GRC Controls Assurance Analyst III – Enterprise Security

Fanatics-fb44f34a

Jacksonville (FL)

On-site

USD 100,000 - 150,000

Full time

37 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Fanatics Information Security is hiring an experienced GRC Analyst III, Controls Assurance. You will verify control effectiveness across PCI DSS, SOX ITGC, SOC reporting, and internal baselines, partnering with control owners across Fanatics brands and subsidiaries.

You will collect evidence, manage user access reviews, and contribute to findings tracking, remediation, and reporting in a fast-paced, enterprise-wide security program.

Qualifications

  • Four years+ in IT audit, IT control testing, information security GRC, or a related discipline.
  • Experience executing control tests to a defined procedure, including sampling, evidence evaluation, and documented conclusions.
  • Experience with user access reviews, either administering campaigns or testing them as a control.
  • Exposure to PCI DSS, SOX ITGC, SOC, or an internal security control baseline.
  • Experience driving a recurring process across stakeholders outside a direct reporting line.
  • Curiosity and adaptability to understand how Fanatics's subsidiaries and brands operate.
  • Knowledge of core control domains: access management, change management, SDLC, logging, encryption, backups, and cloud fundamentals.
  • Excellent written and verbal communication skills.
  • Preferred: CISA certification.
  • Preferred: exposure to two or more of PCI DSS, SOX ITGC, and SOC, including familiarity with PCI DSS v4.0.1 and NIST CSF.
  • Preferred: familiarity with an enterprise GRC platform.

Responsibilities

  • Execute control tests in partnership with control set owners, including sampling, evidence requests, walkthroughs, and conclusions.
  • Communicate control requirements and results clearly to control owners, influencing timely remediation.
  • Prepare workpapers that withstand assessor review with minimal rework.
  • Evaluate evidence critically and identify non-substantiating artifacts.
  • Support QSA, audit, and service auditor engagements with evidence lists and walkthroughs.
  • Support user access review campaigns: scoping, assignments, monitoring, and revocation verification.
  • Collect and quality-check evidence for framework cycles and close gaps before fieldwork.
  • Assist control exception processes: intake, routing, compensating controls, expiry tracking, re-review.
  • Apply risk-based judgment to grey-area questions and compensating controls.
  • Identify opportunities to reduce manual evidence collection.
  • Maintain the control library: owners, test procedures, evidence requirements, testing frequency, and mappings.
  • Support cross-framework mapping to satisfy external requirements.
  • Contribute to findings tracking, remediation, and retesting of closed items.
  • Participate in control reporting and metrics, and update the GRC platform workflows.
  • Collaborate daily with business units, IT, Security Operations, and InfoSec GRC counterparts across Fanatics's brands.
  • Build depth across control sets to cover during leave or peak workloads.

Skills

IT audit
IT control testing
GRC
Control testing procedures
User access reviews
PCI DSS
SOX ITGC
SOC
Communication
AI tools usage

Education

Bachelor's degree in information security or related field
CISA certification

Tools

GRC platform

Job description

Fanatics Information Security is hiring an experienced GRC Analyst III, Controls Assurance. You will verify control effectiveness across PCI DSS, SOX ITGC, SOC reporting, and internal baselines, partnering with control owners across Fanatics brands and subsidiaries.

You will collect evidence, manage user access reviews, and contribute to findings tracking, remediation, and reporting in a fast-paced, enterprise-wide security program.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security GRC Analyst — Controls Assurance
Information Security GRC Analyst — Controls Assurance

Fanatics Inc. • Jacksonville (FL)

On-site
USD 110,000 - 150,000
Information Security GRC Analyst III, Controls Assurance
Information Security GRC Analyst III, Controls Assurance

Fanatics Inc. • Jacksonville (FL)

On-site
USD 110,000 - 150,000
Senior Tech GRC Analyst: Governance, Risk & Compliance
Senior Tech GRC Analyst: Governance, Risk & Compliance

FanDuel • Atlanta (GA)

On-site
USD 120,000 - 160,000
FanDuel Total Rewards
Health plans
PTO & sick leave
+5
Senior Tech GRC Analyst: Governance, Risk & Compliance
Senior Tech GRC Analyst: Governance, Risk & Compliance

Doist • Atlanta (GA)

On-site
USD 138,000 - 173,000
Health plans
Paid time off
401(k) with company match
+1
Senior GRC Analyst
Senior GRC Analyst

Averity • New York (NY)

On-site
USD 90,000 - 140,000
Remote Technology Risk & SOX Controls Analyst
Remote Technology Risk & SOX Controls Analyst

Jobright.ai • New York (NY)

On-site
USD 85,000 - 105,000
Senior GRC Cybersecurity Strategist
Senior GRC Cybersecurity Strategist

ICCU • Meridian (ID), Chubbuck (ID)

On-site
USD 105,000 - 150,000
Senior GRC Analyst: PCI & SOC 2 Compliance Lead – Onsite
Senior GRC Analyst: PCI & SOC 2 Compliance Lead – Onsite

Wolfe,-LLC-1 • Pittsburgh

On-site
USD 114,000 - 163,000
RSUs
Profit Sharing
Medical Insurance
+5
GRC-Driven IT Security & Compliance Specialist
GRC-Driven IT Security & Compliance Specialist

Spirit Airlines • Little Rock (AR)

On-site
USD 110,000 - 160,000
GRC & Security Compliance Analyst
GRC & Security Compliance Analyst

Socket.dev • Austin (TX)

On-site
USD 85,000 - 105,000