Impress employers and recruiters.
Choose from hundreds of resume examples.

Impress employers and recruiters.
Choose from hundreds of resume examples.
Tailor your resume to this Information Security GRC Analyst III, Controls Assurance role.
Rezi rewrites your resume against Fanatics Inc.'s job description. Free.

Tailor your resume to this Information Security GRC Analyst III, Controls Assurance role.
Rezi rewrites your resume against Fanatics Inc.'s job description. Free.
Don't guess if your resume is good enough.
See how it scores against the Information Security GRC Analyst III, Controls Assurance posting at Fanatics Inc. — free, in seconds.

Don't guess if your resume is good enough.
See how it scores against the Information Security GRC Analyst III, Controls Assurance posting at Fanatics Inc. — free, in seconds.
About the Role
The Information Security GRC Analyst III, Controls Assurance role is central to verifying the effectiveness of Fanatics' security controls across various frameworks like PCI DSS, SOX ITGC, and SOC reporting. This corporate-level position offers broad exposure to the entire Fanatics portfolio, requiring daily collaboration with business units, IT teams, Security Operations, and InfoSec GRC counterparts across all subsidiaries and brands. You will gain a unique, enterprise-wide perspective on how a global, multi-brand organization operates and secures itself.
Responsibilities
- Execute assigned control tests in partnership with control set owners, including sample selection, evidence requests, walkthroughs, and documented conclusions on operating effectiveness.
- Communicate control requirements, testing results, and rationale clearly and consistently to control owners across technical and non-technical audiences, influencing timely, positive adoption of controls and remediation.
- Prepare workpapers that withstand assessor review without rework.
- Evaluate evidence critically, identifying artifacts that do not substantiate the control.
- Support QSA, audit, and service auditor engagements, including evidence request lists and walkthrough preparation.
- Support user access review campaigns: population scoping, reviewer assignments, completion monitoring, and verification that revocations were executed.
- Collect and quality-check evidence for framework cycles, resolving gaps before assessor fieldwork.
- Support the control exception process: intake, routing, compensating controls, expiry tracking, and re-review.
- Apply practical, risk-based judgment to grey-area control questions, including whether a compensating control adequately addresses the underlying risk given how a specific subsidiary or brand operates.
- Identify opportunities to reduce manual evidence collection.
- Help maintain the control library: owners, test procedures, evidence requirements, testing frequency, and system mappings.
- Support cross-framework mapping, including mapping internal baseline controls to the external requirements they satisfy.
- Support findings tracking and remediation follow-up, retesting closed items rather than accepting closure on assertion.
- Contribute to control reporting and metrics, and to workflow upkeep in the designated GRC platform.
- Partner day-to-day with business units, IT teams, Security Operations, and InfoSec GRC counterparts across Fanatics' subsidiaries and brands, understanding how each operates in order to apply controls appropriately.
- Build sufficient depth across control sets to provide backup coverage during leave, peak workload, or overlapping cycles.
Requirements
- Four years or more in IT audit, IT control testing, information security GRC, or a related discipline; Big Four or regional firm IT audit experience applies directly.
- Demonstrated experience executing control tests to a defined procedure, including sampling, evidence evaluation, and documented conclusions.
- Experience with user access reviews, either administering campaigns or testing them as a control.
- Exposure to at least one of PCI DSS, SOX ITGC, SOC, or an internal security control baseline.
- Experience driving a recurring process across stakeholders outside a direct reporting line, with a record of following items to completion.
- Curiosity and adaptability to understand how Fanatics' different subsidiaries and brands operate, and how that context shapes how a control should be applied and assessed for effectiveness.
- Working knowledge of core control domains: access management and access reviews, privileged access, change management, SDLC, logging and monitoring, encryption, vulnerability and patch management, backup and recovery, and cloud platform fundamentals.
- Excellent written and verbal communication, with the ability to explain technical and non-technical control concepts clearly and consistently to control owners, and to influence stakeholders toward timely, positive adoption of controls and remediation, even without direct authority over them.
- Effective use of approved AI tools in day-to-day work, with sound judgment about where AI output can and cannot be relied upon in an audit context.
- Organizational discipline, persistence, and judgment about when to escalate.
- Detail-oriented, with sound judgment for navigating grey areas in control descriptions and a practical, risk-based approach to evaluating compensating controls rather than a strict pass/fail mindset.
- Bachelor's degree in information security, cybersecurity, information systems, accounting, or a related field, or equivalent practical experience.
- Preferred: CISA certification.
- Preferred: exposure to two or more of PCI DSS, SOX ITGC, and SOC, including familiarity with PCI DSS v4.0.1, and testing against NIST 800-53 or the NIST Cybersecurity Framework.
- Preferred: familiarity with an enterprise GRC or IRM platform.
Skills
- PCI DSS
- SOX ITGC
- SOC reporting
- NIST
- Control testing
- Evidence evaluation
- User access reviews
- Risk-based approach
- Communication
- AI tools
- Information security
- Cybersecurity
- Information systems
- Accounting
- CISA
- NIST 800-53
- NIST Cybersecurity Framework
- GRC platform
- IRM platform
Location
- New York City
Work Type
- Corporate
Experience Level
- Four years + in IT audit, IT control testing, information security GRC, or a related discipline
Education Level
- Bachelor's degree in information security, cybersecurity, information systems, accounting, or a related field, or equivalent practical experience.
Salary/Compensations
- $120,000—$160,000 USD
Benefits
- For information about our benefits, please visit https://benefitsatfanatics.com/
About the Company
- Fanatics is building a leading global digital sports platform, igniting the passions of global sports fans and maximizing the presence and reach for its hundreds of sports partners globally. The company operates across Fanatics Commerce, Fanatics Collectibles, and Fanatics Betting & Gaming. Fanatics has an established database of over 100 million global sports fans; a global partner network with approximately 900 sports properties, including major national and international professional sports leagues, players associations, teams, colleges, college conferences and retail partners, 2,500 athletes and celebrities, and 200 exclusive athletes; and over 2,000 retail locations, including its Lids retail stores. The company employs over 22,000 individuals committed to enhancing the fan experience globally.
Equal Opportunity
- By submitting your application, you agree to our terms of service and acknowledge you have read our Candidate Privacy Policy.