Information Security GRC Analyst — Controls Assurance

Fanatics Inc.

Jacksonville (FL)

On-site

USD 110,000 - 150,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Fanatics Inc. is seeking an Information Security GRC Analyst III, Controls Assurance, at corporate level.

You will work across PCI DSS, SOX ITGC, SOC reporting, and internal NIST-aligned baselines, collaborating with business units, IT, Security Operations, and GRC teams to demonstrate controls effectiveness. This role offers enterprise-wide visibility across Fanatics brands and subsidiaries, with a focus on testing, evidence collection, and remediation support in a fast-paced digital sports

Responsibilities

  • Execute assigned control tests in partnership with control set owners, including sample selection, evidence requests, walkthroughs, and documented conclusions on operating effectiveness.
  • Communicate control requirements, testing results, and rationale clearly and consistently to control owners across technical and non-technical audiences, and use that clarity to influence timely, positive adoption of controls and remediation.
  • Prepare workpapers that withstand assessor review without rework.
  • Evaluate evidence critically, identifying artifacts that do not substantiate the control.
  • Support QSA, audit, and service auditor engagements, including evidence request lists and walkthrough preparation.
  • Support user access review campaigns: population scoping, reviewer assignments, completion monitoring, and verification that revocations were executed.
  • Collect and quality-check evidence for framework cycles, resolving gaps before assessor fieldwork.
  • Support the control exception process: intake, routing, compensating controls, expiry tracking, and re-review.
  • Apply practical, risk-based judgment to grey-area control questions, including whether a compensating control adequately addresses the underlying risk given how a specific subsidiary or brand operates.
  • Identify opportunities to reduce manual evidence collection.
  • Help maintain the control library: owners, test procedures, evidence requirements, testing frequency, and system mappings.
  • Support cross-framework mapping, including mapping internal baseline controls to the external requirements they satisfy.
  • Support findings tracking and remediation follow-up, retesting closed items rather than accepting closure on assertion.
  • Contribute to control reporting and metrics, and to workflow upkeep in the designated GRC platform.
  • Partner day-to-day with business units, IT teams, Security Operations, and InfoSec GRC counterparts across Fanatics' subsidiaries and brands, understanding how each operates in order to apply controls appropriately.

Job description

Fanatics Inc. is seeking an Information Security GRC Analyst III, Controls Assurance, at corporate level.

You will work across PCI DSS, SOX ITGC, SOC reporting, and internal NIST-aligned baselines, collaborating with business units, IT, Security Operations, and GRC teams to demonstrate controls effectiveness. This role offers enterprise-wide visibility across Fanatics brands and subsidiaries, with a focus on testing, evidence collection, and remediation support in a fast-paced digital sports

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

GRC Controls Assurance Analyst III – Enterprise Security
GRC Controls Assurance Analyst III – Enterprise Security

Fanatics-fb44f34a • Jacksonville (FL)

On-site
USD 100,000 - 150,000
Information Security GRC Analyst III, Controls Assurance
Information Security GRC Analyst III, Controls Assurance

Fanatics Inc. • Jacksonville (FL)

On-site
USD 110,000 - 150,000
Senior Tech GRC Analyst: Governance, Risk & Compliance
Senior Tech GRC Analyst: Governance, Risk & Compliance

FanDuel • Atlanta (GA)

On-site
USD 120,000 - 160,000
FanDuel Total Rewards
Health plans
PTO & sick leave
+5
Senior Tech GRC Analyst: Governance, Risk & Compliance
Senior Tech GRC Analyst: Governance, Risk & Compliance

Doist • Atlanta (GA)

On-site
USD 138,000 - 173,000
Health plans
Paid time off
401(k) with company match
+1
Remote Technology Risk & SOX Controls Analyst
Remote Technology Risk & SOX Controls Analyst

Jobright.ai • New York (NY)

On-site
USD 85,000 - 105,000
Technology Risk and Internal Controls Analyst, Entry Level (Remote)
Technology Risk and Internal Controls Analyst, Entry Level (Remote)

Jobright.ai • New York (NY)

On-site
USD 85,000 - 105,000
Information Security GRC Analyst III, Controls Assurance
Information Security GRC Analyst III, Controls Assurance

Fanatics-fb44f34a • Jacksonville (FL)

On-site
USD 100,000 - 150,000
Senior Tech GRC Strategist: Risk & Controls
Senior Tech GRC Strategist: Risk & Controls

Doist • New York (NY)

Hybrid
USD 138,000 - 173,000
Health plans
PTO & sick leave
Annual bonus
+4
Senior Information Security GRC Analyst
Senior Information Security GRC Analyst

CareSource • United States

On-site
USD 94,000 - 165,000
Bonus potential
Total rewards package
Senior GRC Cybersecurity Strategist
Senior GRC Cybersecurity Strategist

ICCU • Meridian (ID), Chubbuck (ID)

On-site
USD 105,000 - 150,000