795,742open jobs
50,860companies
125,050added this week
Browse all
Salary
$120k – $160k per year
Location
In office (Jacksonville)
Seniority
Middle

Confirmed on the employer's own hiring board on Sep 26, 2026. First seen by Alion on Sep 24, 2026. Fanatics scores A on the Alion truth index.

Overview
Company
Impact
Profile match
Fanatics is a licensed sports merchandise and digital sports company headquartered in New York City, tracing its origins to a retail business founded in Jacksonville, Florida, in 1995. The company designs, manufactures, and sells team apparel and fan gear, and runs separate units covering collectibles and trading cards, sports betting, and live commerce. It holds licenses with major leagues and teams across North America and Europe and operates the online stores of many of those partners.

About Us

Fanatics is building a leading global digital sports platform. We ignite the passions of global sports fans and maximize the presence and reach for our hundreds of sports partners globally by offering products and services across Fanatics Commerce, Fanatics Collectibles, and Fanatics Betting & Gaming, allowing sports fans to Buy, Collect, and Bet. Through the Fanatics platform, sports fans can buy licensed fan gear, jerseys, lifestyle and streetwear products, headwear, and hardgoods; collect physical and digital trading cards, sports memorabilia, and other digital assets; and bet as the company builds its Sportsbook and iGaming platform. Fanatics has an established database of over 100 million global sports fans; a global partner network with approximately 900 sports properties, including major national and international professional sports leagues, players associations, teams, colleges, college conferences and retail partners, 2,500 athletes and celebrities, and 200 exclusive athletes; and over 2,000 retail locations, including its Lids retail stores. Our more than 22,000 employees are committed to relentlessly enhancing the fan experience and delighting sports fans globally. 

The Role

The Information Security GRC Analyst III, Controls Assurance (Fanatics Corporate) sits at the center of how Fanatics proves its security controls actually work, testing across PCI DSS, SOX ITGC, SOC reporting, and our internal NIST-aligned control baselines. This is a Corporate-level role with direct exposure across the full Fanatics portfolio: you will work daily with business units, IT teams, Security Operations, and InfoSec GRC counterparts across our subsidiaries and brands, giving you a rare, enterprise-wide view of how a global, multi-brand organization operates and secures itself.

Working in partnership with the designated owner of each control set, you will execute assigned control testing, collect and evaluate evidence, support user access reviews and control exception administration, and contribute to findings tracking and control reporting. Control effectiveness is rarely a clean pass or fail; you will need to read the intent behind a control, work through the grey areas, and take a practical, risk-based approach to compensating controls, tailored to how each subsidiary or brand actually does business. Strong communication is central to the role: you will explain technical and non-technical control requirements clearly and consistently to control owners, and use that clarity to influence timely, positive adoption of controls and remediation.

Control baselines and framework control sets are established and owned within the GRC team, so this is a controls assurance role rather than a program build-out or control design role. A substantial portion of the work is recurring and deadline-driven, including access review cycles, evidence collection, and assessment calendars.

What You'll Do 

  • Execute assigned control tests in partnership with control set owners, including: sample selection, evidence requests, walkthroughs, and documented conclusions on operating effectiveness.
  • Communicate control requirements, testing results, and rationale clearly and consistently to control owners across technical and non-technical audiences, and use that clarity to influence timely, positive adoption of controls and remediation.
  • Prepare workpapers that withstand assessor review without rework.
  • Evaluate evidence critically, identifying artifacts that do not substantiate the control.
  • Support QSA, audit, and service auditor engagements, including evidence request lists and walkthrough preparation.
  • Support user access review campaigns: population scoping, reviewer assignments, completion monitoring, and verification that revocations were executed.
  • Collect and quality-check evidence for framework cycles, resolving gaps before assessor fieldwork.
  • Support the control exception process: intake, routing, compensating controls, expiry tracking, and re-review.
  • Apply practical, risk-based judgment to grey-area control questions, including whether a compensating control adequately addresses the underlying risk given how a specific subsidiary or brand operates.
  • Identify opportunities to reduce manual evidence collection.
  • Help maintain the control library: owners, test procedures, evidence requirements, testing frequency, and system mappings.
  • Support cross-framework mapping, including mapping internal baseline controls to the external requirements they satisfy.
  • Support findings tracking and remediation follow-up, retesting closed items rather than accepting closure on assertion.
  • Contribute to control reporting and metrics, and to workflow upkeep in the designated GRC platform.
  • Partner day-to-day with business units, IT teams, Security Operations, and InfoSec GRC counterparts across Fanatics' subsidiaries and brands, understanding how each operates in order to apply controls appropriately.
  • Build sufficient depth across control sets to provide backup coverage during leave, peak workload, or overlapping cycles.

What We're Looking For 

  • Four years + in IT audit, IT control testing, information security GRC, or a related discipline; Big Four or regional firm IT audit experience applies directly.
  • Demonstrated experience executing control tests to a defined procedure, including sampling, evidence evaluation, and documented conclusions.
  • Experience with user access reviews, either administering campaigns or testing them as a control.
  • Exposure to at least one of PCI DSS, SOX ITGC, SOC, or an internal security control baseline.
  • Experience driving a recurring process across stakeholders outside a direct reporting line, with a record of following items to completion.
  • Curiosity and adaptability to understand how Fanatics' different subsidiaries and brands operate, and how that context shapes how a control should be applied and assessed for effectiveness.
  • Working knowledge of core control domains: access management and access reviews, privileged access, change management, SDLC, logging and monitoring, encryption, vulnerability and patch management, backup and recovery, and cloud platform fundamentals.
  • Excellent written and verbal communication, with the ability to explain technical and non-technical control concepts clearly and consistently to control owners, and to influence stakeholders toward timely, positive adoption of controls and remediation, even without direct authority over them.
  • Effective use of approved AI tools in day-to-day work, with sound judgment about where AI output can and cannot be relied upon in an audit context.
  • Organizational discipline, persistence, and judgment about when to escalate.
  • Detail-oriented, with sound judgment for navigating grey areas in control descriptions and a practical, risk-based approach to evaluating compensating controls rather than a strict pass/fail mindset.
  • Bachelor's degree in information security, cybersecurity, information systems, accounting, or a related field, or equivalent practical experience.
  • Preferred: CISA certification.
  • Preferred: exposure to two or more of PCI DSS, SOX ITGC, and SOC, including familiarity with PCI DSS v4.0.1, and testing against NIST 800-53 or the NIST Cybersecurity Framework.
  • Preferred: familiarity with an enterprise GRC or IRM platform

The salary range represents base pay only and does not include short-term or long-term incentive compensation.  This salary range is specific to New York City and may not be applicable to other locations.  When determining base pay, as part of a final compensation package, we consider several factors such as location, experience, qualifications, and training. For information about our benefits, please visit https://benefitsatfanatics.com/

NYC Salary Range

$120,000—$160,000 USD

By submitting your application, you agree to our terms of service and acknowledge you have read our  Candidate Privacy Policy.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
795,742 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Jacksonville
$75k – $83k per year • In office • Full-Time • 5+ years exp • Bachelor's Degree • Washington • New York
DevOps
Azure DevOps
Azure
CI/CD
GitHub
GitLab
Cybersecurity
OWASP Top 10
Threat Modeling
Apply
$76k – $156k per year • In office • 5+ years exp • Bachelor's Degree • Houston
Python
C++
Cybersecurity
Threat Modeling
Apply
DevSecOps 10 hours ago
$125k – $170k per year • Hybrid • Full-Time • 5+ years exp • Vienna
Python
PowerShell
DevOps
Splunk
Terraform
GitHub Actions
Terragrunt
GitLab CI
Azure
CI/CD
AWS
Docker
Kubernetes
AWS Fargate
Amazon S3
IAM
Amazon ECS
DNS
Cybersecurity
Snyk
SonarQube
Trivy
Checkmarx
Microsoft Sentinel
Zscaler
Checkov
NIST 800-53
FedRAMP
Zero Trust
Least Privilege
SBOM
tfsec
SIEM
Apply
$167k – $213k per year • Equity • In office • Full-Time • 4+ years exp • Bachelor's Degree • San Francisco
DevOps
AWS
Apply
$159k – $202k per year • Equity • In office • Full-Time • 4+ years exp • Boston
Python
JavaScript
Ruby
C#
C++
C#
.NET
DevOps
AWS
Cybersecurity
Threat Modeling
Apply
Sr. GRC Engineer 1 day ago
$157k – $220k per year • Equity • In office • Full-Time • 7+ years exp • Bachelor's Degree • Seattle
Python
JavaScript
TypeScript
PowerShell
DevOps
Rest API
Terraform
Puppet
Ansible
Chef
GitLab CI
Azure
CI/CD
Configuration Management
Bicep
Cybersecurity
ISO 27001
CIS Benchmarks
NIST 800-53
SIEM
Apply
$493k – $667k per year • In office • South Korea
Go
JavaScript
Java
Kotlin
TypeScript
Java
Spring Boot
Databases
MySQL
PostgreSQL
DynamoDB
AI/ML
Copilot
Claude Code
OpenAI Codex
Frontend
Vue.js
Nuxt.js
React.js
DevOps
Terraform
GCP
GitHub Actions
AWS
Docker
Kubernetes
AWS Fargate
Amazon ECS
Cybersecurity
PCI DSS
Management
Confluence
Jira
Stripe
Apply
≈ $78k – $166k per year (Estimated) • In office • Full-Time • 4+ years exp • Bachelor's Degree • Ottawa • Vancouver
DevOps
Incident Management
Cybersecurity
ISO 27001
NIST CSF
PCI DSS
SOC 2
GDPR
HIPAA
Threat Modeling
Apply
$150k – $190k per year • In office • Secret • Full-Time • McLean
Python
PowerShell
AI/ML
AWS Bedrock
LLM
Amazon SageMaker
DevOps
Splunk
Terraform
Ansible
Helm
OpenTelemetry
CloudFormation
Prometheus
GitLab CI
CI/CD
GitOps
ArgoCD
Jenkins
Git
AWS
Docker
Kubernetes
Grafana
Platform Engineering
Amazon EKS
AWS Fargate
Amazon S3
IAM
Amazon ECS
Amazon CloudWatch
Cybersecurity
HashiCorp Vault
NIST 800-53
NIST 800-171
FedRAMP
Zero Trust
Least Privilege
SBOM
Apply
$139k – $182k per year • In office • Full-Time • 5+ years exp • Austin
AI/ML
Model Context Protocol
Vertex AI
AI Agents
AWS Bedrock
OpenAI
Anthropic
LLM Guardrails
Agentic Workflows
DevOps
Terraform
GCP
CloudFormation
Azure
CI/CD
AWS
Kubernetes
eBPF
IAM
Cybersecurity
Wiz
PCI DSS
SOC 2
HIPAA
FedRAMP
Zero Trust
Apply
≈ $91k – $194k per year (Estimated) • In office • 10+ years exp • Hong Kong
Apply
$180k – $215k per year • Remote (United States) • Atlanta
AI/ML
PyTorch
Ignite
Apply
$122k – $200k per year • Remote (United States) • Full-Time • 5+ years exp • New York
Go
JavaScript
TypeScript
Databases
Apache Kafka
AI/ML
PyTorch
Ignite
Frontend
React.js
DevOps
Rest API
gRPC
GCP
Azure
CI/CD
AWS
Cybersecurity
Okta
GDPR
Auth0
Management
Agile
Scrum
Apply
$144k – $237k per year • Remote (United States) • Full-Time • 8+ years exp • New York
JavaScript
TypeScript
Databases
Apache Kafka
AI/ML
PyTorch
Ignite
Frontend
React.js
Apply
$120k – $150k per year • In office • Bachelor's Degree • Jacksonville
Databases
Oracle
AI/ML
PyTorch
Ignite
Analytics
Microsoft Excel
Apply
$110k – $120k per year • In office • Secret • Full-Time • 4+ years exp • Bachelor's Degree • Jacksonville
Cybersecurity
Nessus
Fortify
Management
Service Desk
Apply
$46k – $72k per year • Hybrid • Full-Time • 2+ years exp • Bachelor's Degree • Jacksonville
Apply
≈ $36k – $85k per year (Estimated) • In office • Full-Time • High School Diploma • Jacksonville
Apply
≈ $43k – $76k per year (Estimated) • In office • 2+ years exp • High School Diploma • Jacksonville
Apply
≈ $43k – $77k per year (Estimated) • In office • 2+ years exp • High School Diploma • Jacksonville
Apply
See all jobs
This is one of many
795,742 more open roles from verified company boards, updated every day.