Fanatics

Information Security GRC Analyst III, Controls Assurance

Fanatics • $120K — $160K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 4+ years in IT audit, IT control testing, or information security GRC; Big Four experience preferred.
  • Proven experience executing control tests, including sampling and evidence evaluation.
  • Familiarity with user access reviews and their testing.
  • Knowledge of PCI DSS, SOX ITGC, SOC, or an internal control baseline.
  • Ability to drive recurring processes across stakeholders effectively.
  • Strong understanding of core control domains such as access management and change management.
  • Excellent communication skills to articulate technical concepts clearly.

Responsibilities

  • Execute control tests and document effectiveness with control set owners.
  • Communicate control requirements and results to both technical and non-technical audiences.
  • Prepare durable workpapers for assessor review.
  • Critically evaluate evidence to ensure it substantiates controls.
  • Support engagement with auditors, including evidence request lists preparation.
  • Manage user access review campaigns, ensuring effective compliance and monitoring.
  • Collect and quality-check evidence for framework cycles, resolving gaps promptly.

Benefits

  • Comprehensive benefits package including health, dental, and vision insurance.
  • 401(k) plan with company match for retirement savings.
  • Career development opportunities and training programs.
  • Flexible work options to support work-life balance.
  • Employee discounts on Fanatics merchandise.
  • Access to mental health resources and support.
Full Job Description
The Role
The Information Security GRC Analyst III, Controls Assurance (Fanatics Corporate) sits at the center of how Fanatics proves its security controls actually work, testing across PCI DSS, SOX ITGC, SOC reporting, and our internal NIST-aligned control baselines. This is a Corporate-level role with direct exposure across the full Fanatics portfolio: you will work daily with business units, IT teams, Security Operations, and InfoSec GRC counterparts across our subsidiaries and brands, giving you a rare, enterprise-wide view of how a global, multi-brand organization operates and secures itself.

Working in partnership with the designated owner of each control set, you will execute assigned control testing, collect and evaluate evidence, support user access reviews and control exception administration, and contribute to findings tracking and control reporting. Control effectiveness is rarely a clean pass or fail; you will need to read the intent behind a control, work through the grey areas, and take a practical, risk-based approach to compensating controls, tailored to how each subsidiary or brand actually does business. Strong communication is central to the role: you will explain technical and non-technical control requirements clearly and consistently to control owners, and use that clarity to influence timely, positive adoption of controls and remediation.

Control baselines and framework control sets are established and owned within the GRC team, so this is a controls assurance role rather than a program build-out or control design role. A substantial portion of the work is recurring and deadline-driven, including access review cycles, evidence collection, and assessment calendars.

What You'll Do
  • Execute assigned control tests in partnership with control set owners, including: sample selection, evidence requests, walkthroughs, and documented conclusions on operating effectiveness.
  • Communicate control requirements, testing results, and rationale clearly and consistently to control owners across technical and non-technical audiences, and use that clarity to influence timely, positive adoption of controls and remediation.
  • Prepare workpapers that withstand assessor review without rework.
  • Evaluate evidence critically, identifying artifacts that do not substantiate the control.
  • Support QSA, audit, and service auditor engagements, including evidence request lists and walkthrough preparation.
  • Support user access review campaigns: population scoping, reviewer assignments, completion monitoring, and verification that revocations were executed.
  • Collect and quality-check evidence for framework cycles, resolving gaps before assessor fieldwork.
  • Support the control exception process: intake, routing, compensating controls, expiry tracking, and re-review.
  • Apply practical, risk-based judgment to grey-area control questions, including whether a compensating control adequately addresses the underlying risk given how a specific subsidiary or brand operates.
  • Identify opportunities to reduce manual evidence collection.
  • Help maintain the control library: owners, test procedures, evidence requirements, testing frequency, and system mappings.
  • Support cross-framework mapping, including mapping internal baseline controls to the external requirements they satisfy.
  • Support findings tracking and remediation follow-up, retesting closed items rather than accepting closure on assertion.
  • Contribute to control reporting and metrics, and to workflow upkeep in the designated GRC platform.
  • Partner day-to-day with business units, IT teams, Security Operations, and InfoSec GRC counterparts across Fanatics' subsidiaries and brands, understanding how each operates in order to apply controls appropriately.
  • Build sufficient depth across control sets to provide backup coverage during leave, peak workload, or overlapping cycles.


What We're Looking For
  • Four years + in IT audit, IT control testing, information security GRC, or a related discipline; Big Four or regional firm IT audit experience applies directly.
  • Demonstrated experience executing control tests to a defined procedure, including sampling, evidence evaluation, and documented conclusions.
  • Experience with user access reviews, either administering campaigns or testing them as a control.
  • Exposure to at least one of PCI DSS, SOX ITGC, SOC, or an internal security control baseline.
  • Experience driving a recurring process across stakeholders outside a direct reporting line, with a record of following items to completion.
  • Curiosity and adaptability to understand how Fanatics' different subsidiaries and brands operate, and how that context shapes how a control should be applied and assessed for effectiveness.
  • Working knowledge of core control domains: access management and access reviews, privileged access, change management, SDLC, logging and monitoring, encryption, vulnerability and patch management, backup and recovery, and cloud platform fundamentals.
  • Excellent written and verbal communication, with the ability to explain technical and non-technical control concepts clearly and consistently to control owners, and to influence stakeholders toward timely, positive adoption of controls and remediation, even without direct authority over them.
  • Effective use of approved AI tools in day-to-day work, with sound judgment about where AI output can and cannot be relied upon in an audit context.
  • Organizational discipline, persistence, and judgment about when to escalate.
  • Detail-oriented, with sound judgment for navigating grey areas in control descriptions and a practical, risk-based approach to evaluating compensating controls rather than a strict pass/fail mindset.
  • Bachelor's degree in information security, cybersecurity, information systems, accounting, or a related field, or equivalent practical experience.
  • Preferred: CISA certification.
  • Preferred: exposure to two or more of PCI DSS, SOX ITGC, and SOC, including familiarity with PCI DSS v4.0.1, and testing against NIST 800-53 or the NIST Cybersecurity Framework.
  • Preferred: familiarity with an enterprise GRC or IRM platform


The salary range represents base pay only and does not include short-term or long-term incentive compensation. This salary range is specific to New York City and may not be applicable to other locations. When determining base pay, as part of a final compensation package, we consider several factors such as location, experience, qualifications, and training. For information about our benefits, please visit https://benefitsatfanatics.com/

NYC Salary Range

$120,000-$160,000 USD

By submitting your application, you agree to our terms of service and acknowledge you have read our Candidate Privacy Policy.

About Fanatics

Fanatics is a leading retailer of licensed sports merchandise. The company was founded in 1995 and has grown to become the largest online retailer of officially licensed sports merchandise in the world. Fanatics offers a wide range of products, including jerseys, hats, and other apparel, as well as collectibles and memorabilia. The company has partnerships with all major sports leagues and teams, as well as with individual athletes. Fanatics is committed to providing a seamless shopping experience for its customers and has invested heavily in technology and logistics to ensure fast and reliable delivery.
Learn more about Fanatics
Size
5,000 employees
Industry
Founded
1995

Similar Jobs

More Jobs at Fanatics

More Information Technology Jobs

Find similar Information Security GRC Analyst III, Controls Assurance jobs: