Information Security GRC Analyst III, Controls Assurance
$120k - $160kFanatics Inc.
About Us Fanatics is building a leading global digital sports platform. We ignite the passions of global sports fans and maximize the presence and reach for our hundreds of sports partners globally by offering products and services across Fanatics Commerce, Fanatics Collectibles, and Fanatics Betting & Gaming, allowing sports fans to Buy, Collect, and Bet. Through the Fanatics platform, sports fans can buy licensed fan gear, jerseys, lifestyle and streetwear products, headwear, and hardgoods; collect physical and digital trading cards, sports memorabilia, and other digital assets; and bet as the company builds its Sportsbook and iGaming platform. Fanatics has an established database of over 100 million global sports fans; a global partner network with approximately 900 sports properties, including major national and international professional sports leagues, players associations, teams, colleges, college conferences and retail partners, 2,500 athletes and celebrities, and 200 exclusive athletes; and over 2,000 retail locations, including its Lids retail stores. Our more than 22,000 employees are committed to relentlessly enhancing the fan experience and delighting sports fans globally.
The Role
The Information Security GRC Analyst III, Controls Assurance (Fanatics Corporate) sits at the center of how Fanatics proves its security controls actually work, testing across PCI DSS, SOX ITGC, SOC reporting, and our internal NIST-aligned control baselines. This is a Corporate-level role with direct exposure across the full Fanatics portfolio: you will work daily with business units, IT teams, Security Operations, and InfoSec GRC counterparts across our subsidiaries and brands, giving you a rare, enterprise-wide view of how a global, multi-brand organization operates and secures itself.
Working in partnership with the designated owner of each control set, you will execute assigned control testing, collect and evaluate evidence, support user access reviews and control exception administration, and contribute to findings tracking and control reporting. Control effectiveness is rarely a clean pass or fail; you will need to read the intent behind a control, work through the grey areas, and take a practical, risk-based approach to compensating controls, tailored to how each subsidiary or brand actually does business. Strong communication is central to the role: you will explain technical and non-technical control requirements clearly and consistently to control owners, and use that clarity to influence timely, positive adoption of controls and remediation.
Control baselines and framework control sets are established and owned within the GRC team, so this is a controls assurance role rather than a program build-out or control design role. A substantial portion of the work is recurring and deadline-driven, including access review cycles, evidence collection, and assessment calendars.
What You'll Do
Execute assigned control tests in partnership with control set owners, including: sample selection, evidence requests, walkthroughs, and documented conclusions on operating effectiveness.
Communicate control requirements, testing results, and rationale clearly and consistently to control owners across technical and non-technical audiences, and use that clarity to influence timely, positive adoption of controls and remediation.
Prepare workpapers that withstand assessor review without rework.
Evaluate evidence critically, identifying artifacts that do not substantiate the control.
Support QSA, audit, and service auditor engagements, including evidence request lists and walkthrough preparation.
Support user access review campaigns: population scoping, reviewer assignments, completion monitoring, and verification that revocations were executed.
Collect and quality-check evidence for framework cycles, resolving gaps before assessor fieldwork.
Support the control exception process: intake, routing, compensating controls, expiry tracking, and re-review.
Apply practical, risk-based judgment to grey-area control questions, including whether a compensating control adequately addresses the underlying risk given how a specific subsidiary or brand operates.
Identify opportunities to reduce manual evidence collection.
Help maintain the control library: owners, test procedures, evidence requirements, testing frequency, and system mappings.
Support cross-framework mapping, including mapping internal baseline controls to the external requirements they satisfy.
Support findings tracking and remediation follow-up, retesting closed items rather than accepting closure on assertion.
Contribute to control reporting and metrics, and to workflow upkeep in the designated GRC platform.
Partner day-to-day with business units, IT teams, Security Operations, and InfoSec GRC counterparts across Fanatics' subsidiaries and brands, understanding how each operates in order to apply controls appropriately.
Build sufficient depth across control sets to provide backup coverage during leave, peak workload, or overlapping cycles.
What We're Looking For
Four years + in IT audit, IT control testing, information security GRC, or a related discipline; Big Four or regional firm IT audit experience applies directly.
Demonstrated experience executing control tests to a defined procedure, including sampling, evidence evaluation, and documented conclusions.
Experience with user access reviews, either administering campaigns or testing them as a control.
Exposure to at least one of PCI DSS, SOX ITGC, SOC, or an internal security control baseline.
Experience driving a recurring process across stakeholders outside a direct reporting line, with a record of following items to completion.
Curiosity and adaptability to understand how Fanatics' different subsidiaries and brands operate, and how that context shapes how a control should be applied and assessed for effectiveness.
Working knowledge of core control domains: access management and access reviews, privileged access, change management, SDLC, logging and monitoring, encryption, vulnerability and patch management, backup and recovery, and cloud platform fundamentals.
Excellent written and verbal communication, with the ability to explain technical and non-technical control concepts clearly and consistently to control owners, and to influence stakeholders toward timely, positive adoption of controls and remediation, even without direct authority over them.
Effective use of approved AI tools in day-to-day work, with sound judgment about where AI output can and cannot be relied upon in an audit context.
Organizational discipline, persistence, and judgment about when to escalate.
Detail-oriented, with sound judgment for navigating grey areas in control descriptions and a practical, risk-based approach to evaluating compensating controls rather than a strict pass/fail mindset.
Bachelor's degree in information security, cybersecurity, information systems, accounting, or a related field, or equivalent practical experience.
Preferred: CISA certification.
Preferred: exposure to two or more of PCI DSS, SOX ITGC, and SOC, including familiarity with PCI DSS v4.0.1, and testing against NIST 800-53 or the NIST Cybersecurity Framework.
Preferred: familiarity with an enterprise GRC or IRM platform
The salary range represents base pay only and does not include short-term or long-term incentive compensation. This salary range is specific to New York City and may not be applicable to other locations. When determining base pay, as part of a final compensation package, we consider several factors such as location, experience, qualifications, and training. For information about our benefits, please visit
NYC Salary Range
$120,000—$160,000 USD
By submitting your application, you agree to our terms of service and acknowledge you have read our Candidate Privacy Policy.
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Information Security GRC Analyst III, Controls Assurance in New York, NY vacancy
$134.16k - $213.6k
...About the Team: The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s... ...by proactively managing information security risks and maintaining effective controls. Our mission is to reduce... ...while operating a robust assurance program that builds trust...SuggestedRemote jobFull timeContract workWork experience placementLocal area- ...performs business functions. Information Risk Governance (“IRG”) provides... ...to information and cyber security risk by maintaining and improving... ...Operations Center (SOC) Analyst is responsible for monitoring... ...system, Firewalls, Network Access Control (NAC), Network Detection &...SuggestedWork at officeWork from homeFlexible hours2 days per week
- ...performs business functions. Information Risk Governance (“IRG”)... ...oversight to information and cyber security risk by maintaining and... ...The Information Security Risk Analyst is responsible for supporting... ...components such as domain controllers, DHCP, DNS, and Active Directory...SuggestedWork at officeWork from homeFlexible hours2 days per week
$75k - $85k
...IT Security Analyst Who is Gen II? Gen II is a leading fund administration... ...Support the Chief Information Security Officer in developing an IT security assurance program Develop general... ...documentation describing security controls, system specifications, and operating...SuggestedFull timeWork at officeFlexible hours1 day per week$118.68k - $175.8k
...and Amsterdam. Team: The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s... ...by proactively managing information security risks and maintaining effective controls. Our mission is to reduce... ...while operating a robust assurance program that builds trust...SuggestedRemote jobFull timeWork experience placementLocal area$99.2k - $148.8k
DescriptionThe Applications Analyst III supervises and provides technical guidance to the... ...2. Assists in planning, organizing and controlling the activities of the section. 3. May work... ..., diverse work experience in ITEpic Security Certification and experience required.Employer...TraineeshipWork experience placementLocal areaRemote work- ...Division” which performs business functions. Information Risk Governance (“IRG”) provides oversight to information and cyber security risk by maintaining and improving branch... ...Overview: The Third Party Information Security Analyst supports the Bank’s Third Party Risk...Work at officeWork from homeFlexible hours2 days per week
$145k - $170k
CLEAR is building THE secure identity company of the future. Our mission is to make experiences... ...is seeking a Senior Security Operations Analyst III to join our SOC team to help strengthen... ...judgment to validate findings and make informed decisionsSolving complex security...Casual workWork at officeFlexible hours- ...technology environment supporting enterprise security, data protection, and governance... ...technology groups to strengthen how sensitive information is classified, protected, monitored, and... ..., with a focus on aligning security controls to enterprise standards, regulatory expectations...Contract work
$90k - $105k
...? The Vestwell Corporate Information Technology team is looking... ...detail-oriented Information Security compliance analyst to be responsible for monitoring... ...include reviewing our SOC controls and comparing them to... ...Governance, Risk and Compliance (GRC) solution. Manage...Contract workFor subcontractorWork at officeLocal area- Job-ID31409788Reference25-31660Title : SOC Analyst Location : New York City, Boston MA, Atlanta GA Shift : 3PM to 12AM EST Mon -... ...rotationDescription: The SOC Analyst serves as the first line of defense for information security operationsmonitoring, investigating, and responding to...Shift work
- ...Your Role Overview: Risk and Control Analyst is accountable for engaging in the proactive... ...business operation environment and assure that measures are being taken to... ...including exposure to technology risk, information/cyber security risk, vendor risk and/or model risk...Work at officeRemote workFlexible hours
- ...seeking a Manager to join Technology Assurance - SAP Security & Controls in our Audit practice.... ...opportunities for improvement in the areas of GRC, security and controlsSupervise Managers... ...The attached link contains further information regarding KPMG's compliance with federal...H1bLocal area
$73.5k - $147k
...clients and their employees—whether we’re designing affordable health plans, securing finances for retirement or aligning employees with workforce strategy. We are seeking a Health Actuary - Analyst III which can be located at one of the following Mercer office locations:...Minimum wageWork experience placementWork at officeFlexible hours$80k - $95k
...With our expertise, we are not only creating data and information, but also producing timely insights from every angle... ...us on this journey. Fitch Ratings is seeking an Analyst to join its Asset-Backed Securities (ABS) group in our Chicago or New York office. The...Temporary workWork experience placementInternshipWork at officeImmediate start3 days per week$95k - $110k
...Fitch Ratings is currently seeking a Senior Analyst to join the Commercial Mortgage-Backed Securities (CMBS) group in our New York or Chicago office. About the Team: Fitch Ratings is a global company with a presence in over 30 countries, offering opportunities...Temporary workInternshipWork at officeImmediate startShift work3 days per week$95k - $110k
...Fitch Ratings is seeking a Senior Analyst to join the Residential Mortgage-Backed Securities Group (RMBS) in our New York office. About the Team: The U.S. Residential Mortgage-Backed Securities (RMBS) group is adding a Credit Analyst or a Senior Credit Analyst...Temporary workInternshipWork at officeImmediate start3 days per week$98.96k - $148.44k
...CitiThe Sec & Derivatives Sr Analyst is an intermediate level... ...and investigation of client securities and derivatives transactions... ...escalating, managing and reporting control issues with transparency.... ...holidays. For additional information regarding Citi employee benefits...Full time- ...Success Academy is growing rapidly and security is at the forefront of enabling that... .... We are seeking a Senior Security Analyst to join our Information Security & Privacy team. This... ...advanced detection, DLP, and anti-phishing controls while continuously improving...Work at officeImmediate startVisa sponsorship3 days per week
$129.84k - $194.76k
...CitiThe Sec & Derivatives Lead Analyst is a senior level position... ...and investigation of client securities and derivatives transactions... ..., managing and reporting control issues with transparency.Qualifications... ...holidays. For additional information regarding Citi employee...Full time$117.2k - $176.7k
...future of Salesforce.The ExperienceEnterprise Security is looking for a Senior Analyst to support our Business Information Security Officers (BISOs) in their day-to-day... ...have strong understanding of security internal control methodologies and terminology (e.g., COSO, Cybersecurity...Full time$35 - $40 per hour
...long-term environmental stewardship. Opportunity Summary The Control Room Operator (CRO) supports the safe, reliable, and efficient... ...their rights pursuant to federal employment laws.For further information, please review the Know Your Rights notice from the Department...Hourly payLocal areaFlexible hoursShift workNight shiftRotating shiftWeekend work$17 - $20 per hour
...the door of the #1 radio market? Join the family at AM 570 & 102.3 FM The Mission/WMCA and AM 970 The Answer/WNYM. As a PT Master Control Operator, you steer the ship of our programming on both stations. You will be overseeing programs, both live and pre-recorded and ensuring...Hourly payShift work$135k - $192k
...Technology Risk Management Control Officer will serve as... ...Provide quality assurance (QA) and reports on OpenPages... ...development, secure by design, and system... ...and holidays. For more information on our Total Rewards package... ...Hiring Ordinance, (iii) the Los Angeles County...Full timeWork at officeLocal areaRemote work1 day per week$85k - $100k
...Fitch Group, a global leader in financial information services with operations in more than 3... ...Hearst. At Fitch Ratings, credit analysts play a pivotal role in moving markets,... ...of analysts performing CRE analysis on securities loans Provide Fitch’s opinions and...Temporary workInternshipWork at officeImmediate startShift work3 days per week$110k - $125k
...providing a wide range of investment banking, securities, investment management and wealth... ...Within this multi-faceted group, the Analyst/Associate will concentrate on the marketing... ..., talents, perspectives, and experiences. For more information, please visit:...Full timeTemporary workWorldwide$99.86k - $110.95k
...opportunities with us! Job Title Insurance Analyst III - Remote Requisition Number R7945... ...- Home Teleworkers {+ 21 more} Job Information CSAA Insurance Group (CSAA IG), a... ...procedure development and analysis needed for securing desired solution. Prepares findings...Hourly payH1bWork at officeRemote workWork from homeFlexible hours- ...related to vendor and material qualification, including change controls and supplier notifications. Ensure all materials used in... ...quality teams, legal, and vendors to generate and route Quality Assurance Agreements and support vendor audits. Provide support for inspection...
- ...cybersecurity firm is looking for a detail-oriented Entry-Level GRC Analyst to join their remote team. In this role, you'll work closely... ...cybersecurity and compliance programs. You'll be involved in assessing controls, developing policies, and monitoring remediation efforts, all...Remote work
$102.5k - $187.9k
...Governance, Risk, and Compliance (GRC), EY is seeking SAP Security and GRC professionals who... ...and SAP GRC Access Control solutions across SAP... ...degree in computer science, information systems, information... ...spectrum of services in assurance, consulting, tax, strategy...Summer holidayFlexible hoursShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Information Security GRC Analyst III, Controls Assurance. Be the first to apply!
Related searches
- entry level information security analyst New York, NY
- data protection analyst New York, NY
- data analyst intern New York, NY
- regulatory reporting analyst New York, NY
- junior healthcare data analyst New York, NY
- senior data management analyst New York, NY
- data analyst - r python sql New York, NY
- data visualization analyst New York, NY
- data analyst New York, NY
- oracle data analyst New York, NY


