Senior Technology Governance, Risk & Compliance (GRC) Analyst at FanDuel | New York, United States | Rezi

Senior Technology Governance, Risk & Compliance (GRC) Analyst at FanDuel

Senior Technology Governance, Risk & Compliance (GRC) Analyst

FanDuel · New York, United States

1 weeks ago

Senior Technology Governance, Risk & Compliance (GRC) Analyst

FanDuel · New York, United States

13 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

FanDuel is seeking a Senior Technology Governance, Risk & Compliance (GRC) Analyst to join its Technology GRC team. This role will support the first line of defense (1LOD) function and is instrumental in designing and establishing governance structures and frameworks for technology decisions, accountability, and risk management. The position focuses on building and maturing the Technology Unified Controls framework, ensuring alignment with enterprise principles and regulatory requirements.

Responsibilities

  • Lead and mature a risk-based technology control program to design, implement, and monitor the effectiveness of key controls across the Technology organization, ensuring alignment with FanDuel's security frameworks, industry best practices, and regulatory requirements (NIST CSF, GLI-GSF, PCI, SOC2, SOX)
  • Navigate the complete control lifecycle - including process discovery, control identification and implementation, testing and continuous assurance, and issue management with remediation guidance bringing along an automation-first mindset
  • Develop and deliver executive reports of technology control health, issues, and risk posture
  • Serve as the Technology organization's first line point of contact for various compliance activities (e.g. SOC2, PCI, State Regulatory Exams) and act as a primary liaison between audit teams and internal control stakeholders to ensure clear communication of requirements, timelines, and expectations
  • Partner with Technology and Enterprise Risk Management teams to maintain FanDuel's technology risk and controls framework, ensuring risks are identified, assessed, documented, and mapped to effective controls aligned with the company's risk appetite
  • Advise and support technology control owners during regulatory examinations or internal audits / assessments, including clarifying scope, expectations and timelines, coordinating meetings, facilitating evidence gathering, clarifying issues with relevant SMEs & stakeholders, and developing necessary action plans and management responses
  • Develop and maintain comprehensive technology governance policies, standards, and procedures; ensure alignment with enterprise governance principles and regulatory requirements
  • Actively develop, support, and maintain FanDuel's GRC tools to provide continuous controls monitoring and consistent control health reporting while pushing forward an audit-ready environment.
  • Align control standards with Flutter Entertainment and other brands' GRC groups to push efficiencies and best practices across the enterprise
  • Track issues throughout the lifecycle, from initial deviation identification, root cause analysis, remediation plan development, and reporting, as well as supporting resolution and ongoing monitoring
  • Lead cross-functional discussions and workshops to enhance awareness and foster continuous improvement across the technology control environment
  • Stay abreast of evolving technology & cybersecurity threats, trends, and regulatory changes to enhance control, risk, and governance strategies
  • Develop and deliver tailored training and communications on relevant GRC obligations for the technology community, as needed
  • Maintain procedures, playbooks, reference documentation, and metrics dashboards
  • Assist with special GRC, regulatory, and control assessment and department initiatives, as assigned
  • Mentor and guide junior team members, sharing expertise and promoting continuous professional development

Requirements

  • Bachelor’s degree preferred in a technical field (e.g., Cybersecurity, Information Technology) or equivalent combination of education, training, and relevant experience.
  • 5+ years related experience across technology and cybersecurity Governance, Risk, and Compliance (GRC), with demonstrated breadth across all three disciplines.
  • Hands-on experience navigating the full control lifecycle – process and risk identification, control design and definition, design and operating effectiveness testing, issue management, and remediation tracking.
  • Experience conducting technology risk assessments and maintaining risk registers and partnering with risk owners to define and track mitigation strategies aligned to risk appetite.
  • In-depth understanding of various IT platform and systems including but not limited to AWS, Okta, GitHub, and Atlassian products.
  • Ability to partner with technical stakeholders to discover, analyze, and document comprehensive data flows, establishing a clear line of sight into how data moves across our infrastructure.
  • Experience developing or maintaining technology policies, standards, procedures, and supporting governance committees / forums with related reporting.
  • Hands-on experience executing and managing IT and security audits or regulatory assessments in a heavily regulated industry, including writing, documenting, and assessing risks/controls and drafting business process summaries for executives.
  • Comfortable navigating shifting priorities in a fast-paced environment, with the ability to work independently with minimal supervision while also as an exceptional team player that excels at cultivating relationships and promoting collaboration and cohesiveness to fulfill our “We Are One Team!” principle
  • Strong IT & security risk domain knowledge of technology and cybersecurity best practices, principles, tools, and industry control frameworks (e.g., GLI-33b, GLI-19, NIST 800-53, NIST CSF, SOX, SOC2, PCI)
  • Knowledge of qualitative and quantitative risk management methodologies (e.g., NIST RMF / 800-37 / 800-30, FAIR)
  • Ability to translate risk/control standards into functional business requirements
  • Strong written and verbal communication skills to articulate GRC insights to both technical and non-technical stakeholders
  • Proficient working with Microsoft Office, GRC and project management tools (e.g., Optro, Anecdotes, Jira, Sharepoint)
  • Experience working as a consultant in the risk, compliance, or audit space is a plus

Skills

  • Cybersecurity
  • Information Technology
  • Governance, Risk, and Compliance (GRC)
  • Technology risk assessments
  • Risk registers
  • AWS
  • Okta
  • GitHub
  • Atlassian products
  • Technology policies
  • Technology standards
  • Technology procedures
  • IT and security audits
  • Regulatory assessments
  • NIST 800-53
  • NIST CSF
  • SOX
  • SOC2
  • PCI
  • NIST RMF
  • 800-37
  • 800-30
  • FAIR
  • Microsoft Office
  • GRC tools
  • Project management tools
  • Optro
  • Anecdotes
  • Jira
  • Sharepoint

Location

  • New York
  • Los Angeles
  • Atlanta
  • Jersey City
  • Canada
  • Scotland

Work Type

  • Hybrid

Experience Level

  • Senior
  • 5+ years related experience

Education Level

  • Bachelor’s degree preferred in a technical field (e.g., Cybersecurity, Information Technology) or equivalent combination of education, training, and relevant experience.

Salary/Compensations

  • $138,000 - $173,000 USD

Benefits

  • Array of health plans to choose from (some as low as $0 per paycheck)
  • Programs for fertility and family planning
  • Mental health support
  • Fitness benefits
  • Generous paid time off (PTO & sick leave)
  • Annual bonus and long-term incentive opportunities (based on performance)
  • 401k with up to a 5% match
  • Commuter benefits
  • Pet insurance
  • Medical, vision, and dental insurance
  • Life insurance
  • Disability insurance
  • 401(k) matching program
  • Short-term or long-term incentive compensation, including cash bonuses and stock program participation
  • Paid personal time off
  • 14 paid company holidays
  • Paid sick time in accordance with all applicable state and federal laws

About the Company

  • FanDuel Group is the premier mobile gaming company in the United States and Canada.
  • FanDuel Group consists of a portfolio of leading brands across mobile wagering including: America’s #1 Sportsbook, FanDuel Sportsbook; its leading iGaming platform, FanDuel Casino; the industry’s unquestioned leader in horse racing and advance-deposit wagering, FanDuel Racing; and its daily fantasy sports product.
  • In addition, FanDuel Group operates FanDuel TV, its broadly distributed linear cable television network and FanDuel TV+, its leading direct-to-consumer OTT platform.
  • FanDuel Group has a presence across all 50 states, Canada, and Puerto Rico.
  • The company is based in New York with US offices in Los Angeles, Atlanta, and Jersey City, as well as global offices in Canada and Scotland.
  • The company’s affiliates have offices worldwide, including in Ireland, Portugal, Romania, and Australia.
  • FanDuel Group is a subsidiary of Flutter Entertainment, the world's largest sports betting and gaming operator with a portfolio of globally recognized brands and traded on the New York Stock Exchange (NYSE: FLUT).

Equal Opportunity

  • FanDuel is an equal opportunities employer and we believe, as one of our principles states, “We are One Team!”. As such, we are committed to equal employment opportunity regardless of race, color, ethnicity, ancestry, religion, creed, sex, national origin, sexual orientation, age, citizenship status, marital status, disability, gender identity, gender expression, veteran status, or any other characteristic protected by state, local or federal law. We believe FanDuel is strongest and best able to compete if all employees feel valued, respected, and included.
  • FanDuel is committed to providing reasonable accommodations for qualified individuals with disabilities. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please email Benefits@fanduel.com.