Director of Information Security - Governance Risk and Compliance

Remote Full-time
Position Overview: Fanatics is actively seeking an accomplished and motivated Director of Information Security Governance, Risk and Compliance (GRC) who shares our commitment to information security as a cornerstone in safeguarding our organization. It is an exciting opportunity to be part of a fast-paced environment that pushes you to learn while doing. This role needs to be both strategic and intensely focused on GRC with an emphasis on process, scalability, and automation to ensure our security posture aligns seamlessly with business objectives. We value experience in collaborating with key stakeholders, understanding regulatory requirements, and implementing effective security strategies. Key Responsibilities Will Include: Governance • Develop and maintain an information security governance framework. • Establish and enforce security policies, standards, and procedures. • Provide guidance on security best practices and industry standards. • Collaborate with executive leadership to ensure security strategies align with business objectives. Security Risk Management • Lead the security team's risk management efforts. • Conduct risk assessments to identify and evaluate security risks. • Develop and implement risk mitigation strategies and action plans. • Monitor and report on risk metrics and trends to senior management. Compliance • Ensure the organization's compliance with relevant laws, regulations, certifications, assessments and industry standards including PCI-DSS, ITGCs, SOC1, SOC2, CCPA, CPRA, GDPR, among others. • Facilitate regular third-party compliance assessments and audits. • Collaborate with legal and regulatory affairs to address compliance requirements. • Stay abreast of changes in relevant laws and regulations affecting security. Security Strategy • Contribute to the development of the organization's overall security strategy. • Provide strategic direction for security initiatives and projects. • Collaborate with other departments to integrate security into business processes. • Assess emerging technologies and trends for their impact on security. Vendor and Third-Party Risk Management • Assess and manage security risks associated with third-party vendors. • Maintain and enhance the vendor risk management program. • Ensure third-party compliance with security standards. • Collaborate with legal to ensure third-party contracts reflect security and compliance requirements. Reporting and Communication • Provide regular updates and reports on security, risk, and compliance to senior management. • Communicate security strategies and priorities to all stakeholders. • Act as a liaison between technical security teams and executive leadership. Leadership • Lead and manage a team of security professionals. • Foster a collaborative and high-performing security team. • Provide mentorship and professional development opportunities. Continuous Improvement • Identify opportunities for process improvement within the security GRC function. • Stay informed about industry trends and best practices. • Implement continuous improvement initiatives to enhance security posture. Values and Behaviors • Demonstrate entrepreneurial spirit, strong communication skills, humility, and comfort working in and contributing to a dynamic and cross-functional team environment. Who you are • 10+ years of experience in information security (or 6 years of experience and a relevant bachelor's degree), with a focus on GRC. • Strong understanding of governance, quantitative risk management, and compliance frameworks. • Experience in collaborating with and influencing key stakeholders. • Strong technical background including full-stack software development, system architecture, and security fundamentals. • Relevant certifications (e.g. CISSP, CISM, CRISC, CISA, CIPP/US) preferred. • Exceptional communication skills and the ability to convey complex security concepts to non-technical stakeholders. Apply tot his job
Apply Now

Similar Opportunities

Experienced Registered Behavior Technician for In-Home ABA Therapy - Atlanta, GA

Remote Full-time

Immediate Hiring: Experienced Registered Behavioral Technician (RBT) for Clinic-Based ABA Therapy Services

Remote Full-time

Experienced Registered Behavioral Technician (RBT) - ABA Therapy for Children with Autism Spectrum Disorder

Remote Full-time

Experienced Registered Nurse - Telehealth: Providing Remote Care Coordination and Patient Support

Remote Full-time

Experienced Substitute Teacher for Riverside County Schools - Join Scoot Education's Innovative Team

Remote Full-time

Experienced Substitute Teacher for San Bernardino County - Flexible Schedules & Competitive Pay

Remote Full-time

Experienced School Year Instructional Coach for High-Dosage Tutoring Programs in Edgewater Park, NJ

Remote Full-time

Experienced School Year Tutor for K-8 Students in Math and Literacy - Mickleton, NJ

Remote Full-time

Experienced Secondary Social Studies Teacher for Kansas - Flexible Hybrid Remote Arrangement

Remote Full-time

USPS Office Helper

Remote Full-time

Remote Receptionist and Customer Service Representative - Join Our Dynamic Team at Workwarp

Remote Full-time

senior administrative assistant, Mid South (Rem...

Remote Full-time

Co-Founder & CEO - AI Content & Publishing Engine

Remote Full-time

Product Owner II (Remote)

Remote Full-time

Staff Backend Engineer, AST: Composition Analysis

Remote Full-time

Telerad Daytime in GA | $460K+

Remote Full-time

Lead Data Engineer - Remote

Remote Full-time

Experienced Remote Data Entry Specialist – Flexible Work from Home Opportunities for Career Starters and Seasoned Professionals Alike

Remote Full-time

One Flight Attendant

Remote Full-time

Experienced Part-Time Remote Customer Service Representative – Delivering Exceptional Support and Driving Customer Satisfaction for blithequark

Remote Full-time
← Back to Home