Information Security GRC Analyst III, Controls Assurance
Quick Summary
sample selection, evidence requests, walkthroughs, and documented conclusions on operating effectiveness. Communicate control requirements, testing results,
Responsibilities
~2 min read- →Execute assigned control tests in partnership with control set owners, including: sample selection, evidence requests, walkthroughs, and documented conclusions on operating effectiveness.
- →Communicate control requirements, testing results, and rationale clearly and consistently to control owners across technical and non-technical audiences, and use that clarity to influence timely, positive adoption of controls and remediation.
- →Prepare workpapers that withstand assessor review without rework.
- →Evaluate evidence critically, identifying artifacts that do not substantiate the control.
- →Support QSA, audit, and service auditor engagements, including evidence request lists and walkthrough preparation.
- →Support user access review campaigns: population scoping, reviewer assignments, completion monitoring, and verification that revocations were executed.
- →Collect and quality-check evidence for framework cycles, resolving gaps before assessor fieldwork.
- →Support the control exception process: intake, routing, compensating controls, expiry tracking, and re-review.
- →Apply practical, risk-based judgment to grey-area control questions, including whether a compensating control adequately addresses the underlying risk given how a specific subsidiary or brand operates.
- →Identify opportunities to reduce manual evidence collection.
- →Help maintain the control library: owners, test procedures, evidence requirements, testing frequency, and system mappings.
- →Support cross-framework mapping, including mapping internal baseline controls to the external requirements they satisfy.
- →Support findings tracking and remediation follow-up, retesting closed items rather than accepting closure on assertion.
- →Contribute to control reporting and metrics, and to workflow upkeep in the designated GRC platform.
- →Partner day-to-day with business units, IT teams, Security Operations, and InfoSec GRC counterparts across Fanatics' subsidiaries and brands, understanding how each operates in order to apply controls appropriately.
- →Build sufficient depth across control sets to provide backup coverage during leave, peak workload, or overlapping cycles.
- Four years + in IT audit, IT control testing, information security GRC, or a related discipline; Big Four or regional firm IT audit experience applies directly.
- Demonstrated experience executing control tests to a defined procedure, including sampling, evidence evaluation, and documented conclusions.
- Experience with user access reviews, either administering campaigns or testing them as a control.
- Exposure to at least one of PCI DSS, SOX ITGC, SOC, or an internal security control baseline.
- Experience driving a recurring process across stakeholders outside a direct reporting line, with a record of following items to completion.
- Curiosity and adaptability to understand how Fanatics' different subsidiaries and brands operate, and how that context shapes how a control should be applied and assessed for effectiveness.
- Working knowledge of core control domains: access management and access reviews, privileged access, change management, SDLC, logging and monitoring, encryption, vulnerability and patch management, backup and recovery, and cloud platform fundamentals.
- Excellent written and verbal communication, with the ability to explain technical and non-technical control concepts clearly and consistently to control owners, and to influence stakeholders toward timely, positive adoption of controls and remediation, even without direct authority over them.
- Effective use of approved AI tools in day-to-day work, with sound judgment about where AI output can and cannot be relied upon in an audit context.
- Organizational discipline, persistence, and judgment about when to escalate.
- Detail-oriented, with sound judgment for navigating grey areas in control descriptions and a practical, risk-based approach to evaluating compensating controls rather than a strict pass/fail mindset.
- Bachelor's degree in information security, cybersecurity, information systems, accounting, or a related field, or equivalent practical experience.
- Preferred: CISA certification.
- Preferred: exposure to two or more of PCI DSS, SOX ITGC, and SOC, including familiarity with PCI DSS v4.0.1, and testing against NIST 800-53 or the NIST Cybersecurity Framework.
- Preferred: familiarity with an enterprise GRC or IRM platform
The salary range represents base pay only and does not include short-term or long-term incentive compensation. This salary range is specific to New York City and may not be applicable to other locations. When determining base pay, as part of a final compensation package, we consider several factors such as location, experience, qualifications, and training. For information about our benefits, please visit https://benefitsatfanatics.com/
By submitting your application, you agree to our terms of service and acknowledge you have read our Candidate Privacy Policy.
Location & Eligibility
Listing Details
- Posted
- September 24, 2026
- First seen
- September 24, 2026
- Last seen
- September 25, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 79%
- Scored at
- September 24, 2026
Signal breakdown
Similar Information Security jobs
View all →Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.