Fanduel Senior Technology Governance, Risk & Compliance (GRC) Analyst at FanDuel responsible for building and maturing the Technology Unified Controls framework. Lead risk-based control programs and ensure compliance with regulatory requirements.
Responsibilities
As a senior director-level player-coach, you will own one high-leverage agentic product surface end-to-end in collaboration with product managers and designs in tech and commercial, while also mentoring and raising the bar for how Product Management is practiced at FanDuel. You will lead a team of AI PMs that interface directly with business stakeholders, codify patterns for how product management is done in the AI era, and shape the discipline of product management more widely. If your reflex when you see a problem is to open a terminal and an agent harness before you open a Google Doc, this role is for you.
In addition to the specific responsibilities outlined above, employees may be required to perform other such duties as assigned by the Company. This ensures operational flexibility and allows the Company to meet evolving business needs.
Everyone on our team has a part to play
Mentor and coach AI PMs across the AI and wider product org through pairing, design reviews, written critique, prototype tear-downs, and a shared pattern library you help author. You will supervise multiple AI product managers in the AI Engineering Organization, while also raising the bar for FanDuel’s wider product management practice.
Own end-to-end for one or more workstreams (growth & marketing, customer experience, product innovation, enterprise acceleration), including strategy, roadmap, prioritization, and outcomes. You will build working prototypes with Claude Code, Cursor, Lovable, and modern agent frameworks. And you will design and operate evaluation systems — golden sets, offline evals, online experiments, drift and regression detection, human-rater pipelines — for every surface you own. Define what "good" means in numbers before you ship.
Partner daily with Business partners, FDEs, AI SWE pods, AI Platform, Trust & Safety, Responsible AI, and Legal. Translate ambiguous business problems into agent-shaped solutions that respect our regulatory and RG posture. Set the bar for AI-native PM craft across the function: write and maintain CLAUDE.md files, build MCP-aware tooling for the PM team, share patterns in writing, and pair with other PMs on hard problems.
Qualification
“Stay Hungry
Required
Bachelor’s degree preferred in a technical field (e.g., Cybersecurity, Information Technology) or equivalent combination of education, training, and relevant experience.
5+ years related experience across technology and cybersecurity Governance, Risk, and Compliance (GRC), with demonstrated breadth across all three disciplines.
Hands-on experience navigating the full control lifecycle – process and risk identification, control design and definition, design and operating effectiveness testing, issue management, and remediation tracking.
Experience conducting technology risk assessments and maintaining risk registers and partnering with risk owners to define and track mitigation strategies aligned to risk appetite.
In-depth understanding of various IT platform and systems including but not limited to AWS, Okta, GitHub, and Atlassian products.
Ability to partner with technical stakeholders to discover, analyze, and document comprehensive data flows, establishing a clear line of sight into how data moves across our infrastructure.
Experience developing or maintaining technology policies, standards, procedures, and supporting governance committees / forums with related reporting.
Hands-on experience executing and managing IT and security audits or regulatory assessments in a heavily regulated industry, including writing, documenting, and assessing risks/controls and drafting business process summaries for executives.
“Stay Hungry, Stay Humble” mindset that strives to continuously learn and share new skills with others, and embraces a steep learning curve to understand our business and technology drivers to get the job done
“Anything Is Possible” attitude that is highly organized and results-driven to solve our most important challenges
Comfortable navigating shifting priorities in a fast-paced environment, with the ability to work independently with minimal supervision while also as an exceptional team player that excels at cultivating relationships and promoting collaboration and cohesiveness to fulfill our “We Are One Team” principle
Strong IT & security risk domain knowledge of technology and cybersecurity best practices, principles, tools, and industry control frameworks (e.g., GLI-33b, GLI-19, NIST 800-53, NIST CSF, SOX, SOC2, PCI)