Security Analyst III, Fanatics Markets

Remote Full-time
Overview Fanatics Markets is the real-money prediction and trading app where you can invest in moments you care about. Built on a secure platform, we let users predict real-world outcomes and trade on events they actually follow - from sports and entertainment to political elections and beyond. Our mission is to redefine how fans engage with the moments and markets that matter most. We're looking for the right people to help us build the future of prediction markets. This role combines deep GRC expertise, policy development skills, and collaborative partnership with stakeholders across the organization to strengthen our security posture and compliance programs. You'll lead user access review processes, develop and socialize security policies and standards, manage audit and assessment activities, support incident response efforts, and build dashboards that provide visibility into control effectiveness. Working in a highly regulated industry, you'll help ensure our systems meet rigorous security and compliance standards including SOC 2, ISO 27001, and SOX while enabling the business to innovate with confidence. We need analysts who can balance thorough compliance rigor with the practical realities of a fast-moving organization—who understand both security frameworks and how to make controls work effectively in the real world. If you're passionate about building strong compliance programs that actually make organizations more secure and have the experience to back it up, we want to talk with you. Responsibilities: • Administer and enhance the user access review process to identify and address access control issues effectively. • Draft, refine, and socialize policies/standards (access control, change management, vendor security, incident response, data privacy); maintain clear SOPs and RACI. • Prepare high‑quality evidence, narratives, and diagrams; coordinate with auditors/assessors; manage requests and deadlines. • Participate in Incident response efforts by conducting log analysis, gathering evidence, and executing remediation tasks. • Build dashboards for control health, User Access Reviews completion, vendor coverage, GDPR compliance metrics, and audit findings; present insights to InfoSec leadership and stakeholders. • Automate evidence collection and access reviews where possible; propose control enhancements that improve security and reduce operational toil. • Deliver security awareness presentations for both technical and non-technical users. Actively contribute to ongoing information security education through diverse methods such as phishing simulations, annual training sessions, on-demand courses, and workshops. • Support Governance, Risk, and Compliance (GRC) initiatives by implementing controls and gathering necessary evidence, and control testing. • Support InfoSec Risk Issue Intake process to assess and risk rank new issues, identify and document mitigation plans/timelines with risk owners and SMEs, and track to resolution. • Support quarterly user access review process (UARs) for SOX systems and ensure tickets are tracked to resolution and actioned within audit requirements. Complete lookback analysis where necessary • Support Data Loss Prevention process by triaging and investigating alerts in the Mimecast/Code42 solution. • Lead and coordinate GDPR compliance activities including Data Protection Impact Assessments (DPIAs), Records of Processing Activities (RoPA), data subject rights requests, and privacy audits. • Manage the Third Party Risk Management (TPRM) program including vendor security assessments, ongoing risk monitoring, review of vendor attestations (SOC 2, ISO 27001), and maintenance of the vendor risk register. • Conduct comprehensive security assessments of third-party vendors using standardized questionnaires and frameworks; work with vendors on remediation of identified gaps. • Participate in an on-call rotation to address security incidents and escalations promptly. Qualifications: • Minimum of 4-5 years of experience as an Information security analyst or in a similar role • Ability to leverage security compliance frameworks to support control improvement and evidence correlation. • Working knowledge of SOC 2 (Trust Services Criteria) and ISO/IEC 27001/27002; familiarity with mapping controls across frameworks. • Strong understanding of GDPR requirements including data protection principles, data subject rights, DPIAs, cross-border data transfers, and breach notification requirements. • Proven experience managing Third Party Risk Management programs including vendor assessments, security questionnaire reviews, and ongoing vendor risk monitoring. • Practical experience running User Access Reviews: scoping, sampling, evidence collection including completeness and accuracy, exception handling, and remediation follow‑through. • Solid grasp of least privilege, SoD, joiner/mover/leaver, break‑glass, and privileged access management fundamentals. • Strong documentation skills (control narratives, test plans, SOPs) and stakeholder communication. • Comfort with spreadsheets and basic scripting/queries (e.g., SQL or Python) for sampling and evidence validation. • Foundational knowledge in Agile methodologies with ability to successfully collaborate with multiple stakeholders. • Ability to communicate effectively with technical and non-technical stakeholders. • Ability to prioritize and balance multiple projects simultaneously. • Ability to collaborate and work in a team environment. • Proven experience drafting documentation such as standards, policies and architecture diagrams. • Background in risk assessment methodologies such as NIST and FAIR is a plus Salary Range: $129,200 - $212,500 USD per year The base salary for this role is based on job-related knowledge, skills, and experience and may vary depending on the successful candidate’s geographic location. For information about our benefits, please visit Depending on the role, your interview and onboarding experience may include in-person components, such as onsite interviews or Launching into Better: LIVE—a multi-day cultural immersion in New York City for full-time, non-seasonal hires. These sessions are designed to build connection and bring our culture to life, though specific travel and participation requirements will be confirmed based on your role and location. Your recruiter will provide clear guidance at each stage of the process. Apply tot his job
Apply Now

Similar Opportunities

Experienced Registered Behavior Technician for In-Home ABA Therapy - Atlanta, GA

Remote Full-time

Immediate Hiring: Experienced Registered Behavioral Technician (RBT) for Clinic-Based ABA Therapy Services

Remote Full-time

Experienced Registered Behavioral Technician (RBT) - ABA Therapy for Children with Autism Spectrum Disorder

Remote Full-time

Experienced Registered Nurse - Telehealth: Providing Remote Care Coordination and Patient Support

Remote Full-time

Experienced Substitute Teacher for Riverside County Schools - Join Scoot Education's Innovative Team

Remote Full-time

Experienced Substitute Teacher for San Bernardino County - Flexible Schedules & Competitive Pay

Remote Full-time

Experienced School Year Instructional Coach for High-Dosage Tutoring Programs in Edgewater Park, NJ

Remote Full-time

Experienced School Year Tutor for K-8 Students in Math and Literacy - Mickleton, NJ

Remote Full-time

Experienced Secondary Social Studies Teacher for Kansas - Flexible Hybrid Remote Arrangement

Remote Full-time

USPS Office Helper

Remote Full-time

Policy Service Rep - Life and Annuity Analyst - US

Remote Full-time

Experienced Part-Time Remote Data Entry Specialist – Join the Magical World of arenaflex from Home

Remote Full-time

Experienced Data Entry Assistant for Remote Full-Time Position – Accurate Data Management and Administrative Support

Remote Full-time

Urgent hiring for Product Support Analyst 3 in Remote || only W2|| Remote

Remote Full-time

(Senior) Fullstack Engineer - New Platform (m/f/x) (onsite / remote in Germany)

Remote Full-time

Senior Brand Manager Skinny Pop

Remote Full-time

Experienced Data Entry Specialist for REMS Call Center Operations – Remote Work Opportunity with blithequark

Remote Full-time

Experienced Remote Customer Service Executive – Night Shift Opportunity for Delivering Exceptional Support and Driving Customer Satisfaction

Remote Full-time

Senior Director, Consumer & Customer Service- REMOTE

Remote Full-time

Legal Editor, Practice Area Content (Medical Malpractice & Personal Injury Law)

Remote Full-time
← Back to Home