The Information Security GRC Analyst III, Controls Assurance is responsible for proving the effectiveness of Fanatics' security controls across various frameworks including PCI DSS, SOX ITGC, SOC reporting, and internal NIST-aligned control baselines. This corporate-level role offers a broad view of the entire Fanatics portfolio, requiring daily collaboration with business units, IT teams, Security Operations, and InfoSec GRC counterparts across subsidiaries and brands. The analyst will execute control testing, evaluate evidence, support user access reviews and control exception administration, and track findings and control reporting. A key aspect of the role involves understanding the intent behind controls, navigating ambiguities with a practical, risk-based approach to compensating controls tailored to each business unit, and communicating technical and non-technical requirements clearly to influence positive control adoption and remediation. This is a controls assurance role focused on testing established baselines and framework control sets, rather than program building or design. The position involves recurring, deadline-driven tasks such as access reviews, evidence collection, and managing assessment calendars.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior