    H1b
    Local area

    KPMG

    New York, NY
    3 days ago
  • $73.5k - $147k

     ...clients and their employees—whether we’re designing affordable health plans, securing finances for retirement or aligning employees with workforce strategy. We are seeking a Health Actuary - Analyst III which can be located at one of the following Mercer office locations:... 
    Minimum wage
    Work experience placement
    Work at office
    Flexible hours

    Mercer

    New York, NY
    5 days ago
  • $80k - $95k

     ...With our expertise, we are not only creating data and information, but also producing timely insights from every angle...  ...us on this journey. Fitch Ratings is seeking an Analyst to join its Asset-Backed Securities (ABS) group in our Chicago or New York office. The... 
    Temporary work
    Work experience placement
    Internship
    Work at office
    Immediate start
    3 days per week

    Fitch Group

    New York, NY
    more than 2 months ago
  • $95k - $110k

     ...Fitch Ratings is currently seeking a Senior Analyst to join the Commercial Mortgage-Backed Securities (CMBS) group in our New York or Chicago office. About the Team: Fitch Ratings is a global company with a presence in over 30 countries, offering opportunities... 
    Temporary work
    Internship
    Work at office
    Immediate start
    Shift work
    3 days per week

    Fitch Group

    New York, NY
    14 days ago
  • $95k - $110k

     ...Fitch Ratings is seeking a Senior Analyst to join the Residential Mortgage-Backed Securities Group (RMBS) in our New York office. About the Team: The U.S. Residential Mortgage-Backed Securities (RMBS) group is adding a Credit Analyst or a Senior Credit Analyst... 
    Temporary work
    Internship
    Work at office
    Immediate start
    3 days per week

    Fitch Group

    New York, NY
    4 hours ago
  • $98.96k - $148.44k

     ...CitiThe Sec & Derivatives Sr Analyst is an intermediate level...  ...and investigation of client securities and derivatives transactions...  ...escalating, managing and reporting control issues with transparency....  ...holidays. For additional information regarding Citi employee benefits... 
    Full time

    Citigroup

    New York, NY
    2 days ago
  •  ...Success Academy is growing rapidly and security is at the forefront of enabling that...  .... We are seeking a Senior Security Analyst to join our Information Security & Privacy team. This...  ...advanced detection, DLP, and anti-phishing controls while continuously improving... 
    Work at office
    Immediate start
    Visa sponsorship
    3 days per week

    Success Academy Charter Schools

    New York, NY
    4 days ago
  • $129.84k - $194.76k

     ...CitiThe Sec & Derivatives Lead Analyst is a senior level position...  ...and investigation of client securities and derivatives transactions...  ..., managing and reporting control issues with transparency.Qualifications...  ...holidays. For additional information regarding Citi employee... 
    Full time

    Citigroup

    New York, NY
    1 day ago
  • $117.2k - $176.7k

     ...future of Salesforce.The ExperienceEnterprise Security is looking for a Senior Analyst to support our Business Information Security Officers (BISOs) in their day-to-day...  ...have strong understanding of security internal control methodologies and terminology (e.g., COSO, Cybersecurity... 
    Full time

    Salesforce

    New York, NY
    2 days ago
  • $35 - $40 per hour

     ...long-term environmental stewardship. Opportunity Summary The Control Room Operator (CRO) supports the safe, reliable, and efficient...  ...their rights pursuant to federal employment laws.For further information, please review the Know Your Rights notice from the Department... 
    Hourly pay
    Local area
    Flexible hours
    Shift work
    Night shift
    Rotating shift
    Weekend work

    Ultipro

    New York, NY
    1 day ago
  • $17 - $20 per hour

     ...the door of the #1 radio market? Join the family at AM 570 & 102.3 FM The Mission/WMCA and AM 970 The Answer/WNYM. As a PT Master Control Operator, you steer the ship of our programming on both stations. You will be overseeing programs, both live and pre-recorded and ensuring... 
    Hourly pay
    Shift work

    Salem Media Group

    New York, NY
    2 days ago
  • $135k - $192k

     ...Technology Risk Management Control Officer will serve as...  ...Provide quality assurance (QA) and reports on OpenPages...  ...development, secure by design, and system...  ...and holidays. For more information on our Total Rewards package...  ...Hiring Ordinance, (iii) the Los Angeles County... 
    Full time
    Work at office
    Local area
    Remote work
    1 day per week

    MUFG Bank, Ltd.

    New York, NY
    a month ago
  • $85k - $100k

     ...Fitch Group, a global leader in financial information services with operations in more than 3...  ...Hearst. At Fitch Ratings, credit analysts play a pivotal role in moving markets,...  ...of analysts performing CRE analysis on securities loans Provide Fitch’s opinions and... 
    Temporary work
    Internship
    Work at office
    Immediate start
    Shift work
    3 days per week

    Fitch Group

    New York, NY
    a month ago
  • $110k - $125k

     ...providing a wide range of investment banking, securities, investment management and wealth...  ...Within this multi-faceted group, the Analyst/Associate will concentrate on the marketing...  ..., talents, perspectives, and experiences. For more information, please visit:... 
    Full time
    Temporary work
    Worldwide

    Morgan Stanley

    New York, NY
    a month ago
  • $99.86k - $110.95k

     ...opportunities with us! Job Title Insurance Analyst III - Remote Requisition Number R7945...  ...- Home Teleworkers {+ 21 more} Job Information CSAA Insurance Group (CSAA IG), a...  ...procedure development and analysis needed for securing desired solution. Prepares findings... 
    Hourly pay
    H1b
    Work at office
    Remote work
    Work from home
    Flexible hours

    CSAA Insurance Group, a AAA Insurer

    New York, NY
    4 hours ago
  •  ...related to vendor and material qualification, including change controls and supplier notifications. Ensure all materials used in...  ...quality teams, legal, and vendors to generate and route Quality Assurance Agreements and support vendor audits. Provide support for inspection... 

    ClinLab Solutions Group

    New York, NY
    3 days ago
  •  ...cybersecurity firm is looking for a detail-oriented Entry-Level GRC Analyst to join their remote team. In this role, you'll work closely...  ...cybersecurity and compliance programs. You'll be involved in assessing controls, developing policies, and monitoring remediation efforts, all... 
    Remote work

    Hotman Group, LLC

    New York, NY
    1 day ago
  • $102.5k - $187.9k

     ...Governance, Risk, and Compliance (GRC), EY is seeking SAP Security and GRC professionals who...  ...and SAP GRC Access Control solutions across SAP...  ...degree in computer science, information systems, information...  ...spectrum of services in assurance, consulting, tax, strategy... 
    Summer holiday
    Flexible hours
    Shift work

    Ernst & Young

    New York, NY
    a month ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Information Security GRC Analyst III, Controls Assurance. Be the first to apply!