Über
As a
Security Analyst II
at Fanatics Betting & Gaming (FBG), your knowledge and experience in third party security and risk management will help ensure that our vendor ecosystem operates securely, minimizing risk while enabling the business to scale confidently and compliantly. This role sits within the Information Security department and reports to the Director of Information Security.
Responsibilities: Conduct comprehensive third-party security risk assessments by evaluating vendor controls, policies, and documentation (e.g., SOC 2, ISO, penetration tests) against established frameworks. Analyze assessment results to identify risks, document findings, and provide actionable remediation recommendations. Assess risks related to data handling, privacy, critical integrations, and system dependencies Assess risks associated with third parties use of emerging technologies, including AI/ML, with a focus on data security and governance Collaborate with procurement, legal, and business stakeholders to embed security requirements into vendor onboarding and lifecycle management processes. Monitor vendor risk posture over time, including tracking security incidents, control changes, and emerging risks. Track, measure, and report on third-party risk metrics, trends, and remediation progress to leadership. Support the development, maintenance, and continuous improvement of third-party risk management policies, standards, and procedures. Leverage available tools, including AI-assisted technologies, to improve the efficiency and consistency of third party security risk assessments and documentation. Ensure compliance with applicable regulatory and security frameworks (e.g., NIST, ISO 27001, SOX) and support incident response efforts involving third parties. Qualifications:
2 - 3+ years of experience in cybersecurity, risk management, or third-party/vendor risk management. Strong understanding of security frameworks and standards such as NIST CSF, NIST 800-53, ISO 27001, and SOC 2. Experience reviewing and assessing vendor security documentation (e.g., SOC reports, ISO certifications, security questionnaires). Experience working with or supporting third-party risk management programs and tools (e.g., OneTrust, SecurityScorecard) Understanding of risks associated with third-party use of AI/ML technologies Strong written and verbal communication skills, with the ability to communicate effectively with both technical and non-technical stakeholders. Ability to prioritize and balance multiple projects simultaneously Ability to collaborate and work in a team environment
Salary Range:
$128,250 - $168,750 USD per year The base salary for this role is based on job-related knowledge, skills, and experience and may vary depending on the successful candidate's geographic location. For information about our benefits, please visit https://benefitsatfanatics.com/
Depending on the role, your interview and onboarding experience may include in-person components, such as onsite interviews or Launching into Better: LIVE-a multi-day cultural immersion in New York City for full-time, non-seasonal hires. These sessions are designed to build connection and bring our culture to life, though specific travel and participation requirements will be confirmed based on your role and location. Your recruiter will provide clear guidance at each stage of the process.
Sprachkenntnisse
- English
Hinweis für Nutzer
Dieses Stellenangebot stammt von einer Partnerplattform von TieTalent. Klick auf „Jetzt Bewerben”, um deine Bewerbung direkt auf deren Website einzureichen.