Search all jobs
Fanatics Logo

Security Analyst II

  • New York, USA
  • Full time
  • Competitive
  • 21st November 2025
View organisation profile
Apply Favourite
Copy Link

Full Description

Overview

As Fanatics Betting & Gaming (FBG) accelerates Fanatics' mission to build the ultimate digital sports platform, the Information Security Analyst II role is critical to ensuring our governance, risk, and compliance programs keep pace with our rapid growth and evolving regulatory landscape. As an Information Security Analyst II at FBG, you'll serve as a key contributor to our security compliance efforts, conducting user access reviews, managing audit readiness activities, and implementing controls that protect our customers and business operations across our real-time, high-performance betting and gaming systems.

This role combines deep GRC expertise, policy development skills, and collaborative partnership with stakeholders across the organization to strengthen our security posture and compliance programs. You'll lead user access review processes, develop and socialize security policies and standards, manage audit and assessment activities, support incident response efforts, and build dashboards that provide visibility into control effectiveness. Working in a highly regulated industry, you'll help ensure our systems meet rigorous security and compliance standards including SOC 2, ISO 27001, and SOX while enabling the business to innovate with confidence. We need analysts who can balance thorough compliance rigor with the practical realities of a fast-moving organization—who understand both security frameworks and how to make controls work effectively in the real world. If you're passionate about building strong compliance programs that actually make organizations more secure and have the experience to back it up, we want to talk with you.

Responsibilities:

● Administer and enhance the user access review process to identify and address access control issues effectively.

● Draft, refine, and socialize policies/standards (access control, change management, vendor security, incident response); maintain clear SOPs and RACI.

● Prepare high‑quality evidence, narratives, and diagrams; coordinate with auditors/assessors; manage requests and deadlines.

● Participate in Incident response efforts by conducting log analysis, gathering evidence, and executing remediation tasks.

● Build dashboards for control health, User Access Reviews completion, vendor coverage, and audit findings; present insights to InfoSec leadership and stakeholders.

● Automate evidence collection and access reviews where possible; propose control enhancements that improve security and reduce operational toil.

● Deliver security awareness presentations for both technical and non-technical users. Actively contribute to ongoing information security education through diverse methods such as phishing simulations, annual training sessions, on-demand courses, and workshops.

● Support Governance, Risk, and Compliance (GRC) initiatives by implementing controls and gathering necessary evidence, and control testing.

● Support InfoSec Risk Issue Intake process to assess and risk rank new issues, identify and document mitigation plans/timelines with risk owners and SMEs, and track to resolution.

● Support quarterly user access review process (UARs) for SOX systems and ensure tickets are tracked to resolution and actioned within audit requirements. Complete lookback analysis where necessary

● Support Data Loss Prevention process by triaging and investigating alerts in the Mimecast/Code42 solution.

● Participate in an on-call rotation to address security incidents and escalations promptly.

Qualifications:

● Minimum of 2 years of experience as a Information security analyst or in a similar role

● Ability to leverage security compliance frameworks to support control improvement and evidence correlation.

● Working knowledge of SOC 2 (Trust Services Criteria) and ISO/IEC 27001/27002; familiarity with mapping controls across frameworks.

● Practical experience running User Access Reviews: scoping, sampling, evidence collection including completeness and accuracy, exception handling, and remediation follow‑through.

● Solid grasp of least privilege, SoD, joiner/mover/leaver, break‑glass, and privileged access management fundamentals.

● Strong documentation skills (control narratives, test plans, SOPs) and stakeholder communication.

● Comfort with spreadsheets and basic scripting/queries (e.g., SQL or Python) for sampling and evidence validation.

● Foundational knowledge in Agile methodologies with ability to successfully collaborate with multiple stakeholders.

● Ability to communicate effectively with technical and non-technical stakeholders.

● Ability to prioritize and balance multiple projects simultaneously.

● Ability to collaborate and work in a team environment.

● Proven experience drafting documentation such as standards, policies and architecture diagrams.

● Background in risk assessment methodologies such as NIST and FAIR is a plus

The expected salary range for this role is based on job-related knowledge, skills, and experience. This role is eligible for the Fanatics Betting and Gaming annual bonus program and an equity award. *Salary range is listed in USD; actual salary will vary based on location. *Salary Range: 155,000 - 232,000 per year (actual salary will be determined in part by a successful candidate’s geographic location). In addition to base salary, bonus, and equity, full-time employees are eligible for Medical, Dental, Vision, 401K, paid time off, and other benefits like GymPass, Pet Insurance, Family Care Benefits, and more. We’ll also give you $700 to set up your home office!

The organisation

Fanatics
  • Data & Technology
  • New York, USA
  • 2000+ employees
  • Website

Relentlessly Enhancing the Fan Experience

More jobs from Fanatics

Fanatics Logo
AP Specialist - Payments
  • New York, USA
  • Full time
  • Competitive
Fanatics Logo
Senior Principal Engineer Kotlin Java Kafka
  • New York, USA
  • Full time
  • Competitive
Fanatics Logo
Sr. Manager, Software Engineering
  • Leeds, UK
  • Full time
  • Competitive
Fanatics Logo
Software Engineer III - Full Stack
  • Leeds, UK
  • Full time
  • Competitive
Fanatics Logo
Assoc Counsel
  • Tampa, USA
  • Full time
  • Competitive
Create a job alert

Get notified as soon as new jobs matching your ambitions go live.

Create a course alert

Create a job alert