Information Security GRC Analyst III, Controls Assurance

Fanatics-fb44f34a

Jacksonville (FL)

On-site

USD 100,000 - 150,000

Full time

30 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Fanatics Information Security is hiring an experienced GRC Analyst III, Controls Assurance. You will verify control effectiveness across PCI DSS, SOX ITGC, SOC reporting, and internal baselines, partnering with control owners across Fanatics brands and subsidiaries.

You will collect evidence, manage user access reviews, and contribute to findings tracking, remediation, and reporting in a fast-paced, enterprise-wide security program.

Qualifications

  • Four years+ in IT audit, IT control testing, information security GRC, or a related discipline.
  • Experience executing control tests to a defined procedure, including sampling, evidence evaluation, and documented conclusions.
  • Experience with user access reviews, either administering campaigns or testing them as a control.
  • Exposure to PCI DSS, SOX ITGC, SOC, or an internal security control baseline.
  • Experience driving a recurring process across stakeholders outside a direct reporting line.
  • Curiosity and adaptability to understand how Fanatics's subsidiaries and brands operate.
  • Knowledge of core control domains: access management, change management, SDLC, logging, encryption, backups, and cloud fundamentals.
  • Excellent written and verbal communication skills.
  • Preferred: CISA certification.
  • Preferred: exposure to two or more of PCI DSS, SOX ITGC, and SOC, including familiarity with PCI DSS v4.0.1 and NIST CSF.
  • Preferred: familiarity with an enterprise GRC platform.

Responsibilities

  • Execute control tests in partnership with control set owners, including sampling, evidence requests, walkthroughs, and conclusions.
  • Communicate control requirements and results clearly to control owners, influencing timely remediation.
  • Prepare workpapers that withstand assessor review with minimal rework.
  • Evaluate evidence critically and identify non-substantiating artifacts.
  • Support QSA, audit, and service auditor engagements with evidence lists and walkthroughs.
  • Support user access review campaigns: scoping, assignments, monitoring, and revocation verification.
  • Collect and quality-check evidence for framework cycles and close gaps before fieldwork.
  • Assist control exception processes: intake, routing, compensating controls, expiry tracking, re-review.
  • Apply risk-based judgment to grey-area questions and compensating controls.
  • Identify opportunities to reduce manual evidence collection.
  • Maintain the control library: owners, test procedures, evidence requirements, testing frequency, and mappings.
  • Support cross-framework mapping to satisfy external requirements.
  • Contribute to findings tracking, remediation, and retesting of closed items.
  • Participate in control reporting and metrics, and update the GRC platform workflows.
  • Collaborate daily with business units, IT, Security Operations, and InfoSec GRC counterparts across Fanatics's brands.
  • Build depth across control sets to cover during leave or peak workloads.

Skills

IT audit
IT control testing
GRC
Control testing procedures
User access reviews
PCI DSS
SOX ITGC
SOC
Communication
AI tools usage

Education

Bachelor's degree in information security or related field
CISA certification

Tools

GRC platform

Job description

Information Security GRC Analyst III, Controls Assurance
About Us

Fanatics is building a leading global digital sports platform. We ignite the passions of global sports fans and maximize the presence and reach for our hundreds of sports partners globally by offering products and services across Fanatics Commerce, Fanatics Collectibles, and Fanatics Betting & Gaming, allowing sports fans to Buy, Collect, and Bet. Through the Fanatics platform, sports fans can buy licensed fan gear, jerseys, lifestyle and streetwear products, headwear, and hardgoods; collect physical and digital trading cards, sports memorabilia, and other digital assets; and bet as the company builds its Sportsbook and iGaming platform. Fanatics has an established database of over 100 million global sports fans; a global partner network with approximately 900 sports properties, including major national and international professional sports leagues, players associations, teams, colleges, college conferences and retail partners, 2,500 athletes and celebrities, and 200 exclusive athletes; and over 2,000 retail locations, including its Lids retail stores. Our more than 22,000 employees are committed to relentlessly enhancing the fan experience and delighting sports fans globally.

The Role
The Information Security GRC Analyst III, Controls Assurance (Fanatics Corporate) sits at the center of how Fanatics proves its security controls actually work, testing across PCI DSS, SOX ITGC, SOC reporting, and our internal NIST-aligned control baselines. This is a Corporate-level role with direct exposure across the full Fanatics portfolio: you will work daily with business units, IT teams, Security Operations, and InfoSec GRC counterparts across our subsidiaries and brands, giving you a rare, enterprise-wide view of how a global, multi-brand organization operates and secures itself.

Working in partnership with the designated owner of each control set, you will execute assigned control testing, collect and evaluate evidence, support user access reviews and control exception administration, and contribute to findings tracking and control reporting. Control effectiveness is rarely a clean pass or fail; you will need to read the intent behind a control, work through the grey areas, and take a practical, risk-based approach to compensating controls, tailored to how each subsidiary or brand actually does business. Strong communication is central to the role: you will explain technical and non-technical control requirements clearly and consistently to control owners, and use that clarity to influence timely, positive adoption of controls and remediation.

Control baselines and framework control sets are established and owned within the GRC team, so this is a controls assurance role rather than a program build-out or control design role. A substantial portion of the work is recurring and deadline-driven, including access review cycles, evidence collection, and assessment calendars.

What You'll Do
  • Execute assigned control tests in partnership with control set owners, including: sample selection, evidence requests, walkthroughs, and documented conclusions on operating effectiveness.
  • Communicate control requirements, testing results, and rationale clearly and consistently to control owners across technical and non-technical audiences, and use that clarity to influence timely, positive adoption of controls and remediation.
  • Prepare workpapers that withstand assessor review without rework.
  • Evaluate evidence critically, identifying artifacts that do not substantiate the control.
  • Support QSA, audit, and service auditor engagements, including evidence request lists and walkthrough preparation.
  • Support user access review campaigns: population scoping, reviewer assignments, completion monitoring, and verification that revocations were executed.
  • Collect and quality-check evidence for framework cycles, resolving gaps before assessor fieldwork.
  • Support the control exception process: intake, routing, compensating controls, expiry tracking, and re-review.
  • Apply practical, risk-based judgment to grey-area control questions, including whether a compensating control adequately addresses the underlying risk given how a specific subsidiary or brand operates.
  • Identify opportunities to reduce manual evidence collection.
  • Help maintain the control library: owners, test procedures, evidence requirements, testing frequency, and system mappings.
  • Support cross-framework mapping, including mapping internal baseline controls to the external requirements they satisfy.
  • Support findings tracking and remediation follow-up, retesting closed items rather than accepting closure on assertion.
  • Contribute to control reporting and metrics, and to workflow upkeep in the designated GRC platform.
  • Partner day-to-day with business units, IT teams, Security Operations, and InfoSec GRC counterparts across Fanatics's subsidiaries and brands, understanding how each operates in order to apply controls appropriately.
  • Build sufficient depth across control sets to provide backup coverage during leave, peak workload, or overlapping cycles.
What We're Looking For
  • Four years + in IT audit, IT control testing, information security GRC, or a related discipline; Big Four or regional firm IT audit experience applies directly.
  • Demonstrated experience executing control tests to a defined procedure, including sampling, evidence evaluation, and documented conclusions.
  • Experience with user access reviews, either administering campaigns or testing them as a control.
  • Exposure to at least one of PCI DSS, SOX ITGC, SOC, or an internal security control baseline.
  • Experience driving a recurring process across stakeholders outside a direct reporting line, with a record of following items to completion.
  • Curiosity and adaptability to understand how Fanatics's different subsidiaries and brands operate, and how that context shapes how a control should be applied and assessed for effectiveness.
  • Working knowledge of core control domains: access management and access reviews, privileged access, change management, SDLC, logging and monitoring, encryption, vulnerability and patch management, backup and recovery, and cloud platform fundamentals.
  • Excellent written and verbal communication, with the ability to explain technical and non-technical control concepts clearly and consistently to control owners, and to influence stakeholders toward timely, positive adoption of controls and remediation, even without direct authority over them.
  • Effective use of approved AI tools in day-to-day work, with sound judgment about where AI output can and cannot be relied upon in an audit context.
  • Organizational discipline, persistence, and judgment about when to escape.
  • Detail-oriented, with sound judgment for navigating grey areas in control descriptions and a practical, risk-based approach to evaluating compensating controls rather than a strict pass/fail mindset.
  • Bachelor's degree in information security, cybersecurity, information systems, accounting, or a related field, or equivalent practical experience.
  • Preferred: CISA certification.
  • Preferred: exposure to two or more of PCI DSS, SOX ITGC, and SOC, including familiarity with PCI DSS v4.0.1, and testing against NIST 800-53 or the NIST Cybersecurity Framework.
  • Preferred: familiarity with an enterprise GRC or IRM platform

The salary range represents base pay only and does not include short-term or long-term incentive compensation. This salary range is specific to New York City and may not be applicable to other locations. When determining base pay, as part of a final compensation package, we consider several factors such as location, experience, qualifications, and training. For information about our benefits, please visit https://benefitsatfanatics.com/

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey.Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiringprocess or thereafter. Any information that you do provide will be recorded and maintained in aconfidential file.

As set forth in Fanatics Inc.’s Equal Employment Opportunity policy,we do not discriminate on the basis of any protected group status under any applicable law.

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection.As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measurethe effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categoriesis as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Engineer, Web
Senior Engineer, Web

Fanatics Collectibles • New York (NY)

Hybrid
USD 150,000 - 210,000
Treasury Analyst
Treasury Analyst

Fanatics Collectibles • New York (NY)

On-site
USD 85,000 - 115,000
Officer, Security & Loss Prevention - 3rd Shift
Officer, Security & Loss Prevention - 3rd Shift

Fanatics • Dallas (TX)

On-site
USD 42,000 - 54,000
Officer, Security & Loss Prevention - 3rd Shift
Officer, Security & Loss Prevention - 3rd Shift

Fanatics Collectibles • Sunnyvale (TX)

On-site
USD 23,000 - 32,000
IT Operations Lead
IT Operations Lead

Fanatics Collectibles • Tigard (OR)

On-site
USD 110,000 - 160,000
Officer, Security & Loss Prevention - 2nd Shift
Officer, Security & Loss Prevention - 2nd Shift

Fanatics • Sunnyvale (TX)

On-site
USD 42,000 - 54,000
Director, Strategy Analytics
Director, Strategy Analytics

Fanatics Commerce • San Mateo (CA)

On-site
USD 141,000 - 235,000
Information Security GRC Analyst III, Controls Assurance
Information Security GRC Analyst III, Controls Assurance

Fanatics Inc. • Jacksonville (FL)

On-site
USD 110,000 - 150,000
Software Engineer, Android
Software Engineer, Android

Fanatics • Los Angeles (CA)

On-site
USD 120,000 - 170,000
Director, Physical Security Technology
Director, Physical Security Technology

Fanatics • Dallas (TX), New York (NY)

On-site
USD 180,000 - 260,000