The Information Security GRC Analyst III, Controls Assurance is responsible for proving the effectiveness of Fanatics' security controls across various frameworks including PCI DSS, SOX ITGC, SOC reporting, and internal NIST-aligned control baselines. This corporate-level role offers broad exposure across the Fanatics portfolio, requiring daily collaboration with business units, IT teams, Security Operations, and InfoSec GRC counterparts. The analyst will execute control testing, evaluate evidence, support user access reviews and control exception administration, and contribute to findings tracking and reporting. A key aspect of the role involves understanding the intent behind controls, navigating grey areas with a practical, risk-based approach to compensating controls tailored to specific business operations, and clearly communicating technical and non-technical requirements to influence control adoption and remediation. This is a controls assurance role focused on testing established controls rather than designing new ones, with a significant portion of work being recurring and deadline-driven.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior