Fanduel Senior Technology Governance, Risk & Compliance (GRC) Analyst at FanDuel to lead and mature a risk-based technology control program. Design, implement, and monitor key controls aligned with security frameworks and regulatory requirements.
Responsibilities
Lead and mature a risk-based technology control program
Design, implement, and monitor effectiveness of key controls
Navigate the complete control lifecycle including process discovery, control identification, testing, and issue management
Develop and deliver executive reports of technology controls
Qualification
“Stay Hungry
Required
Bachelor’s degree preferred in a technical field (e.g., Cybersecurity, Information Technology) or equivalent combination of education, training, and relevant experience.
5+ years related experience across technology and cybersecurity Governance, Risk, and Compliance (GRC), with demonstrated breadth across all three disciplines.
Hands-on experience navigating the full control lifecycle – process and risk identification, control design and definition, design and operating effectiveness testing, issue management, and remediation tracking.
Experience conducting technology risk assessments and maintaining risk registers and partnering with risk owners to define and track mitigation strategies aligned to risk appetite.
In-depth understanding of various IT platform and systems including but not limited to AWS, Okta, GitHub, and Atlassian products.
Ability to partner with technical stakeholders to discover, analyze, and document comprehensive data flows, establishing a clear line of sight into how data moves across our infrastructure.
Experience developing or maintaining technology policies, standards, procedures, and supporting governance committees / forums with related reporting.
Hands-on experience executing and managing IT and security audits or regulatory assessments in a heavily regulated industry, including writing, documenting, and assessing risks/controls and drafting business process summaries for executives.
“Stay Hungry, Stay Humble” mindset that strives to continuously learn and share new skills with others, and embraces a steep learning curve to understand our business and technology drivers to get the job done
“Anything Is Possible” attitude that is highly organized and results-driven to solve our most important challenges
Comfortable navigating shifting priorities in a fast-paced environment, with the ability to work independently with minimal supervision while also as an exceptional team player that excels at cultivating relationships and promoting collaboration and cohesiveness to fulfill our “We Are One Team” principle
Strong IT & security risk domain knowledge of technology and cybersecurity best practices, principles, tools, and industry control frameworks (e.g., GLI-33b, GLI-19, NIST 800-53, NIST CSF, SOX, SOC2, PCI)