Information Security GRC Analyst III, Controls Assurance

Fanatics Inc.

Jacksonville (FL)

On-site

USD 110,000 - 150,000

Full time

4 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Fanatics Inc. is seeking an Information Security GRC Analyst III, Controls Assurance, at corporate level.

You will work across PCI DSS, SOX ITGC, SOC reporting, and internal NIST-aligned baselines, collaborating with business units, IT, Security Operations, and GRC teams to demonstrate controls effectiveness. This role offers enterprise-wide visibility across Fanatics brands and subsidiaries, with a focus on testing, evidence collection, and remediation support in a fast-paced digital sports

Responsibilities

  • Execute assigned control tests in partnership with control set owners, including sample selection, evidence requests, walkthroughs, and documented conclusions on operating effectiveness.
  • Communicate control requirements, testing results, and rationale clearly and consistently to control owners across technical and non-technical audiences, and use that clarity to influence timely, positive adoption of controls and remediation.
  • Prepare workpapers that withstand assessor review without rework.
  • Evaluate evidence critically, identifying artifacts that do not substantiate the control.
  • Support QSA, audit, and service auditor engagements, including evidence request lists and walkthrough preparation.
  • Support user access review campaigns: population scoping, reviewer assignments, completion monitoring, and verification that revocations were executed.
  • Collect and quality-check evidence for framework cycles, resolving gaps before assessor fieldwork.
  • Support the control exception process: intake, routing, compensating controls, expiry tracking, and re-review.
  • Apply practical, risk-based judgment to grey-area control questions, including whether a compensating control adequately addresses the underlying risk given how a specific subsidiary or brand operates.
  • Identify opportunities to reduce manual evidence collection.
  • Help maintain the control library: owners, test procedures, evidence requirements, testing frequency, and system mappings.
  • Support cross-framework mapping, including mapping internal baseline controls to the external requirements they satisfy.
  • Support findings tracking and remediation follow-up, retesting closed items rather than accepting closure on assertion.
  • Contribute to control reporting and metrics, and to workflow upkeep in the designated GRC platform.
  • Partner day-to-day with business units, IT teams, Security Operations, and InfoSec GRC counterparts across Fanatics' subsidiaries and brands, understanding how each operates in order to apply controls appropriately.

Job description

About Us

Fanatics is building a leading global digital sports platform. We ignite the passions of global sports fans and maximize the presence and reach for our hundreds of sports partners globally by offering products and services across Fanatics Commerce, Fanatics Collectibles, and Fanatics Betting & Gaming, allowing sports fans to Buy, Collect, and Bet. Through the Fanatics platform, sports fans can buy licensed fan gear, jerseys, lifestyle and streetwear products, headwear, and hardgoods; collect physical and digital trading cards, sports memorabilia, and other digital assets; and bet as the company builds its Sportsbook and iGaming platform. Fanatics has an established database of over 100 million global sports fans; a global partner network with approximately 900 sports properties, including major national and international professional sports leagues, players associations, teams, colleges, college conferences and retail partners, 2,500 athletes and celebrities, and 200 exclusive athletes; and over 2,000 retail locations, including its Lids retail stores. Our more than 22,000 employees are committed to relentlessly enhancing the fan experience and delighting sports fans globally.


The Role

The Information Security GRC Analyst III, Controls Assurance (Fanatics Corporate) sits at the center of how Fanatics proves its security controls actually work, testing across PCI DSS, SOX ITGC, SOC reporting, and our internal NIST-aligned control baselines. This is a Corporate-level role with direct exposure across the full Fanatics portfolio: you will work daily with business units, IT teams, Security Operations, and InfoSec GRC counterparts across our subsidiaries and brands, giving you a rare, enterprise-wide view of how a global, multi-brand organization operates and secures itself.


What You'll Do


  • Execute assigned control tests in partnership with control set owners, including: sample selection, evidence requests, walkthroughs, and documented conclusions on operating effectiveness.

  • Communicate control requirements, testing results, and rationale clearly and consistently to control owners across technical and non-technical audiences, and use that clarity to influence timely, positive adoption of controls and remediation.

  • Prepare workpapers that withstand assessor review without rework.

  • Evaluate evidence critically, identifying artifacts that do not substantiate the control.

  • Support QSA, audit, and service auditor engagements, including evidence request lists and walkthrough preparation.

  • Support user access review campaigns: population scoping, reviewer assignments, completion monitoring, and verification that revocations were executed.

  • Collect and quality-check evidence for framework cycles, resolving gaps before assessor fieldwork.

  • Support the control exception process: intake, routing, compensating controls, expiry tracking, and re-review.

  • Apply practical, risk-based judgment to grey-area control questions, including whether a compensating control adequately addresses the underlying risk given how a specific subsidiary or brand operates.

  • Identify opportunities to reduce manual evidence collection.

  • Help maintain the control library: owners, test procedures, evidence requirements, testing frequency, and system mappings.

  • Support cross-framework mapping, including mapping internal baseline controls to the external requirements they satisfy.

  • Support findings tracking and remediation follow-up, retesting closed items rather than accepting closure on assertion.

  • Contribute to control reporting and metrics, and to workflow upkeep in the designated GRC platform.

  • Partner day-to-day with business units, IT teams, Security Operations, and InfoSec GRC counterparts across Fanatics' subsidiaries and brands, understanding how each operates in order to apply controls appropriately.

  • Build sufficient depth across contro

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security GRC Analyst — Controls Assurance
Information Security GRC Analyst — Controls Assurance

Fanatics Inc. • Jacksonville (FL)

On-site
USD 110,000 - 150,000
GRC Controls Assurance Analyst III – Enterprise Security
GRC Controls Assurance Analyst III – Enterprise Security

Fanatics-fb44f34a • Jacksonville (FL)

On-site
USD 100,000 - 150,000
Information Security GRC Analyst III, Controls Assurance
Information Security GRC Analyst III, Controls Assurance

Fanatics-fb44f34a • Jacksonville (FL)

On-site
USD 100,000 - 150,000
Technology Risk and Internal Controls Analyst, Entry Level (Remote)
Technology Risk and Internal Controls Analyst, Entry Level (Remote)

Jobright.ai • New York (NY)

On-site
USD 85,000 - 105,000
GRC Analyst
GRC Analyst

Golden Technology • North Carolina

Hybrid
USD 120,000 - 160,000
Lead GRC Analyst (IT/Security)
Lead GRC Analyst (IT/Security)

Ultra Clean Technology • Manor (TX)

On-site
USD 90,000 - 120,000
Sr. Security Assurance Engineer
Sr. Security Assurance Engineer

6sense • United States

On-site
USD 140,000 - 200,000
Manager, Control Design & Assurance
Manager, Control Design & Assurance

Fanatics • United States

On-site
USD 120,000 - 150,000
Senior Tech GRC Analyst: Governance, Risk & Compliance
Senior Tech GRC Analyst: Governance, Risk & Compliance

FanDuel • Atlanta (GA)

On-site
USD 120,000 - 160,000
FanDuel Total Rewards
Health plans
PTO & sick leave
+5
Staff Risk & Compliance Analyst
Staff Risk & Compliance Analyst

GE Vernova • United States

On-site
USD 85,000 - 120,000
Relocation assistance